Назад
Company hidden
8 дней назад

Security Incident Response Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Incident Response Engineer (Cybersecurity): Detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across endpoints, identities, cloud environments, applications, and data with an accent on threat detection, digital forensics, and response engineering. Focus on threat hunting, attack-vector analysis, MITRE ATT&CK investigations, detection tuning, SOAR automation, and reducing incident response times and severity.

Location: Atlanta, Georgia, United States; on-site presence required

Company

A global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related solutions across more than 20 countries.

What you will do

  • Investigate and respond to incidents affecting endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
  • Perform triage, severity classification, impact analysis, containment, eradication, recovery, and major incident coordination.
  • Analyze EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence alerts.
  • Conduct threat hunting, root cause analysis, malware investigation, forensic triage, evidence collection, and timeline reconstruction.
  • Develop incident response playbooks, detection improvements, SOAR workflows, and automated response capabilities.
  • Track MTTD, MTTR, incident trends, containment effectiveness, and detection fidelity; produce incident reports and post-incident reviews.

Requirements

  • Comfort with on-site work in Atlanta is required to support collaboration, team leadership, and cross-functional partnership.
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent experience.
  • At least 3 years of progressive information security experience.
  • Experience with EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, or CrowdStrike, and SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or QRadar.
  • Knowledge of Microsoft 365, Entra ID, Active Directory, cloud security, MITRE ATT&CK, threat intelligence, and threat hunting.
  • Experience with Windows, Linux, macOS, log and IOC analysis, and PowerShell, Python, KQL, or other scripting and query languages.

Culture & Benefits

  • Cross-functional collaboration with Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
  • Participation in after-hours incident response and on-call rotations.
  