Source description
About the role
Role: Cybersecurity Incident Response Location: Austin or San Antonio, TX (Onsite) Position Summary Lead cybersecurity incident response across Windows and Linux environments. Perform host-based forensics, investigate security incidents, analyze threats, coordinate incident response as Incident Commander, and produce executive-level reports. Support multi-agency incident response, improve detection capabilities, and participate in 24x7 on-call operations. Must-Have Skills 5+ years of host-based forensics (Windows/Linux), including memory, disk, log, and malware analysis. Experience with NetWitness, Gravwell, Google SecOps, Corelight , and forensic telemetry. Strong incident investigation using CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete attack timelines. Experience creating detailed incident reports and executive summaries. Strong understanding of MITRE ATT&CK, adversary TTPs, intrusion kill chain, and threat hunting . Incident Commander experience leading cybersecurity incidents. Experience supporting SLTT, government, or critical infrastructure environments. Preferred Skills Threat Intelligence platforms: Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, Mandiant . Cyware CSAP for incident orchestration and workflow automation. Security certifications such as CISSP, CIH, or Security+ . Thanks & Regards Prateek Singh
More at Advanced Knowledge Tech