Incident Response Consultant
WHO YOU ARE
As the Incident Response Consultant, you will be the go-to expert during cybersecurity incidents. You will provide immediate support to clients, helping them contain, investigate, and recover from cyber-attacks. This role is crucial for ensuring clients can rely on us during their most critical moments. You will work with various clients, providing rapid and effective solutions to mitigate the impact of security breaches.
This position is perfect for someone with deep technical expertise and a passion for helping organizations through high-pressure situations. You must be comfortable working in an on-call capacity and available to respond to incidents quickly when needed.
RESPONSIBILITIES
- Incident Response Management: Lead technical response efforts during cyber incidents, including triaging, investigation, containment, and recovery.
- Forensic Analysis: Conduct forensic investigations to identify breach root causes and document findings. Provide strategic and tactical recommendations to enhance security posture and incident readiness, along with expert technical remediation guidance. Perform host, network, and memory forensics in on-premises and cloud environments. Analyze artifacts, including malware, threat intelligence, and SIEM data, to identify indicators of compromise and attack vectors.
- Client Communication: Serve as the primary technical contact during incidents, ensuring clear, accurate, and timely communication with clients and stakeholders.
- Real-time Threat Hunting: Engage in proactive threat hunting and identify indicators of compromise (IOCs) to prevent or minimize damage.
- Report Writing: Create comprehensive incident reports for technical and non-technical audiences, offering insights and recommendations. Develop client-facing documentation, including incident response plans, playbooks, and runbooks.
- Collaboration: Work closely with internal teams and client IT departments to ensure smooth incident handling.
- Post-Incident Review: Conduct post-incident analysis and recommend process improvements to prevent future occurrences.
QUALIFICATIONS & REQUIREMENTS
- Minimum 3 years of experience in incident response or security operations with a focus on the analysis of cyber threats and intrusions, malware analysis, or digital forensics
- Perpetual learner and self-motivator, able to work remotely with minimal supervision
- Strong verbal and written communication skills to translate technical findings into strategic and tactical recommendations to reduce cyber security risks
- Strong and practical understanding of offensive security methodologies
- Cloud incident response with AWS, Azure, and/or GCP is an asset
- Certification or hands-on working experience with the Crowdstrike Falcon platform or Microsoft security stack is an asset
- Experience with one or more commonly adopted security frameworks or standards such as ISO 27001, NIST CSF, CIS Top 20, PCI-DSS, etc.
- Industry certifications in incident handling and forensics are an asset (GIAC, GCFE, GCFA). Crowd strike certifications such as CCFA, CCFR, and CCFH are considered an asset
- Hands-on experience with digital forensics analysis tools for incident response investigations in one or more of the following areas: Disk and Memory Forensics in Windows, Linux, and/or Mac environments; Network traffic analysis; Malware analysis; Log analysis; MS Active Directory and MS Office 365; Cloud Forensics; Working experience with threat protection and detection solutions, including SIEM, XDR, EDR, NDR, IDS/IPS, is an asset
- Passion for cybersecurity and a continuous learning mindset to stay ahead of emerging threats and technologies.
- A positive, can-do, customer-focused attitude.
- Proficient with the M365 suite of products.
- Demonstrated ability to communicate effectively with team members from various disciplines, cultures, and backgrounds.
- Bonus: Fluency in additional languages enhances your ability to effectively support our international clientele.
OUR VALUES AND VISION
The DNA of Mirai Security was forged out of Vancouver’s cyber security community by members who wanted to do security better. Mirai’s founders realized the potential of their community and resolved to develop a collective with a great culture that would naturally attract like-minded cyber security professionals to work as one. Our culture is defined by our purpose, core values, and people.
We not only seek out employees but people passionate about contributing to our company culture, our growth within the industry, and the greater cyber security community. You will be a great fit for us if you share our core values of Integrity, Care, Diversity, Growth-Mindset, and Innovation. We are looking for like-minded experts to help make our clients secure!
GROW PERSONALLY AND PROFESSIONALLY
We're a remote-first company and are proud to offer competitive salaries, including merit increases as well as performance bonuses. We also offer a comprehensive benefits package (including but not limited to health, dental, and vision), continuous learning opportunities, and community networking.
At Mirai Security, we want you to be confident bringing your whole self to work—we’re proud to be an inclusive company with a diverse team and values grounded in ethics and equality.
While we thank all applicants for their interest, only shortlisted applicants will be contacted.