Cyderes (cyderes.com) Logo

Cyderes (cyderes.com)

Principal Consultant: DFIR

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
175K-190K Annually
Senior level
Remote
Hiring Remotely in United States
175K-190K Annually
Senior level
Lead customer incident response engagements, performing triage, forensic artifact analysis, threat hunting, evidence preservation, remediation guidance, and incident reporting. Investigate endpoint, network, cloud, memory, and malware evidence using EDR, SIEM, and forensic tools. Coordinate response teams, communicate with technical and non-technical stakeholders, improve incident response services, and coach junior responders.
The summary above was generated by AI
We Help the World Be Everyday Ready™

Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by experienced operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.

🏆 Great Place to Work® Certified™

About the Role:

The Principal Incident Response Consultant will respond to our customer’s major information security incidents, as the lead responder or incident handler. Drawing additional resources from our technical consulting teams, the Principal will build and lead teams for the purpose of responding to and remediating active client threats. As a primary interface to customers in crisis, the Principal will have excellent communication and organizational skills, ensuring the efficient and smooth handling of incidents. The Principal will be highly skilled in collaboration. 

 


Responsibilities

    • Act as a lead responder on high profile and sensitive customer engagements. 

    • Performing incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation 

    • Be involved in the full incident response lifecycle, from preparation for information security incidents, through detecting, managing, and resolving ongoing incidents, and finally reporting on those incidents and identifying improvements and lessons learned. 

    • Collect, triage, and analyze forensic artifacts from client networks or devices in support of incident response investigations 

    • Utilize various EDRs or log collection platforms to conduct large-scale investigations and examine endpoint and network-based sources of evidence. 

    • Communicate with customer in a clear and precise manner throughout all phases of an incident, including verbal and written reports. 

    • Assist with developing, operating, and continuously improving the Cyderes Incident Response services. 

    • Train, develop, coach, and supervise junior and ad-hoc responders. 

Requirements

    • Minimum of 5 years of experience in professional services or information security field with at least 3 of those years in Incident Response 

    • Holds an industry accepted certification validating digital forensics or incident response capabilities: GCIH, GCFA, GCFE, CFCE, GREM, EnCE, CCE, or similar  

    • Experience communicating complex technical topics to both technical and non-technical audiences 

    • Experience coordinating an incident and/or leading a team during an incident 

    • Experience investigating Windows, Linux, MacOS, and cloud environments 

    • Demonstrated experience and competence in endpoint forensics, memory forensics, network forensics, and malware analysis, with specialized knowledge in at least one of those fields using tools such as Axiom, FTK, X-Ways, etc. 

    • Experience identifying indicators of compromise and threat actor activity using a hypothesis-driven approach to uncover connections and correlations in data 

    • Applied knowledge of the Incident Response Lifecycle, the Cyber Kill Chain, and the MITRE ATT&CK Framework. 

    • Strong client facing communication (report issues to customer in a timely manner, demonstrate expertise of the overall business unit and command of the incident, develop presentations to highlight results and solutions, etc.) 

      • Bachelor’s degree in relevant discipline 

      • Experience working with network and security technologies to include Elasticsearch, data analytic platforms, endpoint tools, network technologies, and SIEMs 

      • Proficiency with common programming or scripting languages such as Python and PowerShell 

      • Ability to preserve host-based and network evidence in an industry accepted and forensically sound manner 

      • Experience with project management to bring about the successful completion of specific project goals and objectives 

      • Ability to learn new technology and concepts quickly  

      • Effective in collaboration with teams in remote locations 

      The following will be considered an asset: 

      • Certifications such as CISSP, OSCP, ITIL, COBiT, or SABSA 

      • Working knowledge of NIST SP800-61r2 and ISO 27035 

      • Knowledge of ISO information security standard families, particularly ISO 27001 and 27002 

WHY CYDERES? 

Benefits that go beyond the basics, we support our people so they can do their best work.

✔ Medical Insurance - Employee + dependents covered

✔ Life Insurance - Protection for what matters most

✔ Retirement Match Program - We invest in your future

✔ Hybrid Work Model - 2–3 days in office

✔ Maternity & Paternity Leave - Time for the moments that matter

✔ Paid Time Off - PTO + sick & casual leave

✔ Bereavement & Volunteer Time - Give back to your community

✔ Professional Development - Reimbursement program

✔ LinkedIn L&D Platform - Thousands of courses at your fingertips

✔ Mobile Phone Reimbursement - Stay connected, on us

 
Cyderes is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to race, religion, color, sex, age, disability, sexual orientation, genetic information, national origin, or veteran status.
 
Note: This job posting is intended for direct applicants only. We request that outside recruiters do not contact us regarding this position.
 
 

Similar Jobs

Yesterday
Remote
USA
122K-270K Annually
Senior level
122K-270K Annually
Senior level
Insurance
Leads digital forensics and incident response engagements, including triage, threat assessment, containment, eradication, recovery, evidence analysis, and reporting. Serves as incident commander, manages client and insurer relationships, mentors DFIR teams, develops procedures, and guides complex investigations across endpoint, network, memory, cloud, Linux, and Windows environments. Contributes to business development, cybersecurity strategy, service offerings, and post-incident improvements.
Top Skills: AccessAWSAxiomAzureBashCrowdstrikeElkEncaseExcelFtkGoGoogle Cloud PlatformLinuxMicrosoft 365Microsoft DefenderMS OfficeNist CsfPciPowerPointPowershellPythonSentineloneSiftVolatilityWindowsWordX-Ways
23 Days Ago
Remote
USA
Expert/Leader
Expert/Leader
Cybersecurity
Leads complex digital forensics and incident response engagements, including ransomware, APT, nation-state, insider threat, host and network forensics, malware triage, cloud investigations, and threat attribution. Provides technical oversight, client leadership, methodology development, mentorship, tooling improvements, pre-sales support, and external thought leadership. Participates in on-call coverage and supports high-severity incident surges.
Top Skills: Ai ToolsAWSAzureBashEdrGoGoogle WorkspaceMicrosoft 365NdrPowershellPythonSIEMVelociraptorXdr
26 Days Ago
Remote
USA
230K-300K Annually
Senior level
230K-300K Annually
Senior level
Information Technology • Software • Cybersecurity
Lead digital forensics and incident response investigations across Windows, macOS, Linux, cloud, and SaaS environments. Investigate ransomware, nation-state threats, account takeovers, identity abuse, and multi-cloud intrusions across AWS, GCP, and Azure. Analyze endpoint, network, identity, and cloud audit data while maintaining rigorous evidentiary standards. Advise on investigative methodology, threat intelligence, and incident response services, and help design LLM-based tooling to accelerate triage, timeline creation, and reporting.
Top Skills: Ai-Assisted ToolingAmazon GuarddutyAWSAzureCloudtrailEntra IdGCPLinuxLlmsmacOSMicrosoft 365Vpc Flow LogsWindows

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account