Today's threatscape is relentless. So are we. At Cyderes, we build practical Identity & Access Management (IAM), Exposure Management, and risk programs, helping organizations stop active threats fast with Managed Detection & Response (MDR) that integrates with existing tools. Powering it all is Meridian, our entity fabric that connects identities, assets, and access into one trusted reality. Augmented by AI and driven by experienced operators, our tireless global team arms organizations with the people, platforms, and perspectives they need to conquer whatever tomorrow throws their way.
About the Role:
The Principal Incident Response Consultant will respond to our customer’s major information security incidents, as the lead responder or incident handler. Drawing additional resources from our technical consulting teams, the Principal will build and lead teams for the purpose of responding to and remediating active client threats. As a primary interface to customers in crisis, the Principal will have excellent communication and organizational skills, ensuring the efficient and smooth handling of incidents. The Principal will be highly skilled in collaboration.
Responsibilities
Act as a lead responder on high profile and sensitive customer engagements.
Performing incident triage, to include determining scope, urgency, and potential impact, identifying the specific vulnerability, and making recommendations that enable expeditious remediation
Be involved in the full incident response lifecycle, from preparation for information security incidents, through detecting, managing, and resolving ongoing incidents, and finally reporting on those incidents and identifying improvements and lessons learned.
Collect, triage, and analyze forensic artifacts from client networks or devices in support of incident response investigations
Utilize various EDRs or log collection platforms to conduct large-scale investigations and examine endpoint and network-based sources of evidence.
Communicate with customer in a clear and precise manner throughout all phases of an incident, including verbal and written reports.
Assist with developing, operating, and continuously improving the Cyderes Incident Response services.
Train, develop, coach, and supervise junior and ad-hoc responders.
Requirements
Minimum of 5 years of experience in professional services or information security field with at least 3 of those years in Incident Response
Holds an industry accepted certification validating digital forensics or incident response capabilities: GCIH, GCFA, GCFE, CFCE, GREM, EnCE, CCE, or similar
Experience communicating complex technical topics to both technical and non-technical audiences
Experience coordinating an incident and/or leading a team during an incident
Experience investigating Windows, Linux, MacOS, and cloud environments
Demonstrated experience and competence in endpoint forensics, memory forensics, network forensics, and malware analysis, with specialized knowledge in at least one of those fields using tools such as Axiom, FTK, X-Ways, etc.
Experience identifying indicators of compromise and threat actor activity using a hypothesis-driven approach to uncover connections and correlations in data
Applied knowledge of the Incident Response Lifecycle, the Cyber Kill Chain, and the MITRE ATT&CK Framework.
Strong client facing communication (report issues to customer in a timely manner, demonstrate expertise of the overall business unit and command of the incident, develop presentations to highlight results and solutions, etc.)
Bachelor’s degree in relevant discipline
Experience working with network and security technologies to include Elasticsearch, data analytic platforms, endpoint tools, network technologies, and SIEMs
Proficiency with common programming or scripting languages such as Python and PowerShell
Ability to preserve host-based and network evidence in an industry accepted and forensically sound manner
Experience with project management to bring about the successful completion of specific project goals and objectives
Ability to learn new technology and concepts quickly
Effective in collaboration with teams in remote locations
Certifications such as CISSP, OSCP, ITIL, COBiT, or SABSA
Working knowledge of NIST SP800-61r2 and ISO 27035
Knowledge of ISO information security standard families, particularly ISO 27001 and 27002
The following will be considered an asset:
WHY CYDERES?
Benefits that go beyond the basics, we support our people so they can do their best work.
✔ Medical Insurance - Employee + dependents covered
✔ Life Insurance - Protection for what matters most
✔ Retirement Match Program - We invest in your future
✔ Hybrid Work Model - 2–3 days in office
✔ Maternity & Paternity Leave - Time for the moments that matter
✔ Paid Time Off - PTO + sick & casual leave
✔ Bereavement & Volunteer Time - Give back to your community
✔ Professional Development - Reimbursement program
✔ LinkedIn L&D Platform - Thousands of courses at your fingertips
✔ Mobile Phone Reimbursement - Stay connected, on us
Skills Required
- At least 5 years of experience in professional services or information security, including at least 3 years in incident response.
- Industry-recognized digital forensics or incident response certification such as GCIH, GCFA, GCFE, CFCE, GREM, EnCE, CCE, or similar.
- Experience communicating complex technical topics to technical and non-technical audiences.
- Experience coordinating incidents or leading incident response teams.
- Experience investigating Windows, Linux, macOS, and cloud environments.
- Competence in endpoint, memory, network, and malware forensics, with specialized expertise in at least one area.
- Experience using forensic tools such as Axiom, FTK, or X-Ways.
- Experience identifying indicators of compromise and threat actor activity using hypothesis-driven analysis.
- Applied knowledge of the Incident Response Lifecycle, Cyber Kill Chain, and MITRE ATT&CK Framework.
- Strong client-facing communication and presentation skills.
- Bachelor's degree in a relevant discipline.
- Experience with Elasticsearch, data analytics platforms, endpoint tools, network technologies, and SIEMs.
- Proficiency with programming or scripting languages such as Python and PowerShell.
- Ability to preserve host-based and network evidence in an industry-accepted, forensically sound manner.
- Experience with project management and successful completion of project goals.
- Ability to learn new technologies and concepts quickly.
- Ability to collaborate effectively with teams in remote locations.
- CISSP, OSCP, ITIL, COBIT, or SABSA certification.
- Working knowledge of NIST SP 800-61r2 and ISO 27035.
- Knowledge of ISO 27001 and ISO 27002 information security standards.
What We Do
Cyderes is a global cybersecurity partner built for today’s relentless threatscape. We specialize in identity-centric security, managed detection and response, and cloud defense—powered by AI and driven by expert operators. Our mission: arm organizations with the people, platforms, and perspective to "be everyday ready.”
.png)







