Senior Incident Response Analyst
Coalition
Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines broad insurance coverage with a digital risk assessment and continuous security monitoring to help organizations protect themselves in today’s hyper-connected world.
Coalition offers its Active Insurance products in the U.S., U.K., and Canada through relationships with leading global insurers including Allianz, Arch Insurance, Lloyd’s of London, Swiss Re and Zurich, as well as cyber capacity through its own carrier, Coalition Insurance Company. Coalition's Active Risk Platform provides automated security alerts, threat intelligence, expert guidance, and cybersecurity tools to help businesses worldwide remain resilient against cyber attacks.
Coalition comprises a team of cybersecurity and technology experts, as well as experienced insurance professionals, who have come together to build a world-class organization with a massive technological advantage. Our secret sauce is bringing these expertise together to create a world-class organization with one mission: to protect the unprotected as the world digitizes. Today, Coalition is one of the world’s largest commercial insurtechs serving hundreds of thousands of customers worldwide.
Since its founding, Coalition has raised $755 million in equity funding, including $250 million in June 2022, affirming its ability to deliver profitable growth and cementing its position as a long-term business with a clear competitive advantage.
Coalition’s exceptional growth stems from its ability to address real-world problems for organizations of all sizes, and by remaining true to our founding values of character, humility, responsibility, purpose, authenticity and inclusion. We are proud to have been named among Inc.’s Best Workplaces in 2021 and 2023, and one of Fast Company’s Most Innovative Companies in 2022.
Responsibilities
- Work under the direction of IR lead and outside counsel to conduct IR investigations
- Fulfill consumer requests and resolve incidents received via e-mail or internal ticketing systems in a timely and detail-oriented manner
- Guide all consumer interactions professionally with a strong emphasis on consumer satisfaction
- Assess and assess security incidents and escalate to appropriate internal teams for additional assistance
- Triage and scope incidents for prospective consumers to identify the DFIR objectives and magnitude of effort involved to satisfy objectives
- Provide strategic, relevant, and achievable recommendations to help advance the security posture of organizations during and after an incident
- Communicate effectively with consumers (executives and IT) on the topics of incident type, remediation, forensics and assessment
- Perform host and network-based forensics across Windows, Mac, and Linux platforms as well as cloud environments
- Deliver high-quality written and verbal reports, recommendations, and findings to key stakeholders including consumers and legal counsel
- Participate in, or work directly on additional projects, assignments, or initiatives as required
- Mentor and coach team members and work effectively as part of team unit
- Develop, evaluate and utilize novel methods to hunt for indicators of compromise and perform assessment across large sets of data
- Assist in the development of internal guidelines, playbooks and knowledge base
- Demonstrate industry thought guidance through blog posts and occasional public speaking events
Skills and Qualifications
- 3-5 years of professional experience (2 years directly related to IR or functional area) or equivalent combination of education and experience
- Bachelor's degree in digital forensics, cybersecurity, computer science, information systems or similar field
- Working as part of a team in a remote matrixed consulting environment
- Incident Response: conducting or overseeing IR investigations for organizations, answering to opportunistic and targeted threats such as BECs, FTFs, ransomware and APTs
- Digital Forensic Analysis: a background in using different forensic assessment tools in incident response investigations to ascertain the extent and scope of compromise and possessing creativity and reason in approaching intricate forensic problems
- Incident Remediation: strong knowledge of opportunistic and targeted attacks and aptitude to generate customized strategic and tactical remediation plans for consumers
- Network Forensic Analysis: strong knowledge of networking protocols, network assessment tools, and aptitude to perform assessment of associated network logs
- SOC and EDR: experience with EDR solutions and leveraging detections and analytics to mitigate threats appropriately
- Possessing a knowledge of secure network architecture and a strong knowledge of networking fundamentals
- Cloud Incident Response: knowledge in AWS, Azure, GCP incident response strategies
Additional Skills and Qualifications
- Excellent critical thinking skills with the experience to diagnose and troubleshoot technical issues
- Customer oriented with a strong interest in consumer satisfaction
- Experience to learn new technologies and concepts and comfortable using command-line interfaces
- Experience guiding teams of highly motivated analysts
- Communicate highly technical information to a non-technical audience
- Experience to handle and work with consumers through high priority scenarios
- Knowledge in project management
- Foster a positive work environment and attitude
- Flexibility with your work schedule in times of urgent response needs
- Contribute to thought guidance within the DFIR industry
Bonus Points
- GCIH, GCIA, GCFA, GCFE, ACE, EnCE, CFCE, CISSP, or similar
Perks
- 100% medical, dental and vision coverage
- Flexible PTO policy
- Annual home office stipend and WeWork access
- Mental & physical health wellness programs (One Medical, Headspace, Gympass, and more)!
- Competitive compensation and opportunity for advancement
- Our compensation reflects the cost of labor across several US geographic markets. The US base salary for this position ranges from $115,000/year in our lowest geographic market up to $185,000/year in our highest geographic market. Consistent with applicable laws, an employee's pay within this range is based on a number of factors, which include but are not limited to relevant education, skills, job-related knowledge, qualifications, work experience, credentials, and/or geographic location. Your recruiter can share more on target salary for your location during the interview process. Coalition, Inc. reserves the right to modify this range as needed.
#LI-Remote
To learn more, check out our featured press releases:
- Coalition Closes $250 Million in Series F Funding, Valuing the Cyber Insurance Provider at $5 Billion
- Coalition Named to Fast Company’s Annual List of of the World’s Most Innovative Companies for 2022
- Coalition Launches Active Insurance, Reaches $650M Run Rate GWP
- Coalition launches tech-powered executive risks products with personalized risk assessment for all US small-businesses