Incident Response Principal Consultant in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Incident Response Principal Consultant based in United States.
This is a senior cybersecurity consulting role focused on leading complex incident response engagements for organizations facing sophisticated cyber threats. You’ll investigate major security incidents, uncover attacker activity, and help customers understand and contain the impact of breaches. The role combines technical depth across host, network, cloud, and malware forensics with strong client leadership and communication. You’ll work alongside highly skilled security professionals while engaging directly with executive stakeholders, legal counsel, regulators, and technical teams. The position also offers opportunities to develop innovative threat-hunting techniques and apply AI technologies to improve investigation workflows and decision-making. As a senior practitioner, you’ll contribute to industry thought leadership while mentoring colleagues and helping shape effective response strategies.
- Lead complex incident response engagements, coordinating investigations and guiding teams through high-priority cybersecurity incidents.
- Conduct intrusion investigations, including work performed under the direction of outside counsel, and determine the scope, impact, and nature of compromises.
- Perform host and network-based forensic analysis across Windows, macOS, and Linux environments using a range of investigative and forensic tools.
- Develop and apply advanced threat-hunting methodologies to identify malicious activity across large and complex datasets.
- Analyze network traffic, protocols, and security telemetry using technologies such as Zeek/Bro and Suricata to identify indicators of compromise and attacker behavior.
- Perform basic malware analysis and apply static and dynamic analysis techniques to understand malicious capabilities and behaviors.
- Support cloud incident response activities across environments such as AWS, Azure, and Google Cloud.
- Develop customized tactical and strategic remediation recommendations for organizations affected by targeted attacks.
- Communicate technical findings, risks, recommendations, and investigation outcomes clearly to customer executives, technical stakeholders, regulators, and legal counsel.
- Manage projects effectively in a matrixed consulting environment while coordinating internal teams and maintaining high-quality client delivery.
- Use AI technologies to enhance investigation workflows, accelerate decision-making, streamline processes, and improve business outcomes.
- Mentor colleagues, contribute to a positive team environment, and share expertise through thought leadership, technical content, presentations, and industry events.
- Bachelor’s or master’s degree in Computer Science, Computer Engineering, Mathematics, Information Security, Cybersecurity, Information Assurance, Intelligence Studies, or a related field; equivalent relevant professional experience or training may also be considered.
- Demonstrated experience in incident response, information security, digital forensics, network forensics, malware analysis, remediation, or related cybersecurity disciplines.
- Experience leading teams and managing complex engagements in a consulting or matrixed environment.
- Strong understanding of targeted attacks, including advanced persistent threats, organized cybercrime, and hacktivist activity.
- Hands-on experience with computer forensic investigation tools and methodologies for determining the extent and scope of compromise.
- Strong knowledge of network protocols, network analysis, and associated security logs, with experience using tools such as Zeek/Bro or Suricata.
- Understanding of static and dynamic malware analysis and reverse-engineering concepts.
- Knowledge of secure network architecture, network operations, and cybersecurity engineering principles.
- Experience with cloud incident response methodologies in AWS, Azure, and/or Google Cloud environments.
- Proven ability to independently complete technical tasks, manage projects, and make sound decisions in high-pressure environments.
- Excellent written and verbal communication skills, with the ability to translate complex technical findings for both executive and technical audiences.
- Demonstrated ability to communicate methodology, provide guidance, and coordinate effectively with internal and customer-facing teams.
- Experience leveraging AI technologies to improve cybersecurity decision-making, workflows, efficiency, and outcomes.
- Strong problem-solving skills, a growth mindset, and a commitment to continuously expanding technical and consulting capabilities.
- Ability to contribute as an incident response thought leader and foster a collaborative, constructive team environment.
- Ability to travel on short notice, up to approximately 30% of the time.
- Willingness and ability to meet any applicable employment screening or testing requirements.
- Base salary: $115,000–$160,000 per year for U.S. candidates, depending on experience, skills, certifications, job level, supervisory responsibilities, and location.
- Eligibility for performance-based bonuses and equity awards.
- Comprehensive health insurance and wellness benefits, including programs supporting physical and mental wellbeing.
- 401(k) benefits.
- Competitive paid time off and holidays to support time for rest and recharge.
- Paid parental and adoption leave.
- Professional development opportunities available across career levels and roles.
- Employee networks, community groups, and volunteer opportunities designed to strengthen professional and social connections.
- Remote work environment with flexibility and autonomy.
- Opportunity to work on high-impact cybersecurity investigations involving sophisticated threats and complex enterprise environments.
- Opportunities to contribute to industry thought leadership through technical publications, presentations, and security events.