Principal Incident Response Analyst
nabancard · US - Remote · United States · Remote
Pay: USD 150,000 – 180,000 a year
Posted Oct 6, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Principal Incident Response Analyst
North - Remote
The Principal Incident Response Analyst is a seasoned, deeply experienced incident response expert who runs North’s most complex security incidents from detection through recovery, without supervision.
Incident response is the primary area of expertise for this role, complemented by strong secondary expertise in detection engineering and tertiary expertise in threat hunting. The Principal Incident Response Analyst serves as the top escalation point for security incidents, sets the technical standard for how the organization investigates and contains threats, and mentors other engineers and analysts on incident handling practice. This role works closely with the SOC, IT, and engineering teams, and represents the deepest incident response expertise on the security team, operating across our payment processing environment.
What You'll do:
Incident Response Serve as the principal escalation point and lead investigator for the most complex, highest-severity, and novel security incidents, running them end to end without supervision
Independently triage, investigate, contain, eradicate, and recover from security incidents spanning endpoint, network, cloud, identity, and application layers
Lead full-scope forensic investigations of compromised hosts, accounts, applications, and cloud infrastructure, and reconstruct complete attack timelines from initial access through impact
Translate complex investigation findings into clear narratives for engineering teams and clear executive-level narratives for leadership
Own and continuously evolve incident response process, documentation, and playbooks, incorporating lessons learned from real incidents
Lead root cause analysis and structured post-incident reviews, and drive cross-team remediation of systemic gaps
Serve as the senior technical lead during major incidents, coordinating across IT, legal, compliance, and executive leadership as needed
Provide case-level guidance and mentorship to other incident responders and SOC analysts during live incidents
Participate in or lead on-call rotation for critical incident response as needed
Detection Engineering Translate incident findings and root cause analysis directly into new or improved detection logic, closing the loop between investigation and prevention
Write, tune, and validate detection content in the SIEM/NG-SIEM platform, focused on techniques observed in real investigations and threat hunts
Maintain and improve coverage and gap analysis against the MITRE ATT&CK framework, informed by incident and hunt findings
Review detection logic for accuracy and false-positive rate, and partner with the detection engineering team on rule quality
Contribute documentation of known coverage and detection gaps surfaced through incident response and hunting work
Threat Hunting Conduct proactive, hypothesis-driven threat hunts based on incident trends, emerging adversary TTPs,…