Cyber Defense - Incident Responder

NorthMark Strategies - Dallas-Fort Worth Metroplex

Hiring: Cyber Defense - Incident Responder Company: NorthMark Strategies Location: Dallas-Fort Worth Metroplex Job Posted Time: 2026-09-17 12:33:33 Target Skills & Keywords : AWS, Azure, Root Cause Analysis, SIEM About the job Experience: •6+ years of hands-on experience in Cybersecurity Operations / Incident Response Required Skills: •This role is responsible for the end-to-end execution of the Incident Response lifecycle, leveraging AI-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment. •Operate as both a hands-on technical responder and incident leader, driving rapid mitigation actions while improving detection fidelity, response speed, and operational efficiency. •Execute the full Incident Response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain •Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain to guide investigations and response strategies •Lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated •Utilize AI-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue •Strategically drive adoption of AI-based correlation and context aggregation across SIEM/XDR, case management, and threat intelligence sources •Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments Qualifications: •Strong experience within Microsoft Security Ecosystem •Proven experience investigating incidents across cloud (Azure/AWS), identity, endpoint, and email platforms •Demonstrated experience integrating or leveraging AI/automation in security operations (e.g., security copilots, ML-based detections, automated triage) •Strong proficiency in KQL (Kusto Query Language) for threat hunting and investigation •Strong analytical and critical thinking skills with the ability to operate under pressure •Excellent written and verbal communication skills, including executive-level reporting •Demonstrated capacity to lead incidents, influence stakeholders, and drive rapid decision-making •Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience) •Certified in one or more of the following: CISSP, CISM, CISA,SANS GIAC Security Certifications. •Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future. Compensation: •Company-Paid Lunch Stipend: Lunch is provided via GrubHub Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!