SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 200,000 - 210,000 / annual
Huntress, founded in 2015 by former NSA cyber operators, is a remote-first cybersecurity company protecting 5M+ endpoints and 15M+ identities worldwide. The company operates a 24/7 human-led Security Operations Center (SOC) and builds enterprise-grade security technology accessible to businesses of all sizes.
As a Staff CSIRT Analyst, you will serve as the cornerstone of Huntress' internal security resilience and the primary escalation point from the SOC. You will own the end-to-end incident response lifecycle, strategizing with leaders across multiple functions to identify work streams, guide teams, determine key milestones, and proactively anticipate blockers.
Key responsibilities include:
- Leading identification, triage, and validation of security incidents through various telemetry sources, acting as the ultimate escalation point for the SOC
- Driving organizational incident readiness by designing and executing practical response exercises (tabletops and purple teaming)
- Partnering with engineering, product security, and detection engineering teams to tune telemetry sources for high true-positive rates
- Collaborating with the Offensive Security team to identify visibility gaps and ensure coverage against modern threat actor TTPs
- Leading cross-functional Post-Incident Reviews (PIRs) to extract lessons learned and own remediation task lifecycles
- Developing and presenting comprehensive reports and lessons learned to stakeholders at all levels
- Creating and maintaining playbooks, system configurations, and incident response standards
You will work in a 100% remote environment with a team committed to making meaningful security impact. The role reports to the Director of Product Security and Incident Response.
Requirements:
- 8+ years of experience in Incident Response, SOC Operations, or Digital Forensics (DFIR)
- Advanced knowledge of EDR/MDR platforms, log aggregation (SIEM/ELK), and cloud security environments (AWS/Azure/M365)
- Proven ability to articulate root causes of complex problems using first principles and translate insights into technical solutions
- Experience leading small project teams and aligning tech stacks across functions
- Exceptional ability to convey complex technical incident details to both technical teams and executive leadership
- Familiarity with automation/SOAR platforms and documentation tools (Confluence, Jira, Lucid Chart)
- Proactive, forward-thinking approach to security with passion for building security culture through inclusive and actionable behaviors