← Back to jobs

Incident Response Lead

Location
440 9th Ave, New York, NY 10001, USA
Posted
2026-08-17

Job description

Job Overview: An IR analyst L3 is responsible for the daily operations of IR alerts/tickets, triaging, investigating, and escalating security alerts and incidents, managing IR tools and services, and supporting the overall IR program. These responsibilities are designed to support the identification of and response to cyberthreats affecting B&H systems and assets in a timely manner.

Essential Responsibilities:

Monitor and respond to security events and incidents using established processes and tools

Investigate the root cause, scope, impact, and remediation of security incidents

Manage daily operations of reviewing and responding to IR alerts including but not limited to SIEM, EDR, DLP, FW, and WAF alerts.

Provide direction and guidance to incident responders and analysts

Manage daily operations responsibilities for the operations and support of IR tools and services.

Act as the Incident Lead during significant security events.

Conduct and participate in incident response training and exercises

Upkeep and development of IR documentation

Support the overall B&H IR program.

Provide monthly reporting for the IR function.

Additional Responsibilities:

Assisting with security projects, tasks, and other initiatives

Support overall IS Security initiatives.

Specific Knowledge, Skills, and Abilities:

Extensive knowledge of IT networking (TCP/IP, firewalls, IDS/IPS, routing, etc.), logging (syslog, auditd, window’s event log, etc.), security tooling (A/V, EDR, email security, vulnerability scanners, etc.), ticketing systems (JIRA, HP Service Now, remedy, etc.) and security principles (CIS top 18, NIST, incident response frameworks, etc.)

Experience with threat hunting and operating system malware analysis.

Ability to lead a collaborative team while building inter-departments support.

Excellent communication and writing skills.

Strong analytical and troubleshooting skills.

Attention to detail and curiosity to learn new skills.

Self starter and able to manage multiple competing priorities.

Experience preparing and presenting incident reports

Preferred Education, Experience and Licenses:

Minimum of 5 years of experience in IT/Cyber with at least 3 in Incident Response.

Experience leading major incident response operations and 24/7 security monitoring.

Relevant certifications, such as CompTIA Security+, CySe+, GCIH, GSOC, GMON, CEH, SSCP, or CISSP are a plus.

Original source