> Markdown version of [/jobs/ext/1506389-associate-principal-incident-responder](https://www.wearedevelopers.com/jobs/ext/1506389-associate-principal-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Associate Principal Incident Responder - **Company:** Dragos, Inc. - **Location:** Hanover, MD, United States (Remote available) - **Experience:** Expert - **Salary:** $155,000.0 - **Contract:** Permanent contract - **Skills:** Digital Forensics, Cyber Threat Analysis, Operational Systems, Purple Team (Cyber Security) - **Published:** July 30, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17747300?backUrl=%2Fcareer%2F17747300%2FAssociate-Principal-Incident-Responder-Maryland-Hanover ## About the Role * 8+ years of hands-on incident response and digital forensics experience with proficiency in at least two forensics domains (network, hardware, memory, disk) -- methodology is more important than tool specialization. * Proven experience in ICS/OT cybersecurity including knowlege of industrial architecture, threat landscapes, vulnerabilities, and applicable frameworks and standards. * Proven ability to lead end-to-end investigations, correlate events across multiple data types, and uncover threats through methodical analysis and pivoting. * Proven incident management and communication ability: able to manage coordination during incidents, guide customers calmly and confidently through high-pressure situations, and author customer-facing documentation, playbooks, and executive briefings. * Consulting and advisory experience translating technical depth into strategic customer guidance, incident response planning, and recommendations for advancing incident readiness and response maturity. * Ability to work independently and remotely while coordinating effectively across distributed teams. * Willingness to travel up to 40% (domestic and some international) ## Description Our Professional Services team is hiring an Associate Principal Incident Responder to lead Operational Technology (OT) incident response investigations and advance customer OT IR maturity. This is primarily an incident response role with a strong consulting component: you will lead active response engagements and deliver advisory work, including maturity assessments, incident response planning workshops, tabletop exercises, retainer onboarding, and purple team engagement. You will be responsible for supporting improvements to the Dragos IR methodology. You will represent Dragos as a thought leader through community engagement. This role suits practitioners who are equally strong at executing investigations and advising customers on strategy, and who treat incident response planning and maturity work as core expertise rather than a secondary responsibility., * Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, compromise assessments, and on-call response across onsite and remote environments. * Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks, standard operating procedures, and response methodologies * Develop and deliver advisory services including incident response planning workshops, maturity assessments, playbook design, and tabletop exercises that advance customer readiness. * Manage customer relationships across onboarding, strategic advisory engagements, and stakeholder communication to align response capabilities with evolving business risk. * Contribute to research, threat analysis, and thought leadership (whitepapers, webinars, presentations) that influence Dragos methodology and training. * Mentor and develop teammates through hands-on training and incident guidance; serve as technical escalation point and role model for operational excellence. * Drive delivery accountability for quality, timeliness, and utilization; partner with internal teams on service expansion, scalability improvements, and represent Dragos mission to customers and industry. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Enterprise Linux as Container Images](https://www.wearedevelopers.com/videos/1610-enterprise-linux-as-container-images) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)