Cyber Incident Responder

Other Jobs To Apply

Impact: This role leads high-severity incident response for client environments, reducing client downtime, containing ransomware and hands-on-keyboard intrusions, coordinating recovery resources across MSP teams, and maintaining clear, calm, executive-ready client communications during active incidents.

Position Summary:

The Cyber Incident Responder is a senior technical role within the Security Operations Center responsible for leading response to confirmed or suspected cyber incidents across client environments. The role combines deep incident response expertise with practical leadership: directing technical containment, coordinating resources across SOC, service desk, infrastructure, cloud, networking, compliance, account management, and client leadership teams, and serving as a trusted communicator during high-pressure events.

This position is hands-on and client-facing. The responder is expected to investigate endpoint, identity, cloud, email, network, and SaaS activity; determine scope and impact; recommend and execute containment and eradication steps; and translate technical findings into clear decisions, risks, and next steps for clients and internal stakeholders

The role also improves SOC maturity by mentoring analysts, refining incident response playbooks, leading post-incident reviews, supporting tabletop exercises, and driving measurable improvements in detection, response, documentation, and recovery readiness.

Key Responsibilities/ Duties:

  • Lead end-to-end incident response for high-severity and complex incidents, including triage, validation, scoping, containment, eradication, recovery support, and post-incident review.
    • Serve as technical incident lead and primary coordination point during major incidents, establishing response priorities, assigning actions, tracking decisions, and maintaining momentum across internal MSP/MSSP teams and client stakeholders
  • Conduct in-depth investigations of ransomware, business email compromise, credential compromise, endpoint malware, lateral movement, persistence, suspicious administrative activity, cloud compromise, and data exposure scenarios.
  • Analyze telemetry from EDR/XDR, SIEM, identity providers, email security platforms, firewalls, cloud platforms, vulnerability tooling, remote management tools, and ticketing systems to determine root cause, timeline, blast radius, and recommended response actions.
  • Develop, execute, and/or coordinate containment strategies such as host isolation, account disablement, token/session revocation, conditional access changes, firewall blocks, policy changes, IOC sweeps, and coordination of backup/recovery activities.
  • Coordinate evidence preservation and documentation, including collection of logs, timelines, artifacts, screenshots, containment actions, chain-of-custody notes when needed, and incident decision records.
  • Communicate incident status, risk, impact, and next steps clearly to technical and non-technical audiences, including client IT teams, client executives, internal leadership, account teams, legal/compliance stakeholders, and third-party partners.
  • Prepare concise client-facing incident updates, executive summaries, post-incident reports, root cause summaries, corrective action plans, and lessons-learned documentation.
  • Mentor Tier 1/Tier 2 SOC analysts and other technical teams on investigation methodology, escalation quality, containment standards, incident communications, and documentation expectations.
  • Maintain and improve incident response playbooks, escalation procedures, severity models, incident templates, customer communication standards, and internal handoff processes.
  • Support proactive threat hunting and detection engineering by converting incident learnings into improved SIEM queries, EDR detections, alert tuning, and response automation opportunities.
  • Participate in the on-call rotation and support 24/7 incident response operations for urgent or critical-impact incidents.
  • Contribute to security program maturity through tabletop exercises, operational readiness reviews, knowledge base articles, process improvements, and cross-department training.
  • Perform other duties as assigned, including support for peak workloads, coverage needs, audits, and special security initiatives.

Knowledge, Skills, Abilities, and Behaviors:
  • Advanced knowledge of incident response lifecycle activities, including detection, analysis, containment, eradication, recovery, and post-incident improvement.
  • Strong technical investigation skills across Windows, macOS, Linux, Microsoft 365 / Entra ID, Azure, AWS or other cloud platforms, endpoint protection, network security, email security, and common MSP tooling.
  • Experience with EDR/XDR and SIEM platforms such as SentinelOne, CrowdStrike, Microsoft Defender, Elastic/ELK, or comparable technologies.
  • Ability to identify attack vectors, persistence mechanisms, credential abuse, lateral movement, privilege escalation, data staging/exfiltration indicators, and common ransomware tradecraft.
  • Working knowledge of relevant frameworks and models such as NIST CSF, NIST SP 800-61, MITRE ATT&CK, CIS Controls, and cyber insurance or regulatory reporting considerations.
  • Demonstrated leadership under pressure, with the ability to make risk-informed decisions, prioritize competing tasks, and coordinate technical and non-technical resources without creating unnecessary confusion or delay.
  • Excellent customer communication skills, including the ability to explain incident facts, uncertainty, business risk, containment options, and recovery dependencies in plain language.
  • Strong written documentation skills, including executive summaries, technical timelines, incident action plans, investigation notes, and corrective action recommendations.
  • High degree of professionalism, discretion, integrity, and sound judgment when handling sensitive client data and high-impact security events.
  • Continuous improvement mindset with willingness to mentor others, improve process quality, automate repeatable work, and strengthen SOC operational maturity.

