Full-Time

Senior Incident Response Analyst

Confirmed live in the last 24 hours

Coalition

Coalition

501-1,000 employees

Active insurance and cybersecurity risk management

No salary listed

Mid, Senior

Remote in Canada

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
AWS
Linux/Unix
Google Cloud Platform
Requirements
  • 3-5 years of professional experience (2 years directly related to IR or functional area) or equivalent combination of education and experience
  • Bachelor's degree in digital forensics, cybersecurity, computer science, information systems or similar field
  • Working as part of a team in a remote matrixed consulting environment
  • Incident Response: conducting or overseeing IR investigations for organizations, answering to opportunistic and targeted threats such as BECs, FTFs, ransomware and APTs
  • Digital Forensic Analysis: a background in using different forensic assessment tools in incident response investigations to ascertain the extent and scope of compromise and possessing creativity and reason in approaching intricate forensic problems
  • Incident Remediation: strong knowledge of opportunistic and targeted attacks and aptitude to generate customized strategic and tactical remediation plans for consumers
  • Network Forensic Analysis: strong knowledge of networking protocols, network assessment tools, and aptitude to perform assessment of associated network logs
  • SOC and EDR: experience with EDR solutions and leveraging detections and analytics to mitigate threats appropriately
  • Possessing a knowledge of secure network architecture and a strong knowledge of networking fundamentals
  • Cloud Incident Response: knowledge in AWS, Azure, GCP incident response strategies
Responsibilities
  • Work under the direction of IR lead and outside counsel to conduct IR investigations
  • Fulfill consumer requests and resolve incidents received via e-mail or internal ticketing systems in a timely and detail-oriented manner
  • Guide all consumer interactions professionally with a strong emphasis on consumer satisfaction
  • Assess and assess security incidents and escalate to appropriate internal teams for additional assistance
  • Triage and scope incidents for prospective consumers to identify the DFIR objectives and magnitude of effort involved to satisfy objectives
  • Provide strategic, relevant, and achievable recommendations to help advance the security posture of organizations during and after an incident
  • Communicate effectively with consumers (executives and IT) on the topics of incident type, remediation, forensics and assessment
  • Perform host and network-based forensics across Windows, Mac, and Linux platforms as well as cloud environments
  • Deliver high-quality written and verbal reports, recommendations, and findings to key stakeholders including consumers and legal counsel
  • Participate in, or work directly on additional projects, assignments, or initiatives as required
  • Mentor and coach team members and work effectively as part of team unit
  • Develop, evaluate and utilize novel methods to hunt for indicators of compromise and perform assessment across large sets of data
  • Assist in the development of internal guidelines, playbooks and knowledge base
  • Demonstrate industry thought guidance through blog posts and occasional public speaking events
Desired Qualifications
  • Excellent critical thinking skills with the experience to diagnose and troubleshoot technical issues
  • Customer oriented with a strong interest in consumer satisfaction
  • Experience to learn new technologies and concepts and comfortable using command-line interfaces
  • Experience guiding teams of highly motivated analysts
  • Communicate highly technical information to a non-technical audience
  • Experience to handle and work with consumers through high priority scenarios
  • Knowledge in project management
  • Foster a positive work environment and attitude
  • Flexibility with your work schedule in times of urgent response needs
  • Contribute to thought guidance within the DFIR industry
  • GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, CISSP, or similar

Coalition provides Active Insurance, which combines insurance coverage with cybersecurity tools to help businesses prevent digital risks. Their products are available to policyholders in the U.S., U.K., Canada, and Australia, through partnerships with major global insurers and their own insurance company. Coalition's platform, Coalition Control, offers automated cyber alerts, expert guidance, and third-party risk management to assist businesses in managing potential cyber attacks. Additionally, Coalition Security Labs focuses on research and education in cybersecurity, providing insights to help both policyholders and the wider security community understand and navigate cyber threats. Coalition stands out from competitors by integrating insurance with proactive cybersecurity measures, aiming to reduce the likelihood of cyber incidents before they occur.

Company Size

501-1,000

Company Stage

Series F

Total Funding

$770M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Rising cyber threats increase demand for Coalition's cyber insurance products.
  • Recent $250 million funding round supports expansion and innovation efforts.
  • Acquisition of Jumbo enhances Coalition's cybersecurity capabilities and market reach.

What critics are saying

  • Increased competition from companies like Hawk AI in cybersecurity tools.
  • Integration challenges from acquiring Jumbo may divert focus from core operations.
  • Regulatory challenges from acquiring an insurance carrier could increase compliance costs.

What makes Coalition unique

  • Coalition is the first Active Insurance provider focusing on digital risk prevention.
  • Combines insurance with cybersecurity tools for comprehensive cyber risk management.
  • Offers global cybersecurity solutions with a focus on proactive threat mitigation.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Enjoy a highly fulfilling, mission-driven culture

Health, dental, and vision benefits for you and your family

Life insurance and disability benefits

Paid parental leave

401(k) plan

Wellness and commuter benefits

Flexible working hours

Open vacation days

We embrace distributed work; some benefits will vary by location

You are an owner. We offer stock options to each of our employees

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
PYMNTS
Apr 8th, 2025
Hawk Raises $56 Million To Help Banks Counter Financial Crime

Fraud and money laundering prevention provider Hawk has raised $56 million in new funding. The Germany-based company says its Series C round, announced Tuesday (April 8), will help it finance further product innovation and fuel expansion efforts, especially in the U.S. “Hawk enables banks to move beyond the traditional rules-based approach to anti-money laundering and fraud,” the company said in a news release. “Traditional systems create significant problems for compliance teams, including huge volumes of false positive alerts that need to be reviewed, which in turn leads to staffing challenges and costs.”

Business Wire
Mar 4th, 2025
Coalition and MS&AD Insurance Group Expand Strategic Partnership with Equity Investment

Coalition, the world's first Active Insurance provider designed to prevent digital risk before it strikes, today announced a new $30 million equity in

Coalition Inc.
Nov 30th, 2023
Coalition Closes Series F Funding Round of $250 Million | Coalition Blog

Coalition completed its Series F funding round in June, adding $250 million from Allianz X, Valor Equity Partners, Kinetic Partners and existing investors.

Hawk.ai
Jan 27th, 2023
Hawk AI Accelerates Global Expansion with $17 Million Series B

Munich, January 26, 2023 – Hawk AI, Germany’s leading provider of anti-money laundering (AML) and fraud prevention technology for banks and payment companies, announced $17M in Series B financing to accelerate product development and global expansion.