I'm currently recruiting for a Blue Team / Incident Response Lead to join a growing cybersecurity team supporting a large-scale enterprise environment.
This is a hands‑on leadership role focused on leading high‑severity cyber incidents, driving incident response strategy, and improving enterprise detection and response capabilities.
What you’ll be doing:
- Lead high‑severity security incidents from investigation through containment and remediation.
- Conduct advanced investigations across cloud, identity, endpoint, network, SaaS, and hybrid environments.
- Develop and improve incident response playbooks, tabletop exercises, and operational readiness.
- Partner with security engineering teams to enhance SOAR automation, AI‑assisted response workflows, and security operations.
- Collaborate with infrastructure, cloud, and identity teams to strengthen enterprise security and response capabilities.
- Drive continuous improvement through post‑incident reviews, metrics, and threat‑informed security enhancements.
What we’re looking for:
- 6+ years of Incident Response, Blue Team, or Security Operations experience.
- Experience serving as an incident lead or escalation point for complex security events.
- Strong knowledge of cloud security, identity‑based threats, MITRE ATT&CK, and hybrid environments.
- Experience with SOAR, security automation, and modern detection and response platforms.
- Exposure to AI‑enabled security operations is a plus.