Why This Role Stands Out
Step into a pivotal role at VeridianTech where you'll lead critical cyber incident responses, developing your expertise while mentoring a talented team. This hybrid position offers significant growth potential for seasoned professionals who excel at driving complex investigations and ensuring robust security for a reputable technology leader. Apply today to make a substantial impact and advance your cybersecurity career.
Quick Overview
Job Description
Lead Cyber Incident Responder (Tier 3)
Remote (candidates must be located in either NC, SC, MA, PA, ME, IL)
Contract to Hire(USC)
Role Purpose
The Lead Cyber Incident Responder (T3) provides expert leadership during security incidents,
driving rapid detection, triage, containment, and eradication activities. The role maintains
operational readiness of response capabilities, mentors responders, and ensures clear,
confident communication across technical and business stakeholders. This individual acts as
the escalation point for complex incidents and sets the standard for investigative quality, rhythm,
and discipline.
Core Responsibilities
- Incident Detection, Triage, and Response
Lead and coordinate security incident response operations end-to-end, from initial alert triage
through closure.
Maintain situational awareness for any potential or incoming incidents, including the report
cyber incident distro, identifying and escalating any potential incident as swiftly as possible,
inline with documented processes and procedures.
Validate and prioritize alerts generated by SIEM, EDR, NDR, SOAR, and threat-intel sources,
including hunting activities.
Execute deep and meaningful incident investigations, including analysis across endpoints,
servers, cloud services, and network telemetry.
Direct containment actions: host isolation, account disablement, network blocks, identity
access revocations, emergency control changes.
Ensure eradication and recovery steps are executed cleanly, validated, and documented.
Decide if, when, and how to escalate incidents to senior management, Legal, HR, DPO, Fraud,
BCM, or third parties.
Own the investigation from initial triage through recovery by continuously identifying
investigative leads, validating hypotheses, driving evidence collection, and ensuring no
reasonable investigative avenue remains unexplored before closure.
Maintain accurate, timely, and comprehensive case documentation throughout the
- Document investigative actions, decisions, evidence, rationale, timelines,
containment actions, stakeholder communications, and recovery activities as work
progresses rather than retrospectively.
Identify when additional internal or external teams should be engaged and proactively
coordinate their involvement to accelerate investigation, containment, and recovery activities.
Maintain accurate incident timelines, chain-of-evidence discipline, and investigation notes
according to agreed process, standards and templates.
- Incident Command & Stakeholder Management
Drive the battle rhythm: situation updates, decision points, stakeholder engagement, and
evidence-based assessment of impact.
Define incident objectives, assign tasks, and ensure cross-team accountability.
Assume technical leadership for every assigned incident by directing investigative priorities,
coordinating participating teams, tracking outstanding actions, and maintaining momentum
until all response objectives have been achieved.
Communicate status and risk clearly to technical teams, senior stakeholders, and executives
when required. Technical and non-technical
Maintain operational tempo throughout the incident by regularly reassessing priorities,
identifying blockers, following up on assigned actions, and driving investigations toward
containment and recovery without unnecessary delay.
Ensure lessons-learned sessions are completed and improvement actions are logged,
tracked, and closed.
- Stakeholder Collaboration
Work with CTI to enrich investigations, validate IoCs, link activity to adversary behavior, and
drive hunting hypotheses.
Recommend detection improvements to TDO, signature updates, and tuning based on
incident findings.
Support tactical hunts and pivoting based on novel attacker techniques observed in incidents.
Ensure all required stakeholder notifications, approvals, and communications are initiated at
the appropriate stage of the incident in accordance with established response procedures
and regulatory requirements.
Critical celebrity vulnerability and purple teaming involvement with the ASM team
- Tools, Technology, and Automation
Recommend and request optimization from ACE for IR tooling: EDR, forensic toolkits, log
platforms, case management, SOAR playbooks.
Lead the development, maintenance, and continuous improvement of IR runbooks and
Identify automation opportunities to reduce manual toil and increase response speed.
Lead IR tabletop exercises, live action drills, simulations and continuous improvement efforts
(internal to IR).
Support wider tabletop exercises (Fusion Cell and ASM), simulations, and purple-team
activities to validate readiness.
- Governance, Reporting, and Assurance
Produce high-quality incident reports, impact analysis, and executive summaries.
