North Logo

North

Principal Incident Response Analyst

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in US
150K-180K Annually
Senior level
Remote
Hiring Remotely in US
150K-180K Annually
Senior level
Leads complex security incidents from detection through recovery, including triage, containment, eradication, forensics, root cause analysis, and post-incident remediation. Develops and tunes SIEM detections, conducts threat hunts, improves MITRE ATT&CK coverage, and mentors security personnel. Partners with SOC, IT, engineering, legal, compliance, and leadership during major incidents while maintaining response procedures and playbooks for a payment-processing environment.
The summary above was generated by AI

Principal Incident Response Analyst

North - Remote



The Principal Incident Response Analyst is a seasoned, deeply experienced incident response expert who runs North’s most complex security incidents from detection through recovery, without supervision.


Incident response is the primary area of expertise for this role, complemented by strong secondary expertise in detection engineering and tertiary expertise in threat hunting. The Principal Incident Response Analyst serves as the top escalation point for security incidents, sets the technical standard for how the organization investigates and contains threats, and mentors other engineers and analysts on incident handling practice. This role works closely with the SOC, IT, and engineering teams, and represents the deepest incident response expertise on the security team, operating across our payment processing environment.


 

What You'll do:


  • Incident Response
    • Serve as the principal escalation point and lead investigator for the most complex, highest-severity, and novel security incidents, running them end to end without supervision
    • Independently triage, investigate, contain, eradicate, and recover from security incidents spanning endpoint, network, cloud, identity, and application layers
    • Lead full-scope forensic investigations of compromised hosts, accounts, applications, and cloud infrastructure, and reconstruct complete attack timelines from initial access through impact
    • Translate complex investigation findings into clear narratives for engineering teams and clear executive-level narratives for leadership
    • Own and continuously evolve incident response process, documentation, and playbooks, incorporating lessons learned from real incidents
    • Lead root cause analysis and structured post-incident reviews, and drive cross-team remediation of systemic gaps
    • Serve as the senior technical lead during major incidents, coordinating across IT, legal, compliance, and executive leadership as needed
    • Provide case-level guidance and mentorship to other incident responders and SOC analysts during live incidents
    • Participate in or lead on-call rotation for critical incident response as needed
  • Detection Engineering
    • Translate incident findings and root cause analysis directly into new or improved detection logic, closing the loop between investigation and prevention
    • Write, tune, and validate detection content in the SIEM/NG-SIEM platform, focused on techniques observed in real investigations and threat hunts
    • Maintain and improve coverage and gap analysis against the MITRE ATT&CK framework, informed by incident and hunt findings
    • Review detection logic for accuracy and false-positive rate, and partner with the detection engineering team on rule quality
    • Contribute documentation of known coverage and detection gaps surfaced through incident response and hunting work
  • Threat Hunting
    • Conduct proactive, hypothesis-driven threat hunts based on incident trends, emerging adversary TTPs, and threat intelligence
    • Use hunt outcomes to surface undetected compromises, validate detection coverage, and strengthen incident response readiness
    • Prioritize hunts against the techniques and attack paths most relevant to a payments/fintech environment
    • Partner with threat intelligence sources and feeds to inform hunt hypotheses and target selection
    • Document hunt methodology, findings, and follow-on actions, including new detections and updated incident response playbook material
  • Cross-Functional & Leadership
    • Represent incident response in cross-org planning, tabletop exercises, and architecture reviews
    • Lead complex, ambiguous incident-related investigations and initiatives independently from scoping through delivery
    • Mentor other engineers and analysts on incident response, detection engineering, and threat hunting practices
    • Partner with cloud, network, and identity teams to close visibility and telemetry gaps identified during incidents and hunts
    • Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment
    • Communicate findings, coverage gaps, and recommendations clearly to both technical and non-technical stakeholders, including leadership
    • Develop and maintain procedure and policy documentation supporting incident response operations

What we need from you: 