Education/ Experience:
  • 4+ years of cybersecurity experience, including SOC operations, threat hunting, detection engineering, or closely related defensive security functions.
  • 2+ years of experience leading or coordinating incident response activities during high-priority incidents, preferably in an MSP, MSSP, consulting, or multi-client environment.
  • Demonstrated experience communicating with customers, executives, technical teams, and cross-functional stakeholders during active incidents.
  • Hands-on experience with endpoint, identity, cloud, email, and network investigations; ability to work directly in tools rather than only delegating technical analysis.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience preferred.

Certifications:
  • GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), CISSP, CySA+, Microsoft SC-200, or equivalent certifications preferred.
  • Offensive security or cloud-specific certifications such as OSCP, PNPT, Microsoft Certified: Cybersecurity Architect, or comparable credentials are a plus.

Physical Demands:

Sedentary Work - Exerts up to 10 pounds of force occasionally, a negligible amount of force frequently, and/or constantly having to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time.

Disclaimer:

The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

Meriplex Communications and Meriplex Solutions are Equal Employment Opportunity Employers. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Back to blog

Other Jobs To Apply

QA Software

Remote Long-Term Care Pharmacist Reviewer

Amazon Flex

Remote Policy Leader – Health Regulation & Public Safety

Sr. IT Manager - Supply Chain

Online Encoder Jobs - Flexible Work-from-Home Opportunities

Chief Medical Officer - UCS Clinical Assessment Review Expert

GENERAL MANAGER - Capital One Lounge, JFK

Senior Client Services Specialist, EOR Operations - EMEA

Warehouse Associate PT

Amazon Customer Service - Work From Home $16-$35/hr

Immediate Hire – Remote Job Open | No Experience Required | Start ASAP

Remote Amazon Expert

Customer Service/Sales

Summer Agriculture / Farm Worker, Entry Level (No Experience Needed)

Forensic Technician: Lab Toxicology Unit

General Warehouse Associate - Loader

Senior GIS Developer: React

Warehouse Associate - PT & FT available

Robotics - Software Development Engineer

Clinical Review Nurse I/II/Sr/Lead

Busser

Cashier - Late Night Shift

Remote Clinical Therapist - Flexible Hours & Team Support

Customer Service Representative – Hotel Reservations (Remote)

Business Banking Senior Relationship Manager I - New York City, NY

Remote Pharmacy Technician Clinical Prior Authorization

Warehouse Shopper / Order Fulfillment Associate

Chat Support Agent (Remote) - Entry Level, No Degree Required

DC Operations Manager

Distribution Center Associate

Customer Service/Sales

The UPS Store NOTARY PUBLIC Full

Product Demonstrator Part Time

US_ Controller | 100% Remote – Full-Time or Part-Time|

Sr. IT Manager - Supply Chain

Warehouse Laborer-Full Time-RSCLA4378

Online Encoder Jobs - Flexible Work-from-Home Opportunities

Director, Brand Information Security Officer

Senior Outpatient Coder

Kitchen Team

Landfill Heavy Equipment Operator

Customer Service Representative Agent Work From Home - Part Time Focus Group Panelists

Car Delivery Driver

NOW HIRING: Remote Sales Associates – Entry Level | Start ASAP

Work from Home Inbound Customer Service (State of Louisiana)

Part Time Seasonal - Warehouse Associate - $14 Per Hour

Data Entry Clerk Work From Home - Part-Time Focus Group Participants (Up To $750/Week)

Strategic Production Planning Analyst - Supply Chain

Warehouse Associate PT

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...