Track IR metrics: MTTD, MTTA, MTTC, containment quality, repeat incident patterns, rootcause themes.
Ensure IR actions align with policy, regulatory requirements, and evidentiary standards.
Provide assurance that security controls performed as expected during incidents; identify
deviations and drive remediation.
Ensure end of shift handover is completed and distribute in a timely fashion and to a high
- Additional Responsibilities
Adhoc fulfillment of Audit requests driven by control testing and analysis- Limited to
SOC/monitoring and IR activities only.
Adhoc IR process improvement based on postmortem activities, either driven directly by IR or
Fusion Cell.
Demonstrate proactive ownership of the team's workload by continuously monitoring
assigned work queues, independently selecting the next highest-priority task upon
completion of current activities, and maintaining productive utilization without requiring
Demonstrate ownership, initiative, and accountability by identifying work, solving problems
proactively, escalating risks early, and maintaining high operational standards without
requiring continuous managerial oversight.
Expected Outcomes
Consistently fast, accurate, and well-coordinated incident handling.
Reduced incident impact through strong leadership and decisive containment.
Clear, timely communication that gives stakeholders confidence in the response.
Improved detection quality, fewer false positives, and stronger automation coverage.
Mature, repeatable IR processes and disciplined documentation.
Lessons-learned converted into measurable improvements across people, process, and
Leadership Responsibilities
Mentor junior responders and analysts; build IR capability and confidence across the team.
Provide coaching on investigative techniques, writing quality, containment strategy, and
stakeholder management.
Act as the escalation point for major out-of-hours incidents.
Promote a culture of readiness, professionalism, and evidence-led decision-making.
Additional Responsibilities While On-Call
When on call, the Lead Cyber Incident Responder holds additional operational leadership duties
to maintain resilience and team alignment:
- Participate in Stakeholder Meetings (TDO, CTI, ACE etc)
Attend daily or scheduled stakeholder meetings to review current activities, emerging threats,
and operational risks.
Provide input on ongoing investigations and ensure handover quality between shifts.
- Run Daily Stand-Ups
Lead the daily stand-up to align the team on active cases, priorities, risks, and planned tasks.
Establish clear ownership for investigative actions and verify progress on outstanding items.
Ensure blockers are surfaced and removed quickly.
- Ensure Escalation to Stakeholders Is Managed Correctly
Proactively ensure the right teams (Legal, HR, DPO, Fraud, IT Operations, Identity, Cloud,
Network, etc.) are alerted when needed.
Validate that critical issues are raised promptly and correctly with senior stakeholders.
Ensure escalation paths are followed, impact is understood, and no stakeholder is left out of
the loop during on-call shifts.
- Maintain Situational Awareness
Track significant alerts, ongoing incidents, and operational noise during the on-call window.
Ensure that nothing critical is missed and that any emerging pattern is handed over with
Ensure continuous on-call coverage throughout the assigned rotation. If unable to fulfill oncall responsibilities for any reason (e.g., illness, leave, personal emergency, or other
commitments), proactively arrange an appropriately qualified replacement, and ensure a
complete handover of all active incidents, ongoing activities, and operational context before
relinquishing on-call responsibilities. The assigned on-call responder remains accountable for
ensuring uninterrupted coverage until the replacement has formally assumed the role
Similar jobs
- KP
Senior Associate, SAP Security & Controls
NewKPMG
Addison, Texas🇺🇸Hybrid22 minutes agoTechnology - KP
Senior Associate, SAP Security & Controls
NewKPMG
Chicago, Illinois🇺🇸Hybrid22 minutes agoTechnology - KP
Senior Associate, Salesforce Health Cloud & Agentforce Forward Deployed Engineer
NewKPMG
Washington, Washington DC🇺🇸$118.3k - $212.9k/yrHybrid22 minutes agoSalesforceScrumAgile+2Technology - KP
Senior Associate, SAP Security & Controls
NewKPMG
Denver, Colorado🇺🇸Hybrid22 minutes agoTechnology - KP
Senior Associate, SAP Security & Controls
NewKPMG
Atlanta, Georgia🇺🇸Hybrid22 minutes agoTechnology - LE
Senior Systems Administrator/Helpdesk Engineer
NewLeidos
Arnold, MO🇺🇸$92.3k - $166.8k/yrHybrid21 hours agoDockerAWSActive Directory+11Technology