7 часов назад
DFIR Engineer II - Incident Response (Cybersecurity)
89 360 - 134 040$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
DFIR Engineer II - Incident Response (Cybersecurity): Responding to, investigating, and containing anomalous or malicious network and host activity with an accent on digital forensics, threat hunting, and incident documentation. Focus on analyzing system artifacts and memory, correlating SIEM and endpoint data, improving detection and response procedures, and automating security responses.
Location: Milwaukee, Wisconsin, United States; hybrid
Salary: $89,360–$134,040 per year, plus potential annual bonus opportunities.
Company
is a long-established financial services company focused on helping clients protect and manage their financial lives.
What you will do
- Respond to, investigate, and contain anomalous or malicious activity indicating potential security threats.
- Triage, pivot, and correlate network- and host-based logs across multiple sources.
- Analyze system artifacts and memory for evidence of compromise.
- Proactively hunt for malicious activity using threat intelligence and indicators of compromise.
- Document incident findings and timelines while improving response procedures and documentation.
- Collaborate with Detection Engineering and Red Team to improve monitoring, detection, and automated response capabilities.
Requirements
- Bachelor’s degree in Information Security, Computer Science, or equivalent education, training, and experience.
- At least two years of experience in Incident Response or a Security Operations Center role.
- Information technology background with an emphasis on network or systems administration.
- Foundational knowledge of networking, Windows, macOS, Linux, and cybersecurity principles.
- Experience with SIEM, EDR, antivirus, CASB, next-generation firewalls, VPN, and system or network artifacts.
- Working knowledge of MITRE ATT&CK and practical experience with a scripting or development language such as PowerShell, Python, or .NET, as well as regular expressions.
Nice to have
- GCIH, GCFE, GCFA, GDAT, CISSP, or another relevant security certification, or willingness to obtain one.
- Familiarity with AWS, Azure, Microsoft 365, Docker, Kubernetes, and other cloud or containerization technologies.
Culture & Benefits
- Medical, dental, and vision plans.
- 401(k) and pension program.
- Tuition reimbursement, paid time off, and holiday pay.
- Professional training opportunities and support for career development.
- Annual bonus opportunities and a focus on work-life balance.
- Participation in an on-call rotation with other Incident Response Engineers.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →