> Markdown version of [/jobs/ext/2567312-incident-response](https://www.wearedevelopers.com/jobs/ext/2567312-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response - **Company:** Crowe's Consulting - **Location:** United States - **Salary:** $56,160.0 - $87,360.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Bash Shell, CompTIA Network+, CompTIA Security+, Cyber Security, Linux, Digital Forensics, Python (Programming Language), Microsoft Security Essentials, Windows PowerShell, Security Information and Event Management, Scripting, Office365, Azure Security Center, Information Technology, Microsoft Sentinel, Gsuite, Splunk, SentinelOne Expertise - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/7b8f0a99-f9ba-4ed8-8824-7ff28b288f6c ## About the Role * Excellent problem-solving and analytical skills, with keen attention to detail. * Strong communication and interpersonal skills to effectively collaborate with team members and clients. * Proven adaptability and a strong drive to learn and master new technologies. * Ability to maintain focus and composure in high-stress situations. * Willingness to travel up to 5% of the time or more, as required. * Commitment to continually expanding skillsets and knowledge, with a proven track record of doing so. * Experience in troubleshooting technical issues or investigating security incidents. * Understanding of networking, cybersecurity, and IT concepts. * Preferred Qualifications: * Experience responding to security incidents in a professional setting. * Relevant certifications such as CompTIA Network+, Linux+, Security+, CySA+, GIAC Security Essentials, Microsoft Security Operations Analyst, or AWS Certified Security - Specialty. * Experience working in a Security Operations Center (SOC) environment. * Familiarity with major cloud platforms such as AWS, O365, and Google Workspace. * Experience with EDR tools like SentinelOne, CrowdStrike, Carbon Black, or Microsoft Defender for Endpoint. * Proficiency in utilizing SIEM or log aggregation tools such as Splunk, Elastic, or Microsoft Sentinel. * Understanding of basic scripting and command interpreter usage (e.g., Bash, PowerShell, Python)., Currently pursuing a bachelor's or master's degree in: * Computer Science * Information Technology * Management Information Systems * Cybersecurity, or equivalent educational experience (such as a bachelor's degree in a related field, or relevant certifications)., We are committed to a merit-based hiring process, evaluating all candidates consistently using objective, job-related criteria such as relevant experience, demonstrated skills, measurable impact, and alignment with the role's responsibilities, and making employment decisions in a fair and inclusive manner free from discrimination. ## Description What It Means to Be a Consultant at Crowe Consulting is a dynamic business focused on solving problems for our clients and serving our core markets through innovative solutions. As technology and AI continue to reshape the consulting landscape, we are looking for individuals who are curious, adaptable, and eager to learn. At Crowe, consultants are expected to build both technical and transferable skills, think critically, and use technology to solve real business problems. In this role, you will continuously learn, collaborate across teams, and explore how tools, including emerging AI capabilities, can improve efficiency, insights, and client outcomes. As you grow, you'll also begin to take ownership of client relationships, contribute to account strategy, and support the delivery of high-impact work. Developing a sense of account leadership, including understanding client needs, ensuring delivery excellence, and building trusted partnerships, is part of what sets successful consultants apart. Success in this role comes from a growth mindset, strong communication skills, advanced critical thinking, and the ability to navigate new challenges with confidence. The Incident Response role in Crowe's Consulting Practice, is a position designed for individuals eager to broaden their career in cybersecurity, specifically within the realm of incident response (IR). This role offers a unique opportunity to grow by engaging in the repeatable aspects of incident response, such as forensic collection, console/log review, and basic threat hunting. The successful candidate will work on an IR team to support and enhance our client's cybersecurity posture, ensuring the protection of client data and systems under fire. This position is ideal for those who are passionate about cybersecurity and are looking to develop their skills in a dynamic and supportive environment. As part of the Incident Response (IR) team, your responsibilities will include coordinating with team members to effectively execute and collaborate on incident response engagements. You will review and analyze security events and incidents to identify potential threats and vulnerabilities, as well as assist in the collection of digital forensic evidence to support ongoing investigations. Your role will involve conducting proactive threat hunting activities using Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) tools. Additionally, you will be responsible for reviewing and generating detailed reports based on client-provided metrics and investigation findings. When necessary, you will also participate in on-site incident response engagements, working closely with other on-site personnel to address and mitigate security incidents in real-time. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)