Dragos
via Greenhouse
Associate Principal Incident Responder
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 48d ago
The date the source published, not the day we noticed it (2026-07-29). Last seen at its source just now.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay
$170k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 12d ago · last seen just now
The listing
At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are immediately at risk. We are the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand what is at stake. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.
About the Role:
Our Professional Services team is hiring an Associate Principal Incident Responder to lead Operational Technology (OT) incident response investigations and advance customer OT IR maturity. This is primarily an incident response role with a strong consulting component: you will lead active response engagements and deliver advisory work, including maturity assessments, incident response planning workshops, tabletop exercises, retainer onboarding, and purple team engagement. You will be responsible for supporting improvements to the Dragos IR methodology. You will represent Dragos as a thought leader through community engagement. This role suits practitioners who are equally strong at executing investigations and advising customers on strategy, and who treat incident response planning and maturity work as core expertise rather than a secondary responsibility.
Responsibilities:
- Lead and execute incident response engagements for OT customers as Incident Commander, including triage, investigations, threat hunts, compromise assessments, and on-call response across onsite and remote environments.
- Conduct post-incident reviews, root-cause analysis, and integrate lessons learned into playbooks, standard operating procedures, and response methodologies
- Develop and deliver advisory services including incident response planning workshops, maturity assessments, playbook design, and tabletop exercises that advance customer readiness.
- Manage customer relationships across onboarding, strategic advisory engagements, and stakeholder communication to align response capabilities with evolving business risk.
- Contribute to research, threat analysis, and thought leadership (whitepapers, webinars, presentations) that influence Dragos methodology and training.
- Mentor and develop teammates through hands-on training and incident guidance; serve as technical escalation point and role model for operational excellence.
- Drive delivery accountability for quality, timeliness, and utilization; partner with internal teams on service expansion, scalability improvements, and represent Dragos mission to customers and industry.
Qualifications:
- 8+ years of hands-on incident response and digital forensics experience with proficiency in at least two forensics domains (network, hardware, memory, disk) -- methodology is more important than tool specialization.
- Proven experience in ICS/OT cybersecurity including knowlege of industrial architecture, threat landscapes, vulnerabilities, and applicable frameworks and standards.
- Proven ability to lead end-to-end investigations, correlate events across multiple data types, and uncover threats through methodical analysis and pivoting.
- Proven incident management and communication ability: able to manage coordination during incidents, guide customers calmly and confidently through high-pressure situations, and author customer-facing documentation, playbooks, and executive briefings.
- Consulting and advisory experience translating technical depth into strategic customer guidance, incident response planning, and recommendations for advancing incident readiness and response maturity.
- Ability to work independently and remotely while coordinating effectively across distributed teams.
- Willingness to travel up to 40% (domestic and some international),
Compensation:
- Salary: $170,000
- Competitive Equity Package
- Comprehensive Benefits Plan
#LI-JF1 #LI-REMOTE
Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.