Incident Responder

1 hour, 23 minutes ago
Full-time
Senior
Cybersecurity
LastPass

LastPass

LastPass, a product of LogMeIn, Inc., is a leading password and identity management solution provider with over 33 million users worldwide. From personal password management to enterprise solutions, LastPass offers convenient and secure ways to organiz...

IT Services
251-1K
Founded 2008
$30M raised

Description

  • Own security incidents end to end, from validating MSSP escalations through containment, eradication, and recovery.
  • Conduct proactive threat hunts across cloud and endpoint telemetry and convert findings into durable detections.
  • Build and tune detection content in Microsoft Sentinel and the broader cloud security stack.
  • Develop enrichment and response workflows that reduce manual effort and improve response speed.
  • Apply AI-assisted approaches to triage, investigation, detection authoring, and automation.
  • Analyze logs and telemetry from cloud, identity, endpoint, and network sources to reconstruct attacker activity.
  • Document investigations thoroughly with actions, evidence, timelines, and conclusions.
  • Manage the MSSP relationship by providing feedback, tuning alert thresholds, and supporting lessons-learned reviews.
  • Partner with Detection Engineering and the broader Security Intelligence & Response team on investigations and detections.

Requirements

  • Proven experience in incident response and security operations in cloud-native environments, with hands-on depth in Azure and AWS.
  • Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering.
  • Proven experience working with an MSSP, including managing escalations and providing quality feedback.
  • Proven experience conducting threat hunts and building automation for security operations, including SOAR playbooks, scripting, and enrichment workflows.
  • Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK.
  • Solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID.
  • Strong communication skills with both technical and non-technical stakeholders and sound judgment under pressure.
  • Ability to operate effectively both independently and as part of a collaborative team.
  • Familiarity with the Intelligence-Driven Incident Response approach is preferred.
  • Experience interpreting network traffic and performing packet captures using tcpdump or Wireshark is preferred.
  • Relevant certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty are preferred.

Benefits

  • US pay range of $108,400 to $122,000 USD.
  • Remote-first culture with short-term or remote-centric work arrangements.
  • Competitive compensation.
  • Flexible Paid Time Off, including Quarterly Self-Care Days and Volunteer Days.
  • Parental leave.
  • Comprehensive health coverage, including dependents.
  • Home office setup support and a remote work stipend.
  • Continuous learning and development opportunities, including an annual learning stipend.
  • Employee Assistance Program and peer-to-peer recognition through Motivosity.
  • LastPass Families free account for up to 5 members.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Insider Threat Technical Lead

9th Way Insignia 51-250 Internet Software & Services

9th Way Insignia is seeking a remote Insider Threat Technical Lead to support USPTO’s established insider-risk program by leading Microsoft security tooling, analytics, and stakeholder guidance.

Cybersecurity JSON Penetration Testing SIEM Splunk YAML
1 hour, 23 minutes ago

Risk Analyst (SQL), Card Payment Fraud

Binance 5K-10K Capital Markets

Binance is hiring a Fraud Risk Analyst, Card Payment to protect its card issuing business by monitoring and reducing real-time fraud losses across the card payments lifecycle.

Feature Engineering Machine Learning SQL
1 day, 1 hour ago

Cyber Security Operations Specialist Tier 3

D2 Technical Services 11-50 IT services and consulting

D2 Technical Services is hiring a CSOC Tier 3 Cybersecurity Incident Responder to support incident response operations protecting critical infrastructure under an active TS/SCI clearance.

Cybersecurity
2 days ago

Intelligence Analyst

ZeroFox 251-1K Internet Software & Services

ZeroFox is hiring an intelligence analyst for its ZTAC team to turn noisy online activity into actionable threat intelligence across physical, cyber, geopolitical, and reputational risk.

CRM Cybersecurity
2 days, 1 hour ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers