Senior Incident Response Security Consultant, Mandiant

Unknown Company

Remotefull timePosted July 14, 2026

Job Description

<h3>Minimum qualifications:</h3><ul> <li>Bachelor's degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience.</li> <li>5 years of experience working end to end incident response investigations, analysis, or containment actions.<br></li> <li>5 years of investigative experience with network forensics, malware triage analysis, cloud forensics, or disk and memory forensics.</li> <li>5 years of experience in Linux or Unix.</li> <li>4 years of experience in automation and coding in Python.</li> <li>Ability to travel up to 30% of the time.</li> </ul><h3>Preferred qualifications:</h3><ul> <li>Certification in cloud platforms and GCFA, GCFE, GNFA, GCIA, GREM, GCIH, GX-FA, or equivalent.</li> <li>Experience in security competitions, capture the flags (CTFs) or testing platforms such as Hack the Box, TryHackMe, Overthewire, etc.</li> <li>Experience performing analysis within the cyber threat life cycle (e.g., digital forensics techniques/artifacts, malware research, and vulnerability exploitation).</li> <li>Ability to communicate investigative findings and strategies to technical staff, executive leadership, legal counsel, and internal and external clients.<br></li> <li>Excellent communication skills, with an ability to communicate findings and new initiatives to executive leaders.</li> <li>Excellent time and project management skills.<br></li> </ul><h3>About the job</h3><br><h3>Responsibilities</h3><ul> <li>Lead large, client-facing incident response engagements, examine cloud, end-point, and network-based sources of evidence.</li> <li>Recognize and codify attacker tools, tactics, and procedures (TTPs) and indicators of compromise (IOCs) that can be applied to current and future investigations.<br></li> <li>Build scripts, tools, or methodologies to enhance Mandiant’s incident investigation processes.<br></li> <li>Develop and present comprehensive and accurate reports, trainings, and presentations for both technical and executive audiences.<br></li> <li>Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.<br></li> </ul>

Apply for this job

Sign in to apply or save this job.
Applications0