ApplySarthi

Senior Incident Response Analyst, MDR

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

This role on the market

146 open incident roles across 53 companies are on ApplySarthi right now, most of them in Bengaluru (9), Pune (1), Delhi NCR (1).

What incident roles keep asking for: AWS (41%), GCP (23%), Python (21%), SIEM (19%), Azure (16%), Stakeholder management (14%), Linux (13%), SaaS (12%) — counted across their open postings here.

Jobgether has 4,275 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for incident roles keep coming back to AWS, GCP, Python, SIEM. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. Tell me about an analysis that changed a decision. What did you find?
  3. How do you check that your numbers are right before you share them?
  4. Walk me through a dashboard or report you built. Who used it, and for what?
  5. Explain a join or a window function you have used, and why you needed it.

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Senior Incident Response Analyst, MDR at Jobgether interview free →

Accountabilities: Lead complex incident investigations involving advanced adversaries, multi-vector intrusions, and compromise across multiple environments. Serve as the primary Incident Advisor or designated Commander for high-severity and critical security engagements. Direct investigative, forensic, and containment activities across multiple analysts and response teams. Establish investigation strategies, priorities, and containment approaches based on business risk, technical findings, and incident impact. Validate, correlate, and synthesize technical findings into clear and actionable recommendations for customers and internal stakeholders. Provide technical leadership, mentorship, and oversight to incident response and security operations analysts. Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to validate detections, identify visibility gaps, and improve defensive capabilities. Lead or contribute to post-incident reviews and translate lessons learned into improvements to playbooks, tools, processes, and response workflows. Maintain accurate records of time and activities to support operational visibility, resource planning, and capacity management. Communicate effectively with customer stakeholders, including senior and executive-level audiences, throughout critical incidents. Requirements At least 5 years of professional experience in incident response, managed detection and response, cybersecurity investigations, or a closely related field, including leadership of complex incidents. Advanced expertise in endpoint and network forensics, log analysis, and adversary tactics, techniques, and procedures. Strong understanding of enterprise network architecture, IT infrastructure, and security environments. Proven ability to lead investigations, validate technical findings, assess risk, and develop effective containment strategies. Experience translating complex technical findings into concise, actionable guidance for customers and senior stakeholders. Demonstrated ability to mentor analysts and provide technical leadership within incident response or security operations teams. Strong decision-making, analytical, and problem-solving skills, with the ability to operate effectively under pressure and within time-sensitive situations. Strong customer-facing communication and presentation skills, including the ability to brief executive audiences during security incidents. Willingness to participate in an occasional weekend and holiday rotation. Advanced incident response or digital forensics certifications such as GCFA, GCED, GCIH, OSCP, or equivalent are an asset. Experience serving as an Incident Advisor or Commander during critical engagements is an asset. Cybersecurity publications, presentations, community contributions, or other recognized industry involvement are considered an advantage. Experience influencing detection strategies, security tooling, or cybersecurity service design is an asset. Benefits Base salary ranging from $131,000 to $219,000 CAD per year . Additional compensation opportunities, including bonus eligibility. Comprehensive employee benefits package. Remote-first working model, with remote work as the primary option for most positions. Employee-led diversity and inclusion networks supporting community, education, and advocacy. Paid volunteer days and opportunities to participate in charitable and fundraising initiatives. Employee sustainability initiatives supporting environmental responsibility. Global fitness and trivia activities. Global wellbeing days and monthly wellbeing webinars and training. Inclusive work environment with accommodations available throughout the recruitment and selection process. Opportunity to work on advanced cybersecurity investigations and collaborate with specialists across incident response, threat intelligence, SOC, and detection engineering.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-02. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.