Rooted
Back to jobs
ER
Open role

Echelon Risk + Cyber

Incident Responder

Pittsburgh, Pennsylvania· HYBRID

Hacker+ signal

About the role

You are engaged once an incident is already underway. The work is to establish the scope of the compromise, contain it without destroying evidence, determine the initial access route, and confirm whether the attacker still has access. The written timeline you produce is a deliverable in its own right: it is what the client presents internally and, in regulated sectors, to their regulator.

What you will do

  • Scope and contain live incidents
  • Reconstruct the intrusion from what the logs actually kept
  • Write the timeline the client will read to their board

What they ask for

  • Host and network forensics on real cases
  • Calm under other people's panic
  • Writes fast and accurately when it counts

Nice to have

  • GCFA or equivalent
  • Malware analysis
  • On-call experience

What applying with Rooted means

This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.

Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.

You can read this role without an account. To apply you need a Rooted credential.

This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is Echelon Risk + Cyber. Confirm the final details with the original source or during the application process.

Posted 2026-08-13