Senior Incident Responder @BlackCloak
All Others
Salary $105,000 - $115..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Senior Incident Responder @BlackCloak

1mth ago - BlackCloak is hiring a remote Senior Incident Responder. πŸ’Έ Salary: $105,000 - $115,000 a year πŸ“Location: USA

Role Description

BlackCloak is seeking a seasoned and highly skilled Senior Incident Responder to join our Technical Success Team. This is a senior, client-facing individual contributor role for someone who has spent years on both sides of the problem: the technical compromise of computers, phones, and online accounts, and the financial fraud that so often follows it. In this critical role, you will serve as the primary escalation point and lead investigator for complex security events; taking ownership of the full incident response lifecycle, from initial triage and containment through eradication, recovery, and post-incident reporting.

Our clients are executives, board members, and high-profile individuals whose personal accounts and devices are targeted precisely because their corporate ones are hard to breach. When something goes wrong in a client's personal digital life, you are the person who takes the call, works the incident end to end, and stays with them until it is resolved. You will also help us get better at preventing the next one.

What You Will Do

  • Execute End-to-End Incident Response: Lead comprehensive incident handling consistent with core IR principles (NIST/SANS) from the initial client request and triage through containment, recovery, and post-incident lessons learned.
  • Investigate Complex Compromises & Targeted Attacks: Manage and remediate severe client security incidents, including but not limited to, compromised email ecosystems, SIM swap attacks, financial account takeovers, and targeted credential harvesting.
  • Device Analysis: Conduct analysis on client computers and mobile devices to assess the scope of compromise and implement effective remediation strategies.
  • Remediate Fraud & Identity Theft: Analyze and assess account activity and transaction records available to the client on their email, banking, retail, and social platforms to help establish what occurred, and support clients in their conversations with the platforms on fraud investigations, disputes, account freezes, etc. Guide identity theft victims through the remediation process - credit bureau freezes and fraud alerts, IdentityTheft.gov and law enforcement reporting - and advise clients on the activity they should watch for and report back to the team.
  • Map the Attack Chain: Map observed activity against the personal attack kill chain to identify the likely stage of an attack and the actions that break the chain, focusing on technique and exposure rather than actor attribution.
  • Provide White-Glove Client Support: Interface directly with clients and, where authorized, their families and support staff during high-stakes emergency onboardings and active incidents, providing calm, clear, and authoritative guidance while communicating complex threat assessments.
  • Participate in On-Call Rotation: Serve in an on-call and escalation rotation that requires occasional nights and weekends to address client incidents, emergency onboardings, and time-sensitive issues.
  • Lead & Mentor: Serve as the highest technical escalation point in the on-call rotation, while actively mentoring Security and Client Success team members to elevate the team's overall technical proficiency.
  • Enhance Security Posture: Oversee network vulnerability scans of client infrastructure, proactively refine internal IR playbooks, and conduct periodic post-onboarding touchpoints.

Qualifications

  • 5-8+ years of experience in a dedicated Incident Response, Digital Forensics (DFIR), or advanced cybersecurity analyst role.
  • Proven track record executing the full incident lifecycle, particularly involving personal/executive account takeovers, mobile threats, and endpoint malware.
  • Demonstrated experience investigating fraud in financial transactions, including direct coordination with banks and credit card companies.
  • Deep technical expertise conducting forensics and vulnerability management across Windows, macOS, iOS, Android, and Linux ecosystems.
  • Working command of identity theft remediation and attack kill chain models.
  • Advanced industry certifications are highly preferred (e.g., GCIH, GCFA, CISSP, OSCP, or similar); fraud and financial crime credentials such as CFE, CFCS, or CAMS are a strong plus.
  • Exceptional communication skills with the ability to translate technical jargon into actionable advice for non-technical clients.
  • College degree in an Information Technology (IT/CS/CE) discipline or equivalent real-world experience.

Requirements

  • Ability to operate highly independently.
  • Occasional nights and weekends to address emergency client incidents.

Benefits

  • 100% Remote Company, within the USA.
  • Comprehensive Medical, Dental, and Vision plans with a 100% employer-paid monthly premium option for employees & 50% employer-paid monthly premiums for dependents.
  • Health Savings Account with company contribution for eligible medical plans.
  • Flexible Vacation Plan.
  • 10 Paid Company Holidays.
  • 100% employer-paid Life, AD&D and Short- and Long-Term Disability Insurance.
  • 401k with Traditional and Roth options, including employer match.
  • Company Equity.
  • Paid Parental and Pregnancy Recovery Leave.
  • Company and team off-sites and virtual events throughout the year.
  • Home office stipend.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Incident Responder @BlackCloak
All Others
Salary $105,000 - $115..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,451+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later