Threat Level: green Handler on Duty: Xavier Mertens

SANS ISC: InfoSec Jobs InfoSec Jobs

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Incident Response Consultant - Proactive
Company Secureworks
Location Remote US
Preferred GIAC Certifications GCIH, GCFA
Travel 60%
Salary Not provided
Contact Name Troy M. Bettencourt
Contact Email tbettencourt/at/
Expires 2021-06-26

Job Description

Security Incident Response Consultant

Secureworks® (NASDAQ: SCWX) a global cybersecurity leader, enables our customers and partners to outpace and outmaneuver adversaries with more precision, so they can rapidly adapt and respond to market forces to meet their business needs. With a unique combination of cloud-native, SaaS security platform and intelligence-driven security solutions, informed by 20+ years of threat intelligence and research, no other security platform is grounded and informed with this much real-world experience.

We enjoy competitive compensation and benefits packages, and reward and recognize our employees for exceptional results. A constant focus on continued learning and growth keeps our team members engaged and excited about “what’s next.” We offer flexible work options when available, and emphasize the importance of work-life balance. We know that when our people are rewarded, recognized, and rejuvenated, we win as a team.

IR Consulting Group

The Security Incident Response Consultant works with clients in the growing area of cybersecurity incident response management. This role focuses on preparing clients to effectively handle cybersecurity incidents as well as occasionally providing advisory services to clients experiencing incidents. Helping clients prepare for incidents includes developing and evaluating response capabilities and plan documentation, delivering training, and conducting exercises to test response capabilities. The successful candidate will have experience in developing, managing, and operating incident response capabilities, conducting training, exercises and workshops, and will be familiar with tactics, techniques, and procedures commonly employed by and used to thwart threat actors. Familiarity with the drivers and constraints that organizations are working with and against while trying to secure their infrastructure and data is a necessity.

This position requires up to 60% travel.

This is a remote position.

Role Responsibilities:

Serve as subject matter expert in incident response capability development and improvement
Manage consulting workload, client requirements, and internal projects and tasking as assigned
Design and deliver incident response exercises to test client incident response plans; oversee the delivery of exercises by other consultants
Develop detailed incident response plans and playbooks based on client needs
Contribute to the continual improvement of services that we deliver to clients and the processes that the team utilizes to deliver them
Provide objective, actionable, and complete guidance that enables and improves our clients’ incident management capabilities
Conduct assessments of client readiness to respond to incidents, including designing and delivering incident response exercises to test client incident response capabilities; review the assessments of other consultant
Support complex incident response; review analysis and conclusions of other consultants
Document findings, develop recommendations and present both orally and in written reports
Promote Secureworks by participating in external speaking engagements, writing whitepapers and blogposts, and ensuring identification of opportunities for additional support to be provided to clients
Mentor junior staff


Minimum of 5 years of information security experience (Incident Response, Vulnerability Management, Risk and Governance, Threat Intelligence, Security Architecture, etc.)
Minimum of 5 years developing and managing incident response capabilities across multiple departments in an enterprise environment (IR Plans, Playbooks, Tabletop exercises, etc.)


Understanding of vulnerabilities and tools used to discover, analyze, and exploit vulnerabilities
Networking and system administration experience (Windows and Unix/Linux)
Experience with common computer forensic / incident response tools and processes
Operational experience with security tools (firewalls, IDS, IPS, SIEMs, etc.)
Bachelor's degree in computer science, information systems, information assurance, or equivalent work experience
Technical or professional certifications such as EnCE, CEH, GCIH, GCFA, CISA or CISSP, etc
Familiar with tactics, techniques, and procedures commonly employed by threat actors, and their motivations
Understanding of at least one framework: ISO 27001/2, FISMA, PCI, HITRUST, NIST 800-series, CoBIT, PCI, etc
International travel may be required. The candidate should possess or be able to possess a passport and be able to travel internationally
Demonstrated ability to manage all facets of a client offering, including presales, marketing, steady state maintenance and development, delivery, and post-delivery


Secureworks (A Dell Technologies Company) is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Secureworks are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Secureworks will not tolerate discrimination or harassment based on any of these characteristics. Learn more about Diversity and Inclusion at Secureworks here.

Job ID: R081756