Associate Principal Incident Responder

DragosUnited StatesPosted July 29, 2026

Want this job? Aria tailors your résumé to this role and submits the application on the employer's own platform — on your behalf. Free to start.

About this role

At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.

About the Role:

Our Professional Services team is hiring an Associate Principal Incident Responder to lead Operational Technology (OT) incident response investigations and advance customer OT IR maturity. This is primarily an incident response role with a strong consulting component: you will lead active response engagements and deliver advisory work, including maturity assessments, incident response planning workshops, tabletop exercises, retainer onboarding, and purple team engagement. You will be responsible for supporting improvements to the Dragos IR methodology. You will represent Dragos as a thought leader through community engagement. This role suits practitioners who are equally strong at executing investigations and advising customers on strategy, and who treat incident response planning and maturity work as core expertise rather than a secondary responsibility.

Responsibilities:

• Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, compromise assessments, and on-call response across onsite and remote environments.

• Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks, standard operating procedures, and response methodologies

• Develop and deliver advisory services including incident response planning workshops, maturity assessments, playbook design, and tabletop exercises that advance customer readiness.

• Manage customer relationships across onboarding, strategic advisory engagements, and stakeholder communication to align response capabilities with evolving business risk.

• Contribute to research, threat analysis, and thought leadership (whitepapers, webinars, presentations) that influence Dragos methodology and training.

• Mentor and develop teammates through hands-on training and incident guidance; serve as technical escalation point and role model for operational excellence.

• Drive delivery accountability for quality, timeliness, and utilization; partner with internal teams on service expansion, scalability improvements, and represent Dragos mission to customers and industry.

Qualifications:

• 8+ years of hands-on incident response and digital forensics experience with proficiency in at least two forensics domains (network, hardware, memory, disk) -- met

Stop filling out applications one by one.