Incident Response Lead
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Incident Response Lead directing cybersecurity incidents for Harbor IT’s managed services clients. Building playbooks, escalation processes, and response practice across regulated environments.
Responsibilities:
- Serve as incident commander for client security incidents
- Establish scope, set response priorities, assign actions to named owners, track decisions, and keep incidents moving
- Run triage and initial investigation across Microsoft 365, Entra ID, Active Directory, EDR-managed endpoints, servers, firewalls, and the Sagan detection pipeline
- Delegate information gathering while focusing on incident-command decisions
- Own containment decisions involving isolation, credential resets, evidence preservation, and client approval authority
- Decide whether incidents remain within Harbor’s scope or require escalation to outside DFIR firms, breach counsel, or insurance panels
- Own in-scope incidents from detection through post-incident reporting
- Brief receiving DFIR firms and hand off with a written timeline and evidence inventory
- Carry on-call responsibility and remain available outside business hours for incident escalation
- Translate technical findings into actionable decisions for owners, executives, and general counsel
- Coordinate with breach counsel, cyber insurance carriers and panel firms, third-party DFIR teams, client IT, and law enforcement where applicable
- Keep Client Success and leadership current on active incidents
- Produce post-incident reports covering confirmed and assumed facts, containment, open items, and recommended client changes
- Write and maintain incident response playbooks, severity model, and escalation matrix
- Define Harbor’s incident-response responsibility boundaries in writing
- Build working relationships with outside DFIR firms and breach counsel practices
- Maintain escalation-readiness records for every managed client
- Run tabletop exercises with Harbor teams and clients when applicable and feasible
- Mentor SOC analysts and security engineers on investigative method and incident discipline
- Feed incident lessons back to detection engineering to improve future detection
Requirements:
- 6+ years in cybersecurity, with substantial time spent responding to real intrusions rather than monitoring for them
- Direct experience acting as the lead on security incidents, setting direction while others execute
- Experience responding across multiple distinct organizations, whether from a consulting, MSSP, MDR, or panel DFIR background
- Hands-on investigative depth in Microsoft 365, Google Workspace, and Entra ID compromise
- Experience with unified audit log analysis, message trace, mailbox rules and forwarding, OAuth consent and application grants, device code and token abuse, and conditional access gaps
- Working command of endpoint detection and response tooling for investigation and containment
- Host and Windows internals knowledge sufficient to interpret process lineage, persistence mechanisms, and lateral movement evidence
- Ability to build defensible incident timelines from SIEM and detection alerts, endpoint telemetry, cloud audit logs, firewall logs, and help desk tickets
- Practical understanding of ransomware and hands-on-keyboard intrusion tradecraft
- Experience working alongside breach counsel, cyber insurance carriers, or third-party DFIR firms during a live incident, including investigation handoff
- Ability to brief non-technical executives under pressure and write clear, actionable client documentation
- Willingness and ability to be reachable outside business hours for incident escalation
- Preferred: GCIH, GCFA, GCIA, or comparable GIAC certification; CISSP or CISM
- Preferred: prior experience at a panel DFIR firm, MDR provider, or MSSP incident response team
- Preferred: host and memory forensics, malware triage, or reverse engineering
- Preferred: Linux investigation experience and cloud incident response beyond Microsoft, such as AWS
- Preferred: familiarity with HIPAA, PCI DSS, GLBA, state breach notification statutes, or SEC disclosure rules
- Preferred: background in managed services or another multi-tenant environment where the candidate owned both the relationship and investigation
Benefits:
- Employer-paid medical, dental, and vision coverage for the employee, with additional premium plan options available
- 401(k) with company match
- Paid time off
- Reimbursement for approved tuition, certifications, and conference attendance














