Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
NorthMark Strategies

NorthMark Strategies

via LinkedIn

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

Incident Response Engineer

Irving, TX
Full-time
Posted 6/23/2026
Verified Source
Key Skills:
Incident Response
MITRE ATT&CK Detection Engineering
SOAR Automation
CrowdStrike Falcon
Microsoft Security Ecosystem

Compensation

Salary Range

$85K - 130K a year

Responsibilities

Lead and execute end-to-end incident response lifecycle, leveraging AI and automation to improve detection and containment across enterprise and cloud environments.

Requirements

Requires 6+ years incident response experience, strong Microsoft Security skills, AI/automation integration, KQL proficiency, leadership ability, and relevant cybersecurity certifications.

Full Description

Cyber Defense - Incident Responder About NorthMark Strategies NorthMark Strategies is a multi-strategy investment advisory firm that provides strategic advice, asset management, and value-added professional services to investors, investment managers, and privately owned operating companies around the world. Our company’s mission is to integrate world class investments, operational excellence, and exceptional talent. Our values are Integrity, Ability, and Energy, and the company aims to hire individuals who possess those qualities. Our company offers a dynamic environment where individuals have the freedom to lead companies toward bold achievements by embracing innovation, leveraging technology, and fostering differentiated business strategies. We provide individuals with the opportunity to extend beyond boundaries and be in an optimal position to unlock exceptional value and drive unprecedented growth. About the Role Cyber Defense is responsible for operating and continuously advancing a cloud-first, intelligence-driven cybersecurity program. As a Cyber Incident Responder, you will report to the Manager of Cyber Defense Operations and play a critical role in protecting the organization by leading and executing incident response across enterprise and cloud environments. This role is responsible for the end-to-end execution of the Incident Response lifecycle, leveraging AI-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment. You will operate as both a hands-on technical responder and incident leader, driving rapid mitigation actions while improving detection fidelity, response speed, and operational efficiency. Responsibilities Include, but Are Not Limited to: • Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts and driving containment, eradication, and recovery actions • Execute the full Incident Response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain • Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain to guide investigations and response strategies • Lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated • Utilize AI-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue • Drive the adoption of AI-based correlation and context aggregation across SIEM/XDR, case management, and threat intelligence sources • Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments • Perform host forensics, log analysis, and malware triage to determine scope, impact, and persistence mechanisms • Drive operational efficiency by reducing manual touchpoints and enabling automated containment and remediation actions • Provide technical leadership and mentorship to junior and mid-level analysts, elevating team capability and consistency • Collaborate with IT, Engineering, Legal, HR, and business stakeholders during investigations and incident response activities • Serve as a key contributor across multiple concurrent initiatives, including tool enablement, process improvement, and security strategy • Deliver clear, concise, and executive-ready incident reports, including impact assessments and recommended actions • Conduct post-incident reviews and root cause analysis, driving improvements to detection, response, and prevention controls Requirements and Qualifications • 6+ years of hands-on experience in Cybersecurity Operations / Incident Response • Strong experience within Microsoft Security Ecosystem • Proven experience investigating incidents across cloud (Azure/AWS), identity, endpoint, and email platforms • Demonstrated experience integrating or leveraging AI/automation in security operations (e.g., security copilots, ML-based detections, automated triage) • Strong proficiency in KQL (Kusto Query Language) for threat hunting and investigation • Strong analytical and critical thinking skills with the ability to operate under pressure • Excellent written and verbal communication skills, including executive-level reporting • Ability to lead incidents, influence stakeholders, and drive rapid decision-making • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience) • Certified in one or more of the following: CISSP, CISM, CISA,SANS GIAC Security Certifications.

This job posting was last updated on 6/29/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt