SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff CSIRT Analyst

Huntress - Remote - Remote - posted 2026-09-16

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 200,000 - 210,000 / annual

Huntress, founded in 2015 by former NSA cyber operators, is a remote-first cybersecurity company protecting 5M+ endpoints and 15M+ identities worldwide. The company operates a 24/7 human-led Security Operations Center (SOC) and builds enterprise-grade security technology accessible to businesses of all sizes. As a Staff CSIRT Analyst, you will serve as the cornerstone of Huntress' internal security resilience and the primary escalation point from the SOC. You will own the end-to-end incident response lifecycle, strategizing with leaders across multiple functions to identify work streams, guide teams, determine key milestones, and proactively anticipate blockers. Key responsibilities include: - Leading identification, triage, and validation of security incidents through various telemetry sources, acting as the ultimate escalation point for the SOC - Driving organizational incident readiness by designing and executing practical response exercises (tabletops and purple teaming) - Partnering with engineering, product security, and detection engineering teams to tune telemetry sources for high true-positive rates - Collaborating with the Offensive Security team to identify visibility gaps and ensure coverage against modern threat actor TTPs - Leading cross-functional Post-Incident Reviews (PIRs) to extract lessons learned and own remediation task lifecycles - Developing and presenting comprehensive reports and lessons learned to stakeholders at all levels - Creating and maintaining playbooks, system configurations, and incident response standards You will work in a 100% remote environment with a team committed to making meaningful security impact. The role reports to the Director of Product Security and Incident Response. Requirements: - 8+ years of experience in Incident Response, SOC Operations, or Digital Forensics (DFIR) - Advanced knowledge of EDR/MDR platforms, log aggregation (SIEM/ELK), and cloud security environments (AWS/Azure/M365) - Proven ability to articulate root causes of complex problems using first principles and translate insights into technical solutions - Experience leading small project teams and aligning tech stacks across functions - Exceptional ability to convey complex technical incident details to both technical teams and executive leadership - Familiarity with automation/SOAR platforms and documentation tools (Confluence, Jira, Lucid Chart) - Proactive, forward-thinking approach to security with passion for building security culture through inclusive and actionable behaviors

Similar roles