American Cyber Logo

American Cyber

Incident Response Engineer

Posted 9 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Conduct digital forensic analysis and incident response investigations across endpoints, servers, networks, mobile devices, and cloud environments. Preserve evidence and maintain chain of custody, identify root causes and attacker activity, analyze malware and artifacts, and produce defensible reports for technical, executive, and legal audiences. Collaborate with SOC and threat intelligence teams, support litigation readiness, improve forensic processes and playbooks, and translate lessons learned into security guidance.
The summary above was generated by AI
## About American Cyber American Cyber partners with organizations to strengthen their security posture through modern cybersecurity solutions and services. We help our clients reduce risk, improve operational resilience, and enable secure, scalable growth. Our mission is to build resilient and compliant cybersecurity programs for our customers. ## Role Summary American Cyber is seeking a detail-oriented Incident Response Engineer / Digital Forensics Analyst (Independent Contractor – 1099) to support cybersecurity investigations and incident response efforts. In this contract role, you will conduct forensic analysis, preserve digital evidence, and deliver clear, defensible findings that support security, legal, and compliance needs. You will work closely with incident response, SOC, and threat intelligence stakeholders to investigate incidents, identify root causes, and improve investigative readiness. ## Location * Remote (U.S.-based preferred) * United States ## What You’ll Do * Conduct forensic analysis of digital evidence across endpoints, servers, network traffic, mobile devices, and cloud environments * Collect, preserve, and document evidence using industry best practices and legal standards, maintaining proper chain of custody * Support incident response by performing root cause analysis, identifying Indicators of Compromise (IOCs), and mapping adversary TTPs * Analyze logs, malware samples, memory artifacts, and network data to reconstruct timelines and attacker activity * Produce clear, detailed, and defensible forensic reports for technical, executive, and legal audiences * Provide expert support for internal investigations and litigation readiness; participate in testimony or proceedings when required * Collaborate with SOC, threat intelligence, and vulnerability management teams to strengthen detection, response, and prevention capabilities * Stay current on emerging threats, forensic methodologies, and tooling; recommend improvements to investigative workflows * Contribute to the development and continuous improvement of forensic processes, procedures, documentation, and incident response playbooks * Support security awareness and readiness initiatives by translating lessons learned into actionable guidance ## Required Qualifications * Bachelor’s degree in Computer Science, Information Security, Digital Forensics, or a related field (or equivalent practical experience) * 2–5 years of experience in digital forensics, incident response, or cybersecurity investigations * Strong understanding of Windows, Linux, and macOS operating systems; file systems; and common network protocols * Hands-on experience with forensic tools such as EnCase, FTK, X-Ways, Cellebrite, Magnet AXIOM, Volatility, or similar platforms * Familiarity with SIEM platforms, intrusion detection systems, and endpoint detection and response (EDR) solutions * Working knowledge of evidence handling procedures, chain of custody requirements, and relevant legal/compliance considerations * Strong analytical and problem-solving skills with high attention to detail * Excellent written and verbal communication skills, including the ability to present findings to diverse audiences ## Preferred Qualifications * Industry certifications such as GCFA, GCFE, CHFI, EnCE, CFCE, or CCE * Experience supporting litigation, law enforcement investigations, or regulatory compliance matters * Familiarity with scripting/automation (Python, PowerShell, Bash) to streamline forensic tasks * Experience with cloud and SaaS investigations (AWS, Azure, Google Cloud, and common SaaS platforms) * Knowledge of the MITRE ATT&CK framework and common threat actor tactics and techniques ## Engagement Terms (1099 Contractor) * This role is structured as an independent contractor (1099) engagement and does not constitute an employment relationship * You retain discretion over the manner and means of performing services, consistent with agreed deliverables, timelines, and performance expectations * Compensation structure (hourly and/or project-based) will be defined in a separate agreement * Contractor is responsible for applicable taxes, insurance, and business expenses unless otherwise specified ## Performance Expectations * Timely, accurate forensic analysis that supports incident response and investigative objectives * Proper handling, documentation, and preservation of evidence in accordance with legal standards and chain of custody requirements * Delivery of clear, defensible reporting suitable for technical, executive, and legal stakeholders * Effective collaboration with internal security and response teams in a distributed environment * Continuous improvement of forensic processes, investigative readiness, and incident response capabilities

Similar Jobs

Yesterday
Remote
United States
108K-130K Annually
Senior level
108K-130K Annually
Senior level
Information Technology
Lead end-to-end security incident investigations, including MSSP escalations, containment, eradication, and recovery. Conduct threat hunts across cloud and endpoint telemetry, build and tune Microsoft Sentinel detections, and develop SOAR, scripting, enrichment, and response workflows. Analyze cloud, identity, endpoint, and network data to reconstruct attacks, document investigations, strengthen MSSP performance, and apply AI-assisted security operations responsibly.
Top Skills: Active DirectoryAWSAzureCloud SecurityEntra IdMicrosoft SentinelMitre Att&CkScriptingSIEMSoarTcpdumpWireshark
Senior level
Software
Optimize Microsoft security operations by tuning Sentinel detections, reducing false positives, designing alert and incident-response automation, integrating Defender products and third-party telemetry, improving SOC workflows, and developing investigation playbooks, runbooks, and documentation. This hands-on 3–4 month contract requires strong Sentinel and Defender expertise, advanced KQL, Logic Apps, SOAR automation, SIEM engineering, and security operations optimization experience.
Top Skills: DlpEntra IdItsm PlatformsKusto Query Language (Kql)Microsoft Defender For Cloud AppsMicrosoft Defender For EndpointMicrosoft Defender For IdentityMicrosoft Defender XdrMicrosoft Logic AppsMicrosoft SentinelPurviewSIEMSoarZscaler
24 Days Ago
Remote or Hybrid
220K-280K Annually
Senior level
220K-280K Annually
Senior level
Healthtech • Social Impact • Software
Lead and execute Grow Therapy's multi-year Security Engineering roadmap. Build secure-by-default infrastructure (auth, authZ, logging, egress), drive data security and systematic data tagging, develop org-wide security scorecards, enable automated least-privilege and vulnerability management, and influence AI-native security and security culture across product, platform, and compliance teams.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account