Staff CSIRT Analyst
Incident ResponseSOC operationsDigital ForensicsEDRMDRSIEMAWSAzureMicrosoft 365
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff CSIRT Analyst based in United States. This is a senior cybersecurity role focused on strengthening internal security resilience and incident response capabilities. You will serve as a key escalation point for the SOC, leading the identification, triage, and investigation of complex security incidents. The role combines hands-on incident response with strategic preparedness, telemetry optimization, and cross-functional security leadership. You will work closely with engineering, product security, detection engineering, and offensive security teams to improve visibility and threat coverage. You will also lead exercises, post-incident reviews, and remediation initiatives that strengthen organizational defenses over time. Success in this role requires strong technical depth, clear executive communication, and the ability to turn complex security findings into actionable improvements. The position is fully remote and offers an opportunity to influence security practices across a growing, globally distributed organization. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff CSIRT Analyst based in United States. This is a senior cybersecurity role focused on strengthening internal security resilience and incident response capabilities. You will serve as a key escalation point for the SOC, leading the identification, triage, and investigation of complex security incidents. The role combines hands-on incident response with strategic preparedness, telemetry optimization, and cross-functional security leadership. You will work closely with engineering, product security, detection engineering, and offensive security teams to improve visibility and threat coverage. You will also lead exercises, post-incident reviews, and remediation initiatives that strengthen organizational defenses over time. Success in this role requires strong technical depth, clear executive communication, and the ability to turn complex security findings into actionable improvements. The position is fully remote and offers an opportunity to influence security practices across a growing, globally distributed organization. Accountabilities: Lead the identification, triage, validation, and investigation of security incidents across multiple telemetry sources, serving as the highest-level escalation point for the SOC. Drive organizational incident preparedness by designing and conducting practical response exercises, including tabletop scenarios and purple-team activities, to ensure teams are equipped to respond effectively. Partner with engineering, product security, and detection engineering teams to optimize telemetry sources, improve true-positive rates, reduce alert noise, and strengthen detection effectiveness. Collaborate with offensive security specialists to identify visibility gaps and improve defensive coverage against modern threat actor tactics, techniques, and procedures (TTPs). Work cross-functionally to address identified security gaps, coordinating with relevant teams to implement practical solutions rather than allowing visibility limitations to become persistent blockers. Lead post-incident reviews and translate lessons learned into clearly defined remediation initiatives, owning the resulting actions through completion and driving improvements in tooling, processes, and response capabilities. Develop and present detailed incident reports, exercise findings, and lessons learned to technical stakeholders, business leaders, and executive audiences. Create, maintain, and continuously improve incident response playbooks, system configurations, operational standards, and supporting documentation to promote scalable and consistent security practices. Requirements: Bring 8+ years of professional experience in incident response, SOC operations, digital forensics, or related DFIR disciplines, with demonstrated experience handling complex security events. Have advanced knowledge of EDR/MDR platforms, centralized logging and SIEM technologies such as ELK, and cloud security environments including AWS, Azure, and Microsoft 365. Demonstrate strong analytical and problem-solving capabilities, with the ability to identify root causes using first-principles thinking and translate findings into practical technical solutions. Have experience leading small project teams, coordinating initiatives across functions, and aligning security technologies and processes across different organizational areas. Communicate exceptionally well, with the ability to explain complex technical incidents and security findings clearly to both technical specialists and executive leadership. Be familiar with automation and SOAR platforms, as well as collaboration and documentation tools such as Confluence, Jira, and Lucidchart. Bring a proactive and forward-looking security mindset, with a commitment to building inclusive, practical, and actionable security behaviors across the organization. Benefits: $200,000–$210,000 USD compensation range, plus bonus and equity. 100% remote work environment. Generous paid time off, including vacation, sick time, and paid holidays. 12 weeks of paid parental leave. Comprehensive medical, dental, and vision benefits. 401(k) plan with a 5% employer contribution regardless of employee contribution. Life and disability insurance coverage. Stock options for all full-time employees. One-time $500 reimbursement for building or upgrading a home office. Annual education and professional development assistance. $75 USD monthly digital reimbursement. Access to BetterUp for coaching and personal and professional development. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$200K–$210K
Location
United States
Job type
Full-time
Category
Cybersecurity
Experience
8+ years
Posted
Today
Job Highlights
- $200K–$210K salary
- 8+ years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.