SOC Lead Incident Responder - Confidential

Post Date

Jun 24, 2026

Location

Medford,
Oregon

ZIP/Postal Code

97501
US
Sep 24, 2026 Insight Global

Job Type

Contract-to-perm

Category

Security Engineering

Req #

POR-d2646e99-a13b-45fe-818d-4b98b6118ce7

Pay Rate

$40 - $50 (hourly estimate)

Job Description

The SOC Lead Incident Responder (Tier 1) serves as the primary point of contact for security alerts and is responsible for triaging, investigating, and leading the response to cybersecurity incidents as part of the SOC team. This is a hands-on technical role focused on rapid detection and containment using the organization's Microsoft security stack. While not a people-management position, the responder takes the lead on coordinating incident response activities and guiding fellow analysts through the response process.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience

• Hands-on experience with Microsoft Sentinel (Azure SIEM): alert triage, investigation, and basic KQL queries.
• Proficiency with Microsoft Defender (EDR): endpoint investigation, alert analysis, and containment actions.
• Working knowledge of Microsoft Entra ID: identity protection, sign-in log analysis, and conditional access concepts.
• Solid understanding of incident response fundamentals (detection, triage, containment, eradication, recovery, lessons learned).
• Familiarity with common attack techniques and frameworks (e.g., MITRE ATT&CK).
• Strong analytical, communication, and documentation skills.
• Ability to remain calm and lead under pressure during active incidents.

Nice to Have Skills & Experience

• Relevant certifications such as SC-200, AZ-500, CompTIA Security+, or equivalent.
• Prior experience in a SOC or incident response environment.

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.