





Tier-1 brand, remote role, and mid-level experience balanced by niche ransomware/forensics specialization.
Role requires specialized incident response, ransomware and SIEM forensics skills, so industry transferability is limited.
Explicit 5+ years ransomware IR, forensic/SiEM/scripting requirements and leadership make filters strict and technical.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead and coordinate multiple simultaneous ransomware and business email compromise (BEC) incident response investigations, including initial customer engagement and delivery of forensic findings.
Direct forensic investigations by prioritizing tasks, delegating to analysts, and determining Tactics, Techniques, and Procedures (TTPs) for threat intelligence integration.
Produce timely executive summary reports and manage incident handovers across time zones to support continuous and effective incident management.
5+ years of experience leading incident response investigations involving ransomware and BEC.
Post-secondary education in Cybersecurity or comparable field.
Strong oral and written communication skills with ability to manage multiple incidents and prioritize tasks effectively.
Ability to work under stress, including willingness to work occasional early starts, late hours, weekends, and holidays when required.
Demonstrated expertise in ransomware neutralization and remediation with solid understanding of incident response processes and cyber risk qualification.
Experienced in mentoring junior analysts and working across distributed teams in different time zones.
Familiarity with MITRE ATT&CK framework and basic scripting (PowerShell, Python, or Bash) and/or SIEM technologies is a plus but not mandatory.