Full-Time

Incident Response Lead

Confirmed live in the last 24 hours

Coalition

Coalition

501-1,000 employees

Active insurance and cybersecurity risk management

Compensation Overview

$130k - $201k/yr

Senior

United States

Category
Cybersecurity
IT & Security
Required Skills
TCP/IP
Wireshark
Requirements
  • Bachelor’s Degree in Computer Science, Information Security, Engineering, or other relevant subjects.
  • Minimum of 5+ years of incident response or digital forensics experience.
  • Demonstrated practiced knowledge of the lifecycle of network threats, attacks, attack vectors, and methods of exploitation with a knowledge of intrusion set tactics, techniques, and procedures.
  • Consultative Approach: Ability to effectively communicate complex technical concepts to non-technical stakeholders and provide actionable recommendations.
  • Analytical Skills: Proficiency in analyzing security programs, technologies, and environments to identify gaps and recommend enhancements.
  • Regulatory Knowledge: Familiarity with regulatory requirements and frameworks (e.g., NIST, HIPAA, PCI) is essential for advising clients on compliance issues.
  • Project Management: Experience managing multiple projects simultaneously, from initial scoping through to final deliverables, ensuring high-quality results and client satisfaction.
  • Knowledge of TCP/IP Protocols, network assessment and network/security applications, including log and network traffic capture assessment.
  • Experience with Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, WireShark, Plaso, Skadi or other open source forensic/log analysis/network assessment tools.
  • Experience with EDR tools like CrowdStrike Falcon, Carbon Black, Sentinel One, etc.
  • Knowledge of industry standard frameworks – NIST, HIPAA, PCI.
  • Self-motivated; entrepreneurial spirit; comfortable working in a dynamic environment.
  • Strong interactive communication skills (verbal & written).
  • Aptitude to learn technical concepts/terms, and aptitude to guide multiple tasks/projects simultaneously.
  • Experience deploying tools to AWS and familiarity using Cloud based platform for assessment.
Responsibilities
  • Drive incident response engagements to guide our customers through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations.
  • Coordinate and guide incident response assistance from team members and vendors.
  • Investigate customer data breaches and malicious activity leveraging forensics tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other log sources to identify evidence of malicious activity.
  • Lead proactive cybersecurity advisory and consulting engagements such as: Tabletop Exercises: lead and facilitate tabletop exercises designed to simulate real-world cyber incidents, helping clients enhance their incident response preparedness and resilience. Assessments: conduct comprehensive cybersecurity assessments to evaluate clients' security postures, identify vulnerabilities, and provide actionable recommendations for improvement. Documentation Reviews: evaluate and refine clients' incident response plans, policies, and procedures to ensure they align with industry best practices and regulatory requirements.
  • Provide strategic guidance to clients on enhancing their security architectures, cloud security strategies, and compliance frameworks such as NIST, HIPAA, and PCI.
  • Collaborate with clients to develop and implement longer-term remediation strategies to strengthen their security postures.
  • Contribute to the refinement and improvement of internal processes, methodologies, and service offerings based on your consulting insights and industry expertise.
  • Provide case reporting as required across internal and external audiences with the appropriate technical level of detail for threat researchers and/or business customers.
  • Evaluate customer security programs, technologies, controls, and business environments; recommend and develop enhancements.
  • Provide recommendations on solutions to help customers navigate information security risk.
  • Track emerging security practices and contribute to building internal processes, and our various products.
  • Stay abreast of the current regulatory environment, industry trends and related implications.
Desired Qualifications
  • Security policy, governance, privacy or regulatory experience (e.g., NIST, ISO, HIPAA, PCI).
  • Securing cloud based platforms (Microsoft Azure, Amazon AWS, etc.).
  • Experience with system hardening procedures for Windows, Linux, Unix is helpful.
  • Knowledge and/or experience with Nmap, Nessus, Nexpose, Qualys, Burp, Kali, Metasploit, Meterpreter, or other offensive tools is helpful.
  • Knowledge of scripting for development of security tools and industry frameworks is helpful.
  • SCADA/Control systems network experience is a plus.

Coalition provides Active Insurance, which combines insurance coverage with cybersecurity tools to help businesses prevent digital risks. Their products are designed to assist companies in managing and reducing the chances of cyber attacks. Coalition offers its services to policyholders in the U.S., U.K., Canada, and Australia, working with top global insurers and its own insurance company. A key feature of Coalition is its cyber risk management platform, Coalition Control, which delivers automated alerts, expert advice, and third-party risk management. Additionally, Coalition Security Labs focuses on research and education in cybersecurity, providing valuable insights to help businesses understand and navigate the changing landscape of cyber threats.

Company Size

501-1,000

Company Stage

Series F

Total Funding

$770M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Secured $205M funding, raising valuation to $3.5 billion, supporting tech-driven cyber risk approach.
  • Serves over 52,000 businesses, reporting 70% fewer claims than industry average.
  • Global cyber insurance market expected to grow to $20.4 billion by 2025.

What critics are saying

  • Increased competition from companies like Hawk AI in cybersecurity tools.
  • Integration challenges from acquiring Jumbo may divert focus from core operations.
  • High valuation may lead to investor pressure for quick returns, impacting long-term strategy.

What makes Coalition unique

  • Coalition is the first Active Insurance provider focusing on digital risk prevention.
  • Combines insurance with cybersecurity tools for comprehensive risk management.
  • Offers global cybersecurity solutions with a focus on proactive threat mitigation.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Enjoy a highly fulfilling, mission-driven culture

Health, dental, and vision benefits for you and your family

Life insurance and disability benefits

Paid parental leave

401(k) plan

Wellness and commuter benefits

Flexible working hours

Open vacation days

We embrace distributed work; some benefits will vary by location

You are an owner. We offer stock options to each of our employees

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

1%
Coalition Inc.
May 17th, 2025
Coalition secures $205M in funding

Coalition has secured $205 million in funding from Durable Capital Partners, T. Rowe Price Associates, Whale Rock Capital Management, and existing investors, raising its valuation to $3.5 billion. This investment supports Coalition's technology-driven approach to cyber risk and will help expand its offerings and enhance its platform. Coalition serves over 52,000 businesses in North America and reports 70% fewer claims than the industry average.

PYMNTS
Apr 8th, 2025
Hawk Raises $56 Million To Help Banks Counter Financial Crime

Fraud and money laundering prevention provider Hawk has raised $56 million in new funding. The Germany-based company says its Series C round, announced Tuesday (April 8), will help it finance further product innovation and fuel expansion efforts, especially in the U.S. “Hawk enables banks to move beyond the traditional rules-based approach to anti-money laundering and fraud,” the company said in a news release. “Traditional systems create significant problems for compliance teams, including huge volumes of false positive alerts that need to be reviewed, which in turn leads to staffing challenges and costs.”

Business Wire
Mar 4th, 2025
Coalition and MS&AD Insurance Group Expand Strategic Partnership with Equity Investment

Coalition, the world's first Active Insurance provider designed to prevent digital risk before it strikes, today announced a new $30 million equity in

Coalition Inc.
Nov 30th, 2023
Coalition Closes Series F Funding Round of $250 Million | Coalition Blog

Coalition completed its Series F funding round in June, adding $250 million from Allianz X, Valor Equity Partners, Kinetic Partners and existing investors.