2

Remote Cyber Incident Responder Jobs (NOW HIRING)

Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT ... Remote-first culture * Competitive compensation * Flexible Paid Time Off policies , including but ...

As a Senior Incident Responder, you will play a crucial role as an independent contributor and an ... Remote Company, within the USA - Comprehensive Medical, Dental, and Vision plans with a 100 ...

Notify designated managers, cyber incident responders, and cybersecurity service provider team members of suspected cyber incidents and articulate the event's history, status, and potential impact ...

next page

Showing results 1-20

Remote Cyber Incident Responder information

See salary details

$65.5K

$116K

$162K

How much do remote cyber incident responder jobs pay per year?

As of Aug 6, 2026, the average yearly pay for remote cyber incident responder in the United States is $116,028.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,000.00 and $130,000.00 per year, depending on experience, location, and employer.

How does a remote cyber incident responder typically coordinate with on-site IT teams during an active security incident?

Remote Cyber Incident Responders often collaborate closely with on-site IT teams through secure communication channels such as video calls, chat platforms, and incident tracking systems. During an active incident, they guide on-site staff in collecting forensic data, deploying containment measures, and implementing remediation steps. Clear communication and documentation are crucial, as responders must ensure that all actions are coordinated to minimize downtime and data loss. Building strong working relationships with on-site teams helps streamline the response process and ensures a unified approach to resolving security threats.

What does a remote cyber incident responder do?

A Remote Cyber Incident Responder is a cybersecurity professional who detects, analyzes, and responds to cyber threats and security incidents from a remote location. Their primary responsibilities include investigating security breaches, containing threats, recovering affected systems, and providing recommendations to prevent future incidents. They use specialized tools to monitor networks, analyze digital evidence, and coordinate with other IT teams to mitigate risks. Working remotely allows them to support organizations regardless of physical location, ensuring quick response to cyber incidents.

What is the difference between Remote Cyber Incident Responder vs Remote Security Analyst?

AspectRemote Cyber Incident ResponderRemote Security Analyst
CertificationsGCIH, CISSP, CEHCISSP, Security+, CEH
Work EnvironmentResponds to active security incidents, often in crisis situationsMonitors security systems, analyzes threats, and implements security measures
Employer & Industry UsageCybersecurity firms, large corporations, government agenciesOrganizations with security teams, IT departments, consulting firms

Remote Cyber Incident Responders focus on reacting to and managing active security breaches, while Remote Security Analysts monitor systems and analyze threats proactively. Both roles require similar certifications and often work within the same industry environments, but their core responsibilities differ in response versus prevention.

What are the key skills and qualifications needed to thrive as a remote cyber incident responder, and why are they important?

To thrive as a Remote Cyber Incident Responder, you need a strong background in cybersecurity, digital forensics, and incident response, often supported by a relevant degree and certifications like CEH, CISSP, or GIAC. Familiarity with SIEM tools, endpoint detection and response (EDR) platforms, and forensic analysis software is typically required. Exceptional analytical thinking, problem-solving abilities, and clear communication are vital soft skills for assessing threats and coordinating with remote teams. These skills and qualifications are crucial for quickly identifying, containing, and mitigating cyber threats to protect organizational assets in a remote work environment.
More about Remote Cyber Incident Responder jobs
What cities are hiring for Remote Cyber Incident Responder jobs? Cities with the most Remote Cyber Incident Responder job openings:
What are the most commonly searched types of Cyber Incident Responder jobs? The most popular types of Cyber Incident Responder jobs are:
What states have the most Remote Cyber Incident Responder jobs? States with the most job openings for Remote Cyber Incident Responder jobs include:
Infographic showing various Remote Cyber Incident Responder job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, 1% Temporary, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $116,028 per year, or $55.8 per hour.

Full-time

Medical, PTO

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

About LastPass
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity. From discovering unapproved AI and applications to reducing login friction and securing credentials across the business, LastPass delivers on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected as their environments evolve.
Curious about our products? Visit our website and try it free!
We welcome new ideas, support your growth, and recognize your value, if this aligns with what you are looking for in your next career move, Join Us!
LastPass is looking for an Incident Responder:
In this senior role, you will lead investigations end-to-end and advance our detection capabilities. You will own MSSP escalations, conduct threat hunts, and apply AI-assisted approaches - helping LastPass deliver on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected.
About the team:
Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence - sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.
If you are passionate about complex problem solving and motivated by scale, then this is the role for you!
Who will you work with?
You will partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel, and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations. You will also work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.
What are some of the exciting challenges you will be working on?
  • Own security incidents end-to-end - receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
  • Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
  • Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team
  • Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact
  • Apply AI-assisted approaches to triage, investigation, detection authoring, and automation - helping the team adopt these capabilities responsibly and effectively
  • Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity
  • Document investigations thoroughly - capturing actions, evidence, timelines, and conclusions - to a standard that supports both technical follow-up and stakeholder communication
  • Manage and strengthen the MSSP relationship by providing feedback on escalation quality, tuning alerting thresholds, and contributing to lessons-learned reviews

What does it take to work at LastPass?
  • Proven experience in incident response and security operations in cloud-native environments, with hands-on depth in Azure and AWS
  • Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
  • Proven experience working with an MSSP - managing escalations, providing quality feedback, and closing gaps in coverage - whether as client or vendor
  • Proven experience conducting threat hunts and building automation in support of security operations, including SOAR playbooks, scripting, and enrichment workflows
  • Strong command of attacker tactics, techniques, and procedures, the cyber kill chain, and MITRE ATT&CK, with solid grounding in networking fundamentals, cloud security domains, and identity systems including Active Directory and Entra ID
  • Communicates clearly with both technical and non-technical stakeholders, exercises sound judgment under pressure, and operates effectively both independently and as part of a collaborative team
  • Commitment to continuous improvement - proactively contributing to detections, runbooks, tooling, and operational processes that raise the bar for the team

It's great, but not required:
  • Familiarity with the Intelligence-Driven Incident Response approach, integrating threat intelligence into the detection, analysis, and response lifecycle
  • Experience interpreting network traffic and performing packet captures using tools such as tcpdump or Wireshark
  • Background in relevant industry certifications such as GCIH, GCIA, GCFA, AZ-500, or AWS Security Specialty

Our compensation reflects the cost of labor across several US geographic markets. Pay is based on several factors including market location and may vary depending on job-related knowledge, skills, and experience.
US Pay Range
$108,400-$130,000 USD
Why LastPass?
  • The leader in secure access
  • High-growth, collaborative environment with inclusive teams
  • Remote-first culture
  • Competitive compensation
  • Flexible Paid Time Off policies, including but not limited to: Quarterly Self-Care Days (4 extra paid days off annually) and Volunteer Days
  • Parental leave
  • Comprehensive health coverage, including dependents
  • Home office setup support
  • LastPass Families free account for up to 5 members
  • Continuous learning and development opportunities, including an annual learning stipend to invest in your growth
  • Peer-to-peer recognition through Motivosity
  • Employee Assistance Program for well-being support
  • Remote work stipend to support your home office needs
  • Short-Term or Remote-Centric Work Arrangements for added flexibility

Unlock your potential with us - your skills, experience, and unique perspective matter more than just checking the boxes. Apply today, and let's build the future together!
We're building an inclusive community that reflects the people of all races, genders, sexual orientations, national origins, backgrounds, and perspectives who share our world.
For all US based jobs please review our Applicant Privacy Notice
For all EU based jobs please review our Candidate Privacy Notice
Please review our CCPA Notice