Incident Response Lead
Description
We're looking for an experienced Incident Response Lead to join a financial client in NYC - someone who can take charge of active incidents and drive the response process. The role :• Leading end-to-end incident response from initial triage through to containment, eradication, and post-incident revie w• Managing and coordinating cross-functional teams during live incident s• Developing and refining IR playbooks, processes, and documentatio n• Conducting root cause analysis and translating findings into actionable improvement s• Acting as the senior escalation point for high-severity event s• Engaging with stakeholders and, where necessary, external parties such as regulators or third-party responder s What we're looking fo r:• Significant hands-on experience leading incident response in complex, enterprise environmen ts• Strong working knowledge of Splunk and/or Microsoft Sentinel for log analysis and threat detecti on• Experience with EDR tooling — CrowdStrike Falcon, SentinelOne, or Microsoft Defend er• Deep knowledge of attacker TTPs and the MITRE ATT&CK framewo rk• Ability to remain calm, decisive, and clear-headed under pressu re• Excellent communication skills — able to brief both technical teams and senior leadersh ip Show more Show less