  • Bachelor's degree in a technical field, or equivalent professional experience
  • 7+ years of hands-on information security experience, with deep, demonstrated subject-matter expertise in incident response, and strong working proficiency in detection engineering and threat hunting
  • Demonstrated track record independently leading complex, high-severity security incidents from detection through recovery, without supervision
  • Experience mentoring or providing technical leadership to other security engineers and analysts
  • Excellent written and verbal communication skills, including the ability to translate technical findings for non-technical stakeholders and leadership, including during active incidents
  • Deep, hands-on expertise leading end-to-end incident response (triage, containment, eradication, recovery, and root cause analysis) on complex or novel incidents, independently
  • Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics
  • Advanced experience with EDR/XDR platforms and log analysis across diverse sources: endpoint, network, cloud, and identity
  • Strong working knowledge of detection engineering: writing, tuning, and validating detection content in a SIEM or NG-SIEM platform (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel)
  • Working proficiency in hypothesis-driven threat hunting methodology, informed by threat intelligence and the MITRE ATT&CK framework
  • Deep working knowledge of the MITRE ATT&CK framework and its practical application to incident response, detection gap analysis, and hunt prioritization
  • Strong scripting or automation experience (Python, PowerShell, or similar) applied to security use cases AND/OR experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex
  • Solid understanding of networking, cloud infrastructure (AWS especially, but also Azure and GCP), Windows/Linux systems, and identity platforms
  • Working knowledge of PCI-DSS or a comparable compliance framework
  • Demonstrated ability to lead high-pressure, ambiguous, cross-functional incident investigations with minimal oversight

License and Certification: Relevant hands-on experience and demonstrated subject-matter expertise are weighted more heavily than certifications for this role. Any of the following are preferred.

    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Cyber Threat Intelligence (GCTI)
    • Offensive Security Certified Professional (OSCP)
    • Offensive Security Incident Response (OSIR)
    • CompTIA CySA+

Salary range: $150,000-$180,000


Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.

Please note: North is a US based company and no sponsorship is available for this position at this time.


Who we are: 

North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else.


Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. 


At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.

To learn more about North, and our family of companies, visit our website: north.com

Similar Jobs

11 Minutes Ago
Remote or Hybrid
106K-139K Annually
Senior level
106K-139K Annually
Senior level
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Support and improve security operations for production environments. Responsibilities include troubleshooting complex security issues, reviewing secure configurations, investigating root causes, applying security processes, automating checks, and managing encryption, certificates, PKI, keys, and HSMs. The role also maintains runbooks, documents findings, assesses risk, and coordinates security improvements across teams.
Top Skills: BashCloud PlatformsHsmsIamIpsecKubernetesLinuxPkiPowershellPythonSecurity ToolingSIEMSshTls
11 Minutes Ago
Remote or Hybrid
USA
25K-29K Hourly
Entry level
25K-29K Hourly
Entry level
Healthtech • Social Impact • Software
Reviews and interprets payor contracts, amendments, and policies for new launches; documents key terms, escalates risks, supports reimbursement accuracy, and answers contract questions. Builds and organizes a searchable contract repository and validates AI payor intelligence tools. Partners with payor, billing, eligibility, and revenue cycle teams to resolve information gaps and improve contract-management processes.
32 Minutes Ago
Remote or Hybrid
94K-140K Annually
Senior level
94K-140K Annually
Senior level
Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Administer global equity compensation and employee stock purchase plans, including grants, vestings, releases, exercises, reconciliations, reporting, payroll and tax data validation, SOX controls, audits, and securities filings. Partner with Legal, Finance, Accounting, Payroll, HR, Tax, Procurement, and vendors. Improve processes through automation and AI, maintain documentation, support proxy and CD&A reporting, manage vendor administration, and communicate with employees and stakeholders.
Top Skills: Artificial IntelligenceAutomationFidelity Stock Plan ServicesMicrosoft 365Microsoft CopilotExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft Word

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account