We’re Hiring: Incident Responce Engineer – Ransomware First Responder (Remote, U.S.)
Company:
Proven Data
Location:
Remote (U.S. Only)
Type:
Full-Time Flexible Business Hours
Proven Data is seeking a highly skilled
Incident Responder
to serve as a
first point of contact
for ransomware victims. In this role, you’ll play a critical part in our digital forensics and incident response (DFIR) operations by rapidly assessing active ransomware events, containing threats, and helping clients navigate the recovery process.
Responsibilities:
Triage inbound ransomware incidents and assess scope/severity
Coordinate containment actions with clients (e.g., isolating infected systems)
Perform initial forensic analysis and collect volatile data
Interface with clients during high-pressure situations, maintaining calm and professionalism
Work with internal teams to escalate cases to senior DFIR analysts
Maintain accurate documentation throughout the response lifecycle
Requirements:
2+ years of experience in incident response or cybersecurity operations
Strong knowledge of ransomware behavior, variants, and containment strategies
Familiarity with forensic tools (e.g., FTK Imager, Magnet, KAPE) and EDR platforms
Excellent communication skills – both written and verbal
Able to work independently and manage multiple high-priority incidents
Experience handling cases involving Windows, Linux, and cloud environments
Bonus:
Experience with negotiation and data recovery efforts
Knowledge of MITRE ATT&CK, NIST IR framework, or similar methodologies
Industry certifications (e.g., GCFA, GCIH, CCE, or similar)
Join a mission-driven team helping victims of cybercrime regain control and protect their data.
Apply now or DM us for more info.