Incident Responder
LastPass
| Company | LastPass |
| Category | Security |
| Location | Remote - US |
| Remote | Remote |
| Employment | Not stated |
| Level | Entry |
| Salary | Not stated by the employer |
| Posted | 27 Jul 2026 |
| Last verified | 5 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
About LastPass LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity. From discovering unapproved AI and applications to reducing login friction and securing credentials across the business, LastPass delivers on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected as their environments evolve.
Curious about our products? Visit our website and try it free!
We welcome new ideas, support your growth, and recognize your value, if this aligns with what you are looking for in your next career move, Join Us! LastPass is looking for an Incident Responder:
In this senior role, you will lead investigations end-to-end and advance our detection capabilities. You will own MSSP escalations, conduct threat hunts, and apply AI-assisted approaches — helping LastPass deliver on its mission to give everyone seamless access to everything they need to work, move fast, and stay protected.
About the team:
Our Security Intelligence & Response team operates at the front line of defending our cloud environments, customers, and platform. We are a collaborative, high-trust team where responders work closely across incident response, detection engineering, and threat intelligence — sharing findings, sharpening capabilities, and holding each other to a high standard in a fast-moving operational environment.
If you are passionate about complex problem solving and motivated by scale, then this is the role for you!
Who will you work with?
You will partner closely with the Detection Engineering team to build and tune analytics in Microsoft Sentinel, and collaborate with the broader Security Intelligence & Response team on threat hunts and investigations. You will also work with our Managed Security Service Provider, engaging their analysts to manage escalations and close gaps in coverage.
What are some of the exciting challenges you will be working on?
Own security incidents end-to-end — receive and validate MSSP escalations, lead investigations, coordinate response, and drive containment, eradication, and recovery
Conduct proactive threat hunts across cloud and endpoint telemetry, turning findings into durable detections that improve coverage and fidelity.
Build and tune detection content in Microsoft Sentinel and across the cloud security stack in close partnership with the Detection Engineering team
Develop and improve enrichment and response workflows to reduce manual effort, accelerate response times, and scale the team's impact
Apply AI-assisted approaches to triage, investigation, detection authoring, and automation — helping the team adopt these capabilities responsibly and effectively
Analyze logs and telemetry from cloud platforms, identity systems, endpoints, and network sources to detect and reconstruct attacker activity
Document investigations thoroughly — capturing actions, evidence, timelines, and conclusions — to a standard that supports both technical follow-up and stakeholder communication
Manage and strengthen the MSSP relationship by providing feedback on escalation quality, tuning alerting thresholds, and contributing to lessons-learned reviews
What does it take to work at LastPass?
Proven experience in incident response and security operations in cloud-native environments, with hands-on depth in Azure and AWS
Proven experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering, including authoring and tuning detection content
Proven experience working with an MSSP — managing escalations, providing quality feedback, and closing gaps in coverage — whether as client or vendor
Proven experience c
You found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →