Incident Response Expert

Posted Yesterday
Hiring Remotely in United States
Remote
Mid level
Security • Database • Cybersecurity • Data Privacy
Elite Cyber Consulting, Incident Response and Managed Detection and Response Services. www.sygnia.co
The Role
Lead and perform end-to-end forensic investigations and incident response for complex cyberattacks. Conduct log, host, network, memory, and malware analysis; threat hunt for APTs; identify IOCs/TTPs; use and improve investigation tooling and playbooks; communicate findings and recommendations to technical and executive stakeholders.
Summary Generated by Built In
Description

About Sygnia

Sygnia is a premier cyber technology and services company providing high-impact incident response, cyber resilience consulting, and threat hunting for leading organizations across the globe. Trusted by Fortune 100 companies and government entities alike, Sygnia draws its strength from a team of elite professionals with backgrounds in military-grade cyber operations and the global cybersecurity industry.

Sygnia is rapidly expanding its presence in the United States, growing our incident response capabilities and client base across key industries. Joining now means playing a formative role in shaping our U.S. operations while benefiting from the backing and expertise of an established global leader.

The Role

We are seeking a highly skilled and motivated Incident Response Expert to join our elite global team. In this role, you will lead and participate in complex forensic investigations and incident response engagements involving sophisticated cyberattacks, ransomware events, and nation-state activity. Your expertise will play a critical role in helping Sygnia’s clients understand, contain, and recover from cyber incidents while preserving business continuity and mitigating risk.

What You’ll Do

  • Work with a team to conduct end-to-end forensic investigations, including log analysis, host and network forensics, malware triage, and memory analysis.
  • Support response efforts for major cybersecurity incidents, collaborating closely with internal and external security and IT teams.
  • Perform threat hunting activities in client environments to detect and eliminate advanced persistent threats.
  • Identify Indicators of Compromise (IOCs) and attacker Tactics, Techniques, and Procedures (TTPs) using frameworks like MITRE ATT&CK.
  • Analyze a wide variety of data sources (endpoint, network, SIEM, etc.) to build a clear picture of the attacker’s actions and impact.
  • Leverage and contribute to Sygnia’s internal investigation tools, playbooks, and threat intelligence platforms.
  • Communicate investigation results effectively to both technical stakeholders and executive leadership.
  • Develop and present high-quality technical reports, timelines, and strategic recommendations to clients.
  • Support the continuous improvement of internal methodologies, tooling, and knowledge sharing within the team.
Requirements

What We’re Looking For

  • 3+ years of hands-on experience in incident response, digital forensics, threat hunting, or cyber investigations—whether from the private sector, military, or government.
  • Deep technical understanding of operating systems (Windows, Linux, macOS), file systems, registry and memory structures, and log analysis.
  • Proficiency in network fundamentals and common protocols (DNS, HTTP/S, SMB, etc.) and network traffic analysis (e.g., PCAP review).
  • Experience with tools such as EnCase, X-Ways, FTK, Velociraptor, Splunk, or Wireshark, and EDR platforms like CrowdStrike, SentinelOne, or Microsoft Defender.
  • Competency in scripting or automation (e.g., Python, PowerShell) to support investigations.
  • Familiarity with cloud environments (AWS, Azure, GCP) and related forensic techniques is a plus.
  • Excellent written and verbal communication skills; able to clearly convey complex technical topics to diverse audiences.
  • Strong analytical thinking, attention to detail, and ability to work under pressure in time-sensitive environments.
  • Willingness to travel.

Bonus Points For

  • Industry-recognized certifications (e.g., GCFA, GCIH, GNFA, GCIA, GREM, CISSP).
  • Experience responding to ransomware, business email compromise (BEC), and advanced threat actor incidents.
  • Experience presenting findings to legal counsel, regulators, or board-level stakeholders.
  • Multilingual skills and experience in multinational or cross-cultural environments.
  • A degree in Computer Science, Information Security, or a related field; or equivalent education or training in cybersecurity

Why Sygnia

  • Be part of Sygnia’s continued growth in the U.S., with opportunities to influence how we scale our team, capabilities, and operations in a rapidly expanding market.
  • Work with some of the best minds in cybersecurity on the world’s most high-impact cases.
  • Operate in a fast-paced, elite-tier environment where your technical expertise is trusted and valued.
  • Take part in meaningful, challenging work that directly shapes the outcomes for Fortune 500 organizations.
  • Grow your career while staying hands-on in incident response and mentoring a highly capable team.

Skills Required

  • 3+ years hands-on experience in incident response, digital forensics, threat hunting, or cyber investigations
  • Deep technical understanding of Windows, Linux, and macOS internals, file systems, registry and memory structures
  • Log analysis and SIEM experience (e.g., Splunk)
  • Network fundamentals and traffic analysis experience (DNS, HTTP/S, SMB, PCAP review)
  • Experience with forensic and analysis tools (EnCase, X-Ways, FTK, Velociraptor, Wireshark)
  • Experience with EDR platforms (CrowdStrike, SentinelOne, Microsoft Defender)
  • Competency in scripting or automation (Python, PowerShell) to support investigations
  • Excellent written and verbal communication; ability to produce technical reports and present to stakeholders
  • Strong analytical thinking, attention to detail, ability to work under pressure in time-sensitive environments
  • Willingness to travel
  • Familiarity with cloud environments (AWS, Azure, GCP) and cloud forensic techniques
  • Industry-recognized certifications (GCFA, GCIH, GNFA, GCIA, GREM, CISSP)
  • Experience responding to ransomware, BEC, and advanced threat actor incidents
  • Experience presenting findings to legal counsel, regulators, or board-level stakeholders
  • Degree in Computer Science, Information Security, or related field (or equivalent training)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
New York, New York
264 Employees
Year Founded: 2015

What We Do

Sygnia is a cyber technology and services company, providing high-end consulting and incident response support for organizations worldwide. Sygnia works with companies to proactively build their cyber resilience and to respond and defeat attacks within their networks. It is the trusted advisor and cyber security service provider of IT and security teams, senior managements and boards of leading organizations worldwide, including Fortune 100 companies. The company draws on top talent from the ranks of elite military technology units and from across the cyber industry. It applies technological supremacy, digital combat experience, data analytics and a business-driven mindset to cyber, to deliver military grade security to business. Sygnia was launched with Team8 group, supported by leading investors and design partners, including Microsoft, Cisco, Qualcomm, Intel, Bessemer, Innovation Endeavors, and Temasek. Since October 2018, Sygnia is a Team8 and a Temasek International company.

Similar Jobs

FloQast Logo FloQast

Account Executive

Artificial Intelligence • Fintech • Software
In-Office or Remote
San Francisco, CA, USA
800 Employees
120K-180K Annually

Toast Logo Toast

Bilingual Hybrid Development Representative (Thai)

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
United States
5000 Employees
75K-120K Annually

LeafLink Logo LeafLink

Senior BSA/AML Analyst

Cannabis • eCommerce • Enterprise Web • Logistics • Payments • Software • Database
Easy Apply
Remote
United States
190 Employees
65K-70K Annually

GitLab Logo GitLab

Senior Solutions Architect

Cloud • Security • Software • Cybersecurity • Automation
Easy Apply
Remote
3 Locations
2500 Employees
137K-231K Annually

Similar Companies Hiring

Caliola Engineering Thumbnail
Software • Machine Learning • Hardware • Defense • Data Privacy • App development • Aerospace
Colorado Springs, CO
68 Employees
Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account