Back to jobs

Incident Response Lead, Cyber Security

$40-80/hrRemoteFreelanceCODING

About the Role

What if your hard-won experience in SOC operations could directly strengthen how organizations detect, respond to, and contain cyber threats? We're looking for a seasoned Incident Response Lead to evaluate real-world security operations — scrutinizing detection workflows, response playbooks, and triage logic to identify what's working, what isn't, and what needs to change.

This is a fully remote, flexible contract role built for experienced security professionals who think in timelines, escalation trees, and containment logic.

  • Type: Hourly Contract
  • Location: Remote
  • Commitment: Flexible, based on project scope

What You'll Do

  • Review detection alerts, triage workflows, and escalation pathways for quality and consistency
  • Evaluate the completeness and effectiveness of incident response actions across real-world scenarios
  • Identify gaps in logging coverage, detection logic, and containment strategies
  • Summarize incident patterns, operational bottlenecks, and systemic weaknesses
  • Validate response playbooks for clarity, accuracy, and practical feasibility under pressure
  • Support recurring assessments of SOC maturity and operational readiness
  • Produce structured, analytical documentation that drives meaningful operational improvements

Who You Are

Must-Have:

  • Hands-on experience in SOC operations, incident response leadership, or cybersecurity operations
  • Strong command of detection engineering, response workflows, and incident timeline analysis
  • Ability to critically assess triage quality, escalation logic, and containment decisions
  • Clear, structured analytical writing skills — you can translate complex findings into actionable documentation

Nice to Have:

  • Familiarity with SIEM platforms (Splunk, Microsoft Sentinel, Chronicle, etc.)
  • Experience with EDR tools and cloud-native detection systems
  • Background in red team / blue team exercises or SOC maturity assessments
  • Relevant certifications such as GCIH, GCFA, CISSP, or equivalent

Why Join Us

  • Apply deep domain expertise to real, consequential security assessments
  • Fully remote and flexible — work when and where it suits you
  • Freelance autonomy with the structure of meaningful, project-based work
  • Make a direct impact on how organizations prepare for and respond to cyber threats
  • Potential for ongoing engagements and contract extension as new projects launch