> Markdown version of [/jobs/ext/2708182-incident-responder](https://www.wearedevelopers.com/jobs/ext/2708182-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Responder - **Company:** BlackCloak, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Android Software Development, Apple IOS, Apple Mac Systems, Cyber Security, Linux, Digital Forensics, Fraud Prevention and Detection, Software Vulnerability Management, Information Technology - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-incident-responder-blackcloak-9802761 ## About the Role BlackCloak's mission is to protect corporate executives and high-profile individuals in their personal lives, mitigating risks to their families, companies, reputation, and finances. We defend our clients' digital lives from hackers, privacy leaks, and identity theft. If you are passionate about helping to protect others, then keep reading - this may be your next great opportunity., If you excel at guiding clients through high-stress situations, possess deep technical expertise in digital forensics, and have a proven track record of handling sophisticated threats targeting high-profile individuals, this is an opportunity to elevate your career and make a tangible impact., * 5-8+ years of experience in a dedicated Incident Response, Digital Forensics (DFIR), or advanced cybersecurity analyst role. * Proven track record executing the full incident lifecycle, particularly involving personal/executive account takeovers, mobile threats, and endpoint malware. * Demonstrated experience investigating fraud in financial transactions, including direct coordination with banks and credit card companies - fraud investigation, disputes and chargebacks, transaction analysis, or account takeover response. This may have been gained at a financial institution, card issuer, payment processor, fintech risk team, financial crimes unit, or in a security role working these cases directly. * Deep technical expertise conducting forensics and vulnerability management across Windows, macOS, iOS, Android, and Linux ecosystems. * Working command of identity theft remediation and attack kill chain models, with the ability to apply them to an individual and their family rather than an enterprise network. * Advanced industry certifications are highly preferred (e.g., GCIH, GCFA, CISSP, OSCP, or similar); fraud and financial crime credentials such as CFE, CFCS, or CAMS are a strong plus. * Exceptional communication skills with the ability to translate technical jargon into actionable advice for non-technical clients, maintaining deep empathy and composure during high-stress crises. * College degree in an Information Technology (IT/CS/CE) discipline or equivalent real-world experience, coupled with the ability to operate highly independently. ## Description BlackCloak is seeking a seasoned and highly skilled Senior Incident Responder to join our Technical Success Team. This is a senior, client-facing individual contributor role for someone who has spent years on both sides of the problem: the technical compromise of computers, phones, and online accounts, and the financial fraud that so often follows it. In this critical role, you will serve as the primary escalation point and lead investigator for complex security events; taking ownership of the full incident response lifecycle, from initial triage and containment through eradication, recovery, and post-incident reporting., * Execute End-to-End Incident Response: Lead comprehensive incident handling consistent with core IR principles (NIST/SANS) from the initial client request and triage through containment, recovery, and post-incident lessons learned. * Investigate Complex Compromises & Targeted Attacks: Manage and remediate severe client security incidents, including but not limited to, compromised email ecosystems, SIM swap attacks, financial account takeovers, and targeted credential harvesting. * Device Analysis: Conduct analysis on client computers and mobile devices to assess the scope of compromise and implement effective remediation strategies. * Remediate Fraud & Identity Theft: Analyze and assess account activity and transaction records available to the client on their email, banking, retail, and social platforms to help establish what occurred, and support clients in their conversations with the platforms on fraud investigations, disputes, account freezes, etc.. Guide identity theft victims through the remediation process - credit bureau freezes and fraud alerts, IdentityTheft.gov and law enforcement reporting - and advise clients on the activity they should watch for and report back to the team. * Map the Attack Chain: Map observed activity against the personal attack kill chain - from data-broker reconnaissance and social engineering of the client's inner circle through device compromise, account takeover, and financial monetization - to identify the likely stage of an attack and the actions that break the chain, focusing on technique and exposure rather than actor attribution. * Provide White-Glove Client Support: Interface directly with clients and, where authorized, their families and support staff - assistants, family office, corporate security - during high-stakes emergency onboardings and active incidents, providing calm, clear, and authoritative guidance while communicating complex threat assessments. * Participate in On-Call Rotation: Serve in an on-call and escalation rotation that requires occasional nights and weekends to address client incidents, emergency onboardings, and time-sensitive issues. * Lead & Mentor: Serve as the highest technical escalation point in the on-call rotation, while actively mentoring Security and Client Success team members to elevate the team's overall technical proficiency. * Enhance Security Posture: Oversee network vulnerability scans of client infrastructure, proactively refine internal IR playbooks, and conduct periodic post-onboarding touchpoints. Note: This role requires occasional nights and weekends to address emergency client incidents. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)