Invictus Incident Response
About the job
Invictus Incident Response is the specialist organization you call when cyber incidents exceed what generalist security providers can handle. We bring deep technical credibility, a growing open-source community, and a proven track record in cloud incident response. Our mission is to help organizations stay Invictus, undefeated against cyberattacks. More and more incidents unfold in the cloud, and that is exactly where we intend to be the best in the world.
This is a ground-floor role. We’re building out our US presence fast, and you’d be one of the first responders on the ground here. We’re still a startup, but we’re taking on the giants of the industry and winning so far. If you want your work to make a visible impact rather than disappear into a large team, this is that kind of role.
This is not an entry-level position. You’ll own investigations, from preserving evidence under pressure to telling a client exactly how the attacker got in and how to shut them out.
What you’ll do
- Help organizations hit by a cloud security incident, often under time pressure and high stakes.
- Preserve and analyze digital evidence across cloud environments (AWS, Microsoft Azure/M365, Google Cloud, etc.) to establish how attackers gained access.
- Work core cloud log sources such as AWS CloudTrail, Azure/Entra sign-in logs, and the Microsoft 365 Unified Audit Log.
- Investigate business email compromise and untangle attacks against identity and SaaS platforms.
- Advise clients on how to correctly contain, mitigate, and recover from an incident.
Beyond the response
- Improve our existing processes, playbooks, and tooling so the whole team responds faster.
- Contribute to our open-source tools and public knowledge-sharing through blogs, talks, or videos.
- Help us grow Invictus into the most valuable cloud incident response company in the world.
What we’re looking for
We’re looking for someone with:
- 5+ years of hands-on incident response experience that brings deep investigative and leadership experience.
- Confidence in at least one major public cloud (AWS, Azure/M365/Entra, or Google Cloud) and the motivation to go deep in the others.
- A strong grasp of the identity and SaaS attack surface, which is where more and more incidents now begin.
- Comfort using AI tools to speed up triage, analysis, and investigation, and the judgment to know where they help and where they don’t.
- Strong technical skills, because our clients’ problems are often complex and solving them is the job.
- Flexibility, because incident response is hard to plan and you’re comfortable with that reality.
- A bias toward initiative and ownership. You see opportunities and act on them without waiting for instruction.
- An entrepreneurial instinct for anticipating client needs and market shifts, not just the technical work.
Role details
- Full-time
- Fully remote (US, East Coast preferred but not required)
- Base salary: $75,000 to $125,000, plus meaningful equity and a performance bonus. As an early member of the US team, you share directly in the growth you help create.
- Benefits: Bonus, Equity, Health insurance, Retirement contribution, and 20+ days PTO
To apply for this job please visit www.linkedin.com.
