次の仕事の機会を見つけましょう

職種、スキル、勤務地で求人を検索できます。応募書類を準備する前に募集要件を確認しましょう。

魅力的な職種名を見つけることは、仕事探しの出発点です。業務内容、応募条件、働き方を自分の経験と照らし合わせましょう。このガイドでは、候補の絞り込み、応募書類の準備、提出先の確認を順番に進めるためのポイントを紹介します。

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

条件をクリア

検索結果: 8,487

← 検索結果に戻る

Principal Incident Response Analyst

North American Bancard

リモート勤務

勤務地
Remote (United States)
報酬
USD 150000-180000 per annual
勤務時間
Full Time
掲載日
2026年10月8日

応募する前に、企業のウェブサイトで現在も募集中かどうかと詳しい条件を確認してください。

仕事内容

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

Principal Incident Response Analyst North - Remote The Principal Incident Response Analyst is a seasoned, deeply experienced incident response expert who runs North’s most complex security incidents from detection through recovery, without supervision. Incident response is the primary area of expertise for this role, complemented by strong secondary expertise in detection engineering and tertiary expertise in threat hunting. The Principal Incident Response Analyst serves as the top escalation point for security incidents, sets the technical standard for how the organization investigates and contains threats, and mentors other engineers and analysts on incident handling practice. This role works closely with the SOC, IT, and engineering teams, and represents the deepest incident response expertise on the security team, operating across our payment processing environment. What You'll do: Incident Response Serve as the principal escalation point and lead investigator for the most complex, highest-severity, and novel security incidents, running them end to end without supervision Independently triage, investigate, contain, eradicate, and recover from security incidents spanning endpoint, network, cloud, identity, and application layers Lead full-scope forensic investigations of compromised hosts, accounts, applications, and cloud infrastructure, and reconstruct complete attack timelines from initial access through impact Translate complex investigation findings into clear narratives for engineering teams and clear executive-level narratives for leadership Own and continuously evolve incident response process, documentation, and playbooks, incorporating lessons learned from real incidents Lead root cause analysis and structured post-incident reviews, and drive cross-team remediation of systemic gaps Serve as the senior technical lead during major incidents, coordinating across IT, legal, compliance, and executive leadership as needed Provide case-level guidance and mentorship to other incident responders and SOC analysts during live incidents Participate in or lead on-call rotation for critical incident response as needed Detection Engineering Translate incident findings and root cause analysis directly into new or improved detection logic, closing the loop between investigation and prevention Write, tune, and validate detection content in the SIEM/NG-SIEM platform, focused on techniques observed in real investigations and threat hunts Maintain and improve coverage and gap analysis against the MITRE ATT&CK framework, informed by incident and hunt findings Review detection logic for accuracy and false-positive rate, and partner with the detection engineering team on rule quality Contribute documentation of known coverage and detection gaps surfaced through incident response and hunting work Threat Hunting Conduct proactive, hypothesis-driven threat hunts based on incident trends, emerging adversary TTPs, and threat intelligence Use hunt outcomes to surface undetected compromises, validate detection coverage, and strengthen incident response readiness Prioritize hunts against the techniques and attack paths most relevant to a payments/fintech environment Partner with threat intelligence sources and feeds to inform hunt hypotheses and target selection Document hunt methodology, findings, and follow-on actions, including new detections and updated incident response playbook material Cross-Functional & Leadership Represent incident response in cross-org planning, tabletop exercises, and architecture reviews Lead complex, ambiguous incident-related investigations and initiatives independently from scoping through delivery Mentor other engineers and analysts on incident response, detection engineering, and threat hunting practices Partner with cloud, network, and identity teams to close visibility and telemetry gaps identified during incidents and hunts Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment Communicate findings, coverage gaps, and recommendations clearly to both technical and non-technical stakeholders, including leadership Develop and maintain procedure and policy documentation supporting incident response operations What we need from you: Bachelor's degree in a technical field, or equivalent professional experience 7+ years of hands-on information security experience, with deep, demonstrated subject-matter expertise in incident response, and strong working proficiency in detection engineering and threat hunting Demonstrated track record independently leading complex, high-severity security incidents from detection through recovery, without supervision Experience mentoring or providing technical leadership to other security engineers and analysts Excellent written and verbal communication skills, including the ability to translate technical findings for non-technical stakeholders and leadership, including during active incidents Deep, hands-on expertise leading end-to-end incident response (triage, containment, eradication, recovery, and root cause analysis) on complex or novel incidents, independently Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics Advanced experience with EDR/XDR platforms and log analysis across diverse sources: endpoint, network, cloud, and identity Strong working knowledge of detection engineering: writing, tuning, and validating detection content in a SIEM or NG-SIEM platform (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel) Working proficiency in hypothesis-driven threat hunting methodology, informed by threat intelligence and the MITRE ATT&CK framework Deep working knowledge of the MITRE ATT&CK framework and its practical application to incident response, detection gap analysis, and hunt prioritization Strong scripting or automation experience (Python, PowerShell, or similar) applied to security use cases AND/OR experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex Solid understanding of networking, cloud infrastructure (AWS especially, but also Azure and GCP), Windows/Linux systems, and identity platforms Working knowledge of PCI-DSS or a comparable compliance framework Demonstrated ability to lead high-pressure, ambiguous, cross-functional incident investigations with minimal oversight License and Certification: Relevant hands-on experience and demonstrated subject-matter expertise are weighted more heavily than certifications for this role. Any of the following are preferred. GIAC Certified Forensic Analyst (GCFA) GIAC Certified Incident Handler (GCIH) GIAC Network Forensic Analyst (GNFA) GIAC Cyber Threat Intelligence (GCTI) Offensive Security Certified Professional (OSCP) Offensive Security Incident Response (OSIR) CompTIA CySA+ Salary range: $150,000-$180,000 Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process. Please note: North is a US based company and no sponsorship is available for this position at this time. Who we are: North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else. Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer. To learn more about North, and our family of companies, visit our website: Originally posted on Himalayas

検索して比較し、応募を準備しましょう

次の仕事で活かしたい職種やスキルから検索を始めましょう。勤務地と職種の条件を調整し、求人を開いて担当業務を比較してください。結果がない場合は、短い検索語を試すか、条件を一つずつ外してみましょう。

必須条件と歓迎条件を分けて確認し、勤務時間、報酬、勤務地が掲載されている場合は目を通しましょう。リモート勤務でも、居住国、就労資格、勤務時間帯が指定されることがあります。現在の募集状況と詳しい条件は企業に確認してください。

募集要件に関連する実際の経験を選び、自分の役割と貢献を説明しましょう。数値は根拠がある場合にのみ使ってください。企業の応募方法に従い、送信前に連絡先、内容、PDFの表示を確認しましょう。

応募前の確認リスト

仕事探しに関するよくある質問

英語の求人が表示されるのはなぜですか?

職種名や説明文は企業が作成したものです。条件や要件を変えないように原文を掲載しています。操作画面とこのガイドは日本語です。日本語の検索で見つからない場合は、「software engineer」のように、掲載言語の職種名やスキル名でも検索してみてください。検索語が自動翻訳されるわけではありません。

リモート求人なら、どの国からでも働けますか?

必ずしもそうではありません。居住国、就労資格、勤務時間帯が指定されている場合があります。元の求人ページで条件を確認してください。記載がない場合は、自分の居住地から応募できると判断する前に企業へ確認しましょう。リモートという表示だけでは、勤務地の制限がないことは分かりません。

検索結果が出ない場合はどうすればよいですか?

より一般的な職種名や一つのスキルで検索し、条件を一つずつ外してみてください。同じような仕事でも企業によって呼び方が異なります。特定の求人が見つからなくなった場合は、企業の採用ページで求人番号を探しましょう。検索条件を広げても、終了した募集が再開するわけではありません。

ResumizeAIから応募が送信されますか?

応募ボタンは外部サイトを開きます。企業または採用サービスの案内に従い、そのサイトで送信を完了してください。ResumizeAIで応募書類を作成しただけでは応募は送信されません。リンク先が企業のトップページの場合は、該当する募集を探してから手続きを進めましょう。

応募書類とカバーレターはどう調整すればよいですか?

募集要件と、自分が説明できるプロジェクト、業務、成果を結び付けます。経験していない技術や実績を加えず、関連する経験を分かりやすく示してください。カバーレターでは応募理由を具体例とともに伝えます。指定された言語とファイル形式に従い、送信前に両方の書類を確認しましょう。