Incident Response Lead

1 day, 16 hours ago
Full-time
Lead
Cybersecurity
Aspenview Technology Partners

Aspenview Technology Partners

Aspenview Technology Partners empowers IT organizations by providing agile, expert-staffed nearshore IT teams that deliver scalable capacity and advanced capabilities in software development, data engineering, business intelligence, artificial intellig...

Internet Software & Services

Description

  • Lead major-incident bridges and align the client, partner, and analysts on incident status.
  • Scope incidents and provide evidence-backed containment recommendations across infrastructure, identity, endpoint, and application teams.
  • Prepare operational updates, executive summaries, and post-incident reviews.
  • Own digital forensics and incident response investigations, including host and memory analysis.
  • Analyze CrowdStrike, Microsoft Defender, Okta, AWS CloudTrail, GuardDuty, and VPC flow-log data.
  • Build investigation records and timelines supporting regulatory notification decisions.
  • Develop and review incident-response playbooks and runbooks.
  • Lead tabletop exercises with security, legal, and risk stakeholders.
  • Provide technical direction to two Tier 3 analysts in Latin America.

Requirements

  • Senior-level experience leading technical response to major incidents from investigation through remediation.
  • Hands-on Windows and Linux forensics experience and investigations in at least one major cloud.
  • Ability to query SIEM, EDR, identity, and cloud logs independently.
  • Experience recommending containment actions that balance security and business continuity.
  • Strong written and verbal communication for technical, executive, legal, and regulatory audiences.
  • Experience leading distributed teams without direct management authority.
  • Proficiency with relevant tools such as Elastic, Abstract Security, ServiceNow SecOps, CrowdStrike Falcon, Microsoft Defender, Okta, and AWS security services.
  • US work authorization and permanent authorization without current or future visa sponsorship.
  • Availability for US Eastern business hours, a 24/7 on-call rotation, and periodic travel to client sites and Bogotá and Buenos Aires.
  • Preferred qualifications include financial-services incident response, regulatory knowledge, ransomware or fraud-intrusion experience, consultancy or MSSP experience, relevant certifications, and Spanish proficiency.

Benefits

  • Competitive base compensation.
  • Flexible hybrid, remote, or in-office work model.
  • Growth opportunities and leadership visibility.
  • Inclusive, people-first workplace culture.
  • Periodic travel opportunities to client locations and nearshore offices.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Security Researcher (Europe Remote)

Invicti 251-1K Internet Software & Services

Invicti Security is hiring a hands-on Offensive Security Researcher in Europe to research emerging web, cloud, and AI threats and turn findings into accurate, production-ready detection capabilities.

Burp Suite GraphQL HTTP JavaScript Kubernetes Nmap Python REST API
1 day, 17 hours ago

Director, OT/IoT Security Services- Remote (Anywhere in the U.S.)

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Director of OT/IoT Security Services to lead its industrial cybersecurity practice, overseeing its team, service portfolio, delivery quality, client engagements, and financial performance.

Cybersecurity
3 days, 16 hours ago

Technical Consultant - Network Security SASE

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to independently deliver enterprise SASE and SSE deployments, configuring Zero Trust architectures across platforms such as Zscaler, Palo Alto Prisma Access, Cisco Secure Access, and Netskope.

Network Security
1 week, 4 days ago

Senior Penetration Tester

Dark Wolf Solutions 51-250 Internet Software & Services

Dark Wolf is hiring a remote Senior Penetration Tester to assess and improve the security of hardware, software, firmware, embedded systems, networks, and wireless technologies through advanced penetration testing and exploit development.

AWS Azure Cybersecurity GCP Network Security Penetration Testing
1 week, 5 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers