寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 8,531

← 返回搜索结果

Principal Incident Response Analyst

North American Bancard

远程工作

地点
Remote (United States)
薪资
USD 150000-180000 per annual
工作安排
Full Time
发布日期
2026年10月8日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

Principal Incident Response Analyst North - Remote The Principal Incident Response Analyst is a seasoned, deeply experienced incident response expert who runs North’s most complex security incidents from detection through recovery, without supervision. Incident response is the primary area of expertise for this role, complemented by strong secondary expertise in detection engineering and tertiary expertise in threat hunting. The Principal Incident Response Analyst serves as the top escalation point for security incidents, sets the technical standard for how the organization investigates and contains threats, and mentors other engineers and analysts on incident handling practice. This role works closely with the SOC, IT, and engineering teams, and represents the deepest incident response expertise on the security team, operating across our payment processing environment. What You'll do: Incident Response Serve as the principal escalation point and lead investigator for the most complex, highest-severity, and novel security incidents, running them end to end without supervision Independently triage, investigate, contain, eradicate, and recover from security incidents spanning endpoint, network, cloud, identity, and application layers Lead full-scope forensic investigations of compromised hosts, accounts, applications, and cloud infrastructure, and reconstruct complete attack timelines from initial access through impact Translate complex investigation findings into clear narratives for engineering teams and clear executive-level narratives for leadership Own and continuously evolve incident response process, documentation, and playbooks, incorporating lessons learned from real incidents Lead root cause analysis and structured post-incident reviews, and drive cross-team remediation of systemic gaps Serve as the senior technical lead during major incidents, coordinating across IT, legal, compliance, and executive leadership as needed Provide case-level guidance and mentorship to other incident responders and SOC analysts during live incidents Participate in or lead on-call rotation for critical incident response as needed Detection Engineering Translate incident findings and root cause analysis directly into new or improved detection logic, closing the loop between investigation and prevention Write, tune, and validate detection content in the SIEM/NG-SIEM platform, focused on techniques observed in real investigations and threat hunts Maintain and improve coverage and gap analysis against the MITRE ATT&CK framework, informed by incident and hunt findings Review detection logic for accuracy and false-positive rate, and partner with the detection engineering team on rule quality Contribute documentation of known coverage and detection gaps surfaced through incident response and hunting work Threat Hunting Conduct proactive, hypothesis-driven threat hunts based on incident trends, emerging adversary TTPs, and threat intelligence Use hunt outcomes to surface undetected compromises, validate detection coverage, and strengthen incident response readiness Prioritize hunts against the techniques and attack paths most relevant to a payments/fintech environment Partner with threat intelligence sources and feeds to inform hunt hypotheses and target selection Document hunt methodology, findings, and follow-on actions, including new detections and updated incident response playbook material Cross-Functional & Leadership Represent incident response in cross-org planning, tabletop exercises, and architecture reviews Lead complex, ambiguous incident-related investigations and initiatives independently from scoping through delivery Mentor other engineers and analysts on incident response, detection engineering, and threat hunting practices Partner with cloud, network, and identity teams to close visibility and telemetry gaps identified during incidents and hunts Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment Communicate findings, coverage gaps, and recommendations clearly to both technical and non-technical stakeholders, including leadership Develop and maintain procedure and policy documentation supporting incident response operations What we need from you: Bachelor's degree in a technical field, or equivalent professional experience 7+ years of hands-on information security experience, with deep, demonstrated subject-matter expertise in incident response, and strong working proficiency in detection engineering and threat hunting Demonstrated track record independently leading complex, high-severity security incidents from detection through recovery, without supervision Experience mentoring or providing technical leadership to other security engineers and analysts Excellent written and verbal communication skills, including the ability to translate technical findings for non-technical stakeholders and leadership, including during active incidents Deep, hands-on expertise leading end-to-end incident response (triage, containment, eradication, recovery, and root cause analysis) on complex or novel incidents, independently Advanced digital forensics skills across endpoint, network, cloud, and identity sources, including memory and disk forensics Advanced experience with EDR/XDR platforms and log analysis across diverse sources: endpoint, network, cloud, and identity Strong working knowledge of detection engineering: writing, tuning, and validating detection content in a SIEM or NG-SIEM platform (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel) Working proficiency in hypothesis-driven threat hunting methodology, informed by threat intelligence and the MITRE ATT&CK framework Deep working knowledge of the MITRE ATT&CK framework and its practical application to incident response, detection gap analysis, and hunt prioritization Strong scripting or automation experience (Python, PowerShell, or similar) applied to security use cases AND/OR experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex Solid understanding of networking, cloud infrastructure (AWS especially, but also Azure and GCP), Windows/Linux systems, and identity platforms Working knowledge of PCI-DSS or a comparable compliance framework Demonstrated ability to lead high-pressure, ambiguous, cross-functional incident investigations with minimal oversight License and Certification: Relevant hands-on experience and demonstrated subject-matter expertise are weighted more heavily than certifications for this role. Any of the following are preferred. GIAC Certified Forensic Analyst (GCFA) GIAC Certified Incident Handler (GCIH) GIAC Network Forensic Analyst (GNFA) GIAC Cyber Threat Intelligence (GCTI) Offensive Security Certified Professional (OSCP) Offensive Security Incident Response (OSIR) CompTIA CySA+ Salary range: $150,000-$180,000 Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process. Please note: North is a US based company and no sponsorship is available for this position at this time. Who we are: North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else. Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer. To learn more about North, and our family of companies, visit our website: Originally posted on Himalayas

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。