Principal Incident Response Analyst
North - Remote
The Principal Incident Response Analyst is a seasoned, deeply experienced incident response expert who runs North's most complex security incidents from detection through recovery, without supervision.
Incident response is the primary area of expertise for this role, complemented by strong secondary expertise in detection engineering and tertiary expertise in threat hunting. The Principal Incident Response Analyst serves as the top escalation point for security incidents, sets the technical standard for how the organization investigates and contains threats, and mentors other engineers and analysts on incident handling practice. This role works closely with the SOC, IT, and engineering teams, and represents the deepest incident response expertise on the security team, operating across our payment processing environment.
What You'll do:
Incident Response
Serve as the principal escalation point and lead investigator for the most complex, highest-severity, and novel security incidents, running them end to end without supervision
Independently triage, investigate, contain, eradicate, and recover from security incidents spanning endpoint, network, cloud, identity, and application layers
Lead full-scope forensic investigations of compromised hosts, accounts, applications, and cloud infrastructure, and reconstruct complete attack timelines from initial access through impact
Translate complex investigation findings into clear narratives for engineering teams and clear executive-level narratives for leadership
Own and continuously evolve incident response process, documentation, and playbooks, incorporating lessons learned from real incidents
Lead root cause analysis and structured post-incident reviews, and drive cross-team remediation of systemic gaps
Serve as the senior technical lead during major incidents, coordinating across IT, legal, compliance, and executive leadership as needed
Provide case-level guidance and mentorship to other incident responders and SOC analysts during live incidents
Participate in or lead on-call rotation for critical incident response as needed
Detection Engineering
Translate incident findings and root cause analysis directly into new or improved detection logic, closing the loop between investigation and prevention
Write, tune, and validate detection content in the SIEM/NG-SIEM platform, focused on techniques observed in real investigations and threat hunts
Maintain and improve coverage and gap analysis against the MITRE ATT&CK framework, informed by incident and hunt findings
Review detection logic for accuracy and false-positive rate, and partner with the detection engineering team on rule quality
Contribute documentation of known coverage and detection gaps surfaced through incident response and hunting work
Threat Hunting
Conduct proactive, hypothesis-driven threat hunts based on incident trends, emerging adversary TTPs, and threat intelligence
Use hunt outcomes to surface undetected compromises, validate detection coverage, and strengthen incident response readiness
Prioritize hunts against the techniques and attack paths most relevant to a payments/fintech environment
Partner with threat intelligence sources and feeds to inform hunt hypotheses and target selection
Document hunt methodology, findings, and follow-on actions, including new detections and updated incident response playbook material
Cross-Functional & Leadership
Represent incident response in cross-org planning, tabletop exercises, and architecture reviews
Lead complex, ambiguous incident-related investigations and initiatives independently from scoping through delivery
Mentor other engineers and analysts on incident response, detection engineering, and threat hunting practices
Partner with cloud, network, and identity teams to close visibility and telemetry gaps identified during incidents and hunts
Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment
Communicate findings, coverage gaps, and recommendations clearly to both technical and non-technical stakeholders, including leadership
Develop and maintain procedure and policy documentation supporting incident response operations
What we need from you:
License and Certification: Relevant hands-on experience and demonstrated subject-matter expertise are weighted more heavily than certifications for this role. Any of the following are preferred.
Salary range: $150,000-$180,000
Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.
Please note: North is a US based company and no sponsorship is available for this position at this time.
Who we are:
North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won't find anywhere else.
Let's go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling.
At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.
To learn more about North, and our family of companies, visit our website: north.com
| Location | MI |
| Salary | $150,000–$180,000 Per Year |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder