Sr Incident Response & Digital Fore...
Full Job Description
About the job Overview
We are seeking an experienced cybersecurity professional to take ownership of enterprise incident response, threat investigation, and digital forensics activities within a large-scale technology environment. This position plays a critical role in identifying, investigating, containing, and remediating security threats while driving continuous improvement of detection and response capabilities.
Key Responsibilities
Direct and coordinate end-to-end response efforts for cybersecurity incidents, including triage, containment, remediation, recovery, and post-incident review.
Investigate suspicious activity by analyzing security telemetry from systems such as security monitoring platforms, endpoint security solutions, network security controls, and infrastructure logs.
Conduct forensic investigations on affected devices and systems, including examination of memory, storage media, and network activity while maintaining proper evidence handling procedures.
Analyze potentially malicious files, scripts, and executables to identify indicators of compromise and support defensive actions.
Produce comprehensive investigation documentation covering root causes, business impact, attack timelines, and recommended corrective actions.
Partner with technical and non-technical stakeholders to communicate findings, response status, and risk mitigation strategies.
Lead proactive threat hunting initiatives to uncover hidden threats and reduce organizational risk exposure.
Assess existing security controls and recommend enhancements to improve detection, prevention, and response effectiveness.
Share expertise with internal teams through coaching, knowledge transfer, and incident response best practice guidance.
Maintain awareness of emerging attack techniques, threat actor behaviors, and evolving security technologies.
Required Qualifications
Degree in Computer Science, Information Security, Information Technology, or a related discipline, or equivalent professional experience.
At least 8 years of hands-on cybersecurity experience, particularly within incident response, threat investigation, detection engineering, or forensic analysis functions.
Strong practical experience with enterprise security technologies, including security monitoring platforms, endpoint protection and detection solutions, network intrusion detection/prevention systems, vulnerability assessment tools, and firewall technologies.
Advanced log investigation capabilities, including analysis of operating system, application, and network logs.
Demonstrated expertise in incident response frameworks, workflows, and operational procedures.
Experience using automation or scripting languages such as Python, PowerShell, or Bash to improve security operations efficiency.
Strong accountability, initiative, and ownership mindset.
Excellent analytical, troubleshooting, communication, and decision-making skills.
Ability to remain effective during high-severity incidents and manage multiple investigations simultaneously.
Preferred Qualifications
Industry-recognized cybersecurity certifications such as CISSP, GCIH, OSCP, CEH, or similar credentials.
Experience operating within or supporting a Security Operations Center environment, including handling escalated security cases.
Hands-on proficiency with forensic investigation platforms and malware analysis technologies.
Experience investigating security incidents involving cloud infrastructure and cloud-native services.
Familiarity with threat intelligence methodologies and adversary behavior frameworks such as MITRE ATT&CK.
Ability to work effectively in global environments with diverse stakeholders.
Company
Huxley
Huxley is an IT specialist within SThree, a global STEM workforce consultancy. Specializing in financial technology, business intelligence, and strategic transformation, Huxley advises businesses, bui...