Haystack
← Back to Jobs
Technology
VE

Lead Cyber Incident Responder (Tier 3)

VeridianTechUnited States🇺🇸United StatesPosted Sep 17, 2026

Why This Role Stands Out

Step into a pivotal role at VeridianTech where you'll lead critical cyber incident responses, developing your expertise while mentoring a talented team. This hybrid position offers significant growth potential for seasoned professionals who excel at driving complex investigations and ensuring robust security for a reputable technology leader. Apply today to make a substantial impact and advance your cybersecurity career.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday
Case ManagementContinuous ImprovementProcess ImprovementStakeholder ManagementTriage

Job Description

Lead Cyber Incident Responder (Tier 3)

Remote (candidates must be located in either NC, SC, MA, PA, ME, IL)

Contract to Hire(USC)

Role Purpose

The Lead Cyber Incident Responder (T3) provides expert leadership during security incidents,

driving rapid detection, triage, containment, and eradication activities. The role maintains

operational readiness of response capabilities, mentors responders, and ensures clear,

confident communication across technical and business stakeholders. This individual acts as

the escalation point for complex incidents and sets the standard for investigative quality, rhythm,

and discipline.

Core Responsibilities

  1. Incident Detection, Triage, and Response

Lead and coordinate security incident response operations end-to-end, from initial alert triage

through closure.

Maintain situational awareness for any potential or incoming incidents, including the report

cyber incident distro, identifying and escalating any potential incident as swiftly as possible,

inline with documented processes and procedures.

Validate and prioritize alerts generated by SIEM, EDR, NDR, SOAR, and threat-intel sources,

including hunting activities.

Execute deep and meaningful incident investigations, including analysis across endpoints,

servers, cloud services, and network telemetry.

Direct containment actions: host isolation, account disablement, network blocks, identity

access revocations, emergency control changes.

Ensure eradication and recovery steps are executed cleanly, validated, and documented.

Decide if, when, and how to escalate incidents to senior management, Legal, HR, DPO, Fraud,

BCM, or third parties.

Own the investigation from initial triage through recovery by continuously identifying

investigative leads, validating hypotheses, driving evidence collection, and ensuring no

reasonable investigative avenue remains unexplored before closure.

Maintain accurate, timely, and comprehensive case documentation throughout the

  1. Document investigative actions, decisions, evidence, rationale, timelines,

containment actions, stakeholder communications, and recovery activities as work

progresses rather than retrospectively.

Identify when additional internal or external teams should be engaged and proactively

coordinate their involvement to accelerate investigation, containment, and recovery activities.

Maintain accurate incident timelines, chain-of-evidence discipline, and investigation notes

according to agreed process, standards and templates.

  1. Incident Command & Stakeholder Management

Drive the battle rhythm: situation updates, decision points, stakeholder engagement, and

evidence-based assessment of impact.

Define incident objectives, assign tasks, and ensure cross-team accountability.

Assume technical leadership for every assigned incident by directing investigative priorities,

coordinating participating teams, tracking outstanding actions, and maintaining momentum

until all response objectives have been achieved.

Communicate status and risk clearly to technical teams, senior stakeholders, and executives

when required. Technical and non-technical

Maintain operational tempo throughout the incident by regularly reassessing priorities,

identifying blockers, following up on assigned actions, and driving investigations toward

containment and recovery without unnecessary delay.

Ensure lessons-learned sessions are completed and improvement actions are logged,

tracked, and closed.

  1. Stakeholder Collaboration

Work with CTI to enrich investigations, validate IoCs, link activity to adversary behavior, and

drive hunting hypotheses.

Recommend detection improvements to TDO, signature updates, and tuning based on

incident findings.

Support tactical hunts and pivoting based on novel attacker techniques observed in incidents.

Ensure all required stakeholder notifications, approvals, and communications are initiated at

the appropriate stage of the incident in accordance with established response procedures

and regulatory requirements.

Critical celebrity vulnerability and purple teaming involvement with the ASM team

  1. Tools, Technology, and Automation

Recommend and request optimization from ACE for IR tooling: EDR, forensic toolkits, log

platforms, case management, SOAR playbooks.

Lead the development, maintenance, and continuous improvement of IR runbooks and

Identify automation opportunities to reduce manual toil and increase response speed.

Lead IR tabletop exercises, live action drills, simulations and continuous improvement efforts

(internal to IR).

Support wider tabletop exercises (Fusion Cell and ASM), simulations, and purple-team

activities to validate readiness.

  1. Governance, Reporting, and Assurance

Produce high-quality incident reports, impact analysis, and executive summaries.

Track IR metrics: MTTD, MTTA, MTTC, containment quality, repeat incident patterns, rootcause themes.

Ensure IR actions align with policy, regulatory requirements, and evidentiary standards.

Provide assurance that security controls performed as expected during incidents; identify

deviations and drive remediation.

Ensure end of shift handover is completed and distribute in a timely fashion and to a high

  1. Additional Responsibilities

Adhoc fulfillment of Audit requests driven by control testing and analysis- Limited to

SOC/monitoring and IR activities only.

Adhoc IR process improvement based on postmortem activities, either driven directly by IR or

Fusion Cell.

Demonstrate proactive ownership of the team's workload by continuously monitoring

assigned work queues, independently selecting the next highest-priority task upon

completion of current activities, and maintaining productive utilization without requiring

Demonstrate ownership, initiative, and accountability by identifying work, solving problems

proactively, escalating risks early, and maintaining high operational standards without

requiring continuous managerial oversight.

Expected Outcomes

Consistently fast, accurate, and well-coordinated incident handling.

Reduced incident impact through strong leadership and decisive containment.

Clear, timely communication that gives stakeholders confidence in the response.

Improved detection quality, fewer false positives, and stronger automation coverage.

Mature, repeatable IR processes and disciplined documentation.

Lessons-learned converted into measurable improvements across people, process, and

Leadership Responsibilities

Mentor junior responders and analysts; build IR capability and confidence across the team.

Provide coaching on investigative techniques, writing quality, containment strategy, and

stakeholder management.

Act as the escalation point for major out-of-hours incidents.

Promote a culture of readiness, professionalism, and evidence-led decision-making.

Additional Responsibilities While On-Call

When on call, the Lead Cyber Incident Responder holds additional operational leadership duties

to maintain resilience and team alignment:

  1. Participate in Stakeholder Meetings (TDO, CTI, ACE etc)

Attend daily or scheduled stakeholder meetings to review current activities, emerging threats,

and operational risks.

Provide input on ongoing investigations and ensure handover quality between shifts.

  1. Run Daily Stand-Ups

Lead the daily stand-up to align the team on active cases, priorities, risks, and planned tasks.

Establish clear ownership for investigative actions and verify progress on outstanding items.

Ensure blockers are surfaced and removed quickly.

  1. Ensure Escalation to Stakeholders Is Managed Correctly

Proactively ensure the right teams (Legal, HR, DPO, Fraud, IT Operations, Identity, Cloud,

Network, etc.) are alerted when needed.

Validate that critical issues are raised promptly and correctly with senior stakeholders.

Ensure escalation paths are followed, impact is understood, and no stakeholder is left out of

the loop during on-call shifts.

  1. Maintain Situational Awareness

Track significant alerts, ongoing incidents, and operational noise during the on-call window.

Ensure that nothing critical is missed and that any emerging pattern is handed over with

Ensure continuous on-call coverage throughout the assigned rotation. If unable to fulfill oncall responsibilities for any reason (e.g., illness, leave, personal emergency, or other

commitments), proactively arrange an appropriately qualified replacement, and ensure a

complete handover of all active incidents, ongoing activities, and operational context before

relinquishing on-call responsibilities. The assigned on-call responder remains accountable for

ensuring uninterrupted coverage until the replacement has formally assumed the role

Similar jobs