Skip to content

Open nowPosted 10 hours ago

Incident Response Lead

Aspenview Technology Partners58 open roles

Where
United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIncident Response LeadAspenview Technology Partners · United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Aspenview Technology Partners's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 10 hours ago

The posting

Build the Future with AspenView Technology Partners

At AspenView, we are passionate about transforming the way organizations approach technology. We specialize in creating high-performing, nearshore IT teams to help North American clients innovate faster and more efficiently.

As we continue to grow, we’re looking for exceptional people to join our team and help drive impactful change across industries.

Why Join AspenView?

At AspenView, we’re more than a nearshore IT partner—we’re a people-first, purpose-driven company that believes great culture drives great outcomes. We’re passionate about connecting talent and technology to deliver measurable value for clients—and meaningful career paths for our people.

Here’s what you can expect:

  • Competitive base
  • Flexible work model: hybrid, remote, or in-office
  • Real growth opportunities and leadership visibility
  • Inclusive, respectful culture that blends U.S. innovation with Colombian heart
  • A company that listens, invests in you, and celebrates wins together

The Incident Response Lead is a senior, hands-on professional responsible for leading incident response and the embedded digital forensics capability for a large US consumer lender. The client's 24/7 security operations run from a nearshore team in Bogotá, Medellin and Buenos Aires, and you will be one of two US-based seniors on the service, highly visible to the client's security leadership. When the client declares a major incident, you will be the incident lead on its bridge. The client declares incidents and executes containment; your job is to tell it what happened, how far it reached and what to contain, with the evidence to back it. You will report to the SOC / Cyber Operations Lead and provide technical direction to two Tier 3 analysts in Latin America.

What you will do:

Major Incident Leadership

  • Serve as incident lead on the client's major-incident bridge, working alongside its incident commander and keeping the client, the partner and the analysts aligned on one version of events.
  • Scope incidents and deliver evidence-backed containment recommendations for the client's infrastructure, identity, endpoint and application teams to execute.
  • Write operational updates for responders and executive summaries for client leadership during incidents, and lead the post-incident review afterwards.

Digital Forensics & Investigation

  • Own the DFIR work inside the service, including host and memory triage and analysis of CrowdStrike and Defender endpoint telemetry.
  • Investigate Okta sessions and tokens, and AWS activity through CloudTrail, GuardDuty and VPC flow logs.
  • Build investigation records and timelines that give the client what it needs for its own regulatory notification decisions under NYDFS Part 500 and GLBA.

Readiness & Team Direction

  • Develop IR playbooks and runbooks, including a review of the client's existing content.
  • Run tabletop exercises with the client's security, legal and risk teams.
  • Guide two Tier 3 analysts in Latin America who act as your first line on overnight investigations.

Tools & Technologies:

  • SIEM & Case Management: Elastic, Abstract Security and ServiceNow SecOps (Splunk or Sentinel also relevant).
  • Endpoint & Identity: CrowdStrike Falcon, Microsoft Defender and Okta (or Entra ID).
  • Cloud: AWS CloudTrail, GuardDuty and VPC flow logs (Azure or GCP accepted).
  • Email & Network (Bonus): Proofpoint and Palo Alto, or equivalents.
  • Forensics (Bonus): Velociraptor, KAPE, Volatility, FTK, EnCase or X-Ways.

What you bring:

  • Experience: Senior enough to lead the technical response to a major incident, and able to walk through one end to end, including what went wrong and what you changed afterwards. Hands-on forensics on Windows and Linux hosts and investigations in at least one major cloud.
  • Technical Independence: You query SIEM, EDR and identity logs directly rather than waiting for an analyst to pull the data.
  • Judgment: The ability to recommend containment that stops an attacker without taking down a lending platform at month end.
  • Communication / Leadership: Incident reports that a CISO, a lawyer and an examiner can each read without a translator. Proven ability to lead people you don't line-manage, including analysts in another country.
  • Availability: Remote work from the United States on US Eastern business hours, plus a 24/7 on-call rotation and periodic travel to the client and to Bogotá and Buenos Aires. US work authorization is required, and access requires identity, criminal background, employment and education checks, repeated periodically.
  • Bonus Qualifications: Incident response inside a bank, lender, card issuer or insurer; working knowledge of NYDFS Part 500, GLBA, FFIEC, SOX and PCI DSS incident obligations; experience with ransomware, business email compromise or fraud-driven intrusions in consumer finance; consultancy or MSSP background; GCIH, GCFA, GCFE, GREM or CISSP; and Spanish, which helps with the nearshore team but isn't required.

Visa Sponsorship

AspenView does not sponsor employment visas for this role. Applicants must be permanently authorized to work in their country of residence and must not require visa sponsorship now or in the future.

Equal Opportunity Employer

AspenView is proud to be an equal opportunity employer. We believe in creating an environment where all employees feel welcome, valued, and empowered to succeed. We celebrate diversity and strive to build a culture of inclusion where all individuals, regardless of their race, color, gender, gender identity or expression, sexual orientation, disability, age, or any other characteristic, can thrive. We encourage applicants from all walks of life to join our team and make a lasting impact.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Aspenview Technology Partners's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Aspenview Technology Partners's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Aspenview Technology Partners's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.