Role: Incident Commander / Senior Security Incident Response Specialist (Hands-on)
Work Location: Chicago, IL/ Greenwich, CT (Hybrid)
Full Time
Work Schedule:
• Must be open to weekend shifts
• Typical rotations:
• Wednesday–Sunday, OR
• Saturday–Wednesday
• North America (EST time zone alignment required)
⸻
Location:
• Primary: Chicago, IL
• Secondary: Greenwich, Connecticut
• Must be US-based (prefer East Coast / Central)
Identify a hands-on cybersecurity professional who can lead and execute end-to-end incident response, combining:
• SOC analyst depth (L1–L3)
• Security investigation expertise
• Real-time incident command capability
This is not a managerial or leadership-only role — we need a doer who can lead from the front during incidents.
⸻
Core Responsibilities:
• Act as Incident Commander during security incidents (own response lifecycle)
• Perform hands-on investigation across:
• L1 (triage, alert validation)
• L2 (correlation, enrichment, containment support)
• L3 (deep forensic analysis, root cause, remediation guidance)
• Lead real-time incident coordination across stakeholders
• Drive incident containment, eradication, and recovery
• Conduct post-incident reviews (RCA, lessons learned)
• Work closely with SOC, engineering, and threat intelligence teams
⸻
Must-Have Skills:
• Strong SOC experience (L1–L3 exposure)
• Proven incident response leadership (not just participation)
• Hands-on with:
• SIEM tools (Splunk, QRadar, Sentinel, etc.)
• EDR/XDR platforms (CrowdStrike, Defender, etc.)
• Log analysis, threat hunting, and forensic techniques
• Ability to operate under pressure in live incidents
• Strong communication skills for incident coordination
⸻
Experience Requirements:
• 7+ years in cybersecurity / SOC / incident response
• Demonstrated experience in incident command or leading major incidents
• Stable career history:
• Minimum ~4 years tenure in recent role preferred
• Avoid frequent job hoppers
Profile We Do NOT Want:
• Pure people managers / VPs / Directors
• Candidates lacking hands-on technical depth
• Profiles with frequent job changes