Skip to main content
BlackCloak

Senior Incident Responder

RemoteUnited States only
Published
Role
Fullstack
Experience
Senior
Employment
Full-time
$105k–$115k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

BlackCloak is seeking a seasoned and highly skilled Senior Incident Responder to join our Technical Success Team. This is a senior, client-facing individual contributor role for someone who has spent years on both sides of the problem: the technical compromise of computers, phones, and online accounts, and the financial fraud that so often follows it.

Core skills

Digital Forensics/Incident ResponseWindows Administration/Forensics

Required skills

Windows/macOS/iOS/Android/LinuxNetwork Vulnerability ScanningVulnerability ManagementIdentity Theft RemediationKill Chain ModelingFraud Investigation/Financial Transaction Analysis

Optional skills

GCIH certificationGCFA certificationCISSP certificationOSCP certificationCFE certificationCFCS certificationCAMS certification

What you'll do

  • Execute End-to-End Incident Response: Lead comprehensive incident handling consistent with core IR principles (NIST/SANS) from the initial client request and triage through containment, recovery, and post-incident lessons learned.
  • Investigate Complexly Compromises & Targeted Attacks: Manage and remediate severe client security incidents, including but not limited to, compromised email ecosystems, SIM swap attacks, financial account takeovers, and targeted credential harvesting.
  • Device Analysis: Conduct analysis on client computers and mobile devices to assess the scope of compromise and implement effective remediation strategies.
  • Remediate Fraud & Identity Theft: Analyze and assess account activity and transaction records available to the client to help establish what occurred, and support clients in their conversations with the platforms on fraud investigations, disputes, account freezes, etc. Guide identity theft victims through the remediation process - credit bureau freezes and fraud alerts, IdentityTheft.gov and law enforcement reporting - and advise clients on the activity that should watch for and report back
  • Map the Attack Chain: Map observed activity against the personal attack chain - from reconnaissance and social engineering of the client's inner circle through device compromise, account takeover, and financial monetization - to identify the likely stage of an attack and the actions that break the chain, focusing on technique and exposure rather than actor attribution.
  • Provide White-Glove Client Support: Interface directly with clients and, where authorized, their access to their families and support staff during high-stakes and active incidents, providing calm, clear, and authoritative guidance while communicating complex threat assessments.
  • Participate in On-Call Rotation: Serve in an on-call and escalation rotation that requires occasional nights and weekends to address client incidents, emergency onboarding, and time-sensitive issues.
  • Lead & Provate: Serve as the highest technical escalation in the on-call rotation, mentoring teams to elevate the team's overall technical proficiency.
  • Enhance Security Posture: Oversee network vulnerability scans of client infrastructure, proactively refine internal IR procedures, and help with post-onboarding feedback.

What they require

  • 5-8+ years of experience in a dedicated Incident Response, Digital Forensics (DFIR), or advanced cybersecurity analyst role.
  • Proven track record executing the full incident lifecycle, particularly involving personal/executive account takeovers, mobile threats, and endpoint malware.
  • Demonstrated experience investigating fraud in financial transactions, including direct coordination with banks and card brands - fraud investigation, disputes and chargebacks, transaction analysis, or account takeover response. This may have been gained at a financial institution, card issuer, payment processor, fintech risk team, financial crimes unit, or in a security role working directly.
  • Deep technical expertise conducting forensics and vulnerability management across Windows, macOS, iOS, Android, and Linux ecosystems.
  • Working command of identity theft remediation and attack kill chain models, with the ability to apply them to an individual and their family rather than an enterprise.
  • Advanced industry certifications (GCIH, GCFA, CISSP, OSCP, or similar) are preferred; fraud and financial crime certs (CFE, CFCS, CAMS) are a plus.
  • Exceptional communication with ability to translate technical jargon into actionable advice for non-technical clients.
  • College degree in IT/CS/CE or equivalent real-world experience, with the ability to operate highly independently.

Benefits

  • 100% Remote Company, within the USA
  • Comprehensive Medical, Dental, and Vision plans with 100% employer-paid monthly premium option for employees & 50% for dependents
  • Health Savings Account with company contribution for eligible medical plans
  • Flexible Vacation Plan
  • 10 Paid Company Holidays
  • 100% employer-paid Life, AD&D and Short- and Long-Term Disability Insurance
  • 401k with Traditional and Roth options, including employer match
  • Company Equity
  • Paid Parental and Pregnancy Recovery Leave
  • Company and team off-sites and virtual events throughout the year
  • Home office stipend

BlackCloak’s mission is to protect corporate executives and high-profile individuals in their personal lives, mitigating risks to their families, companies, reputation, and finances. They defend clients’ digital lives from hackers, privacy leaks, and identity theft.

CybersecurityStartup
$105k–$115k/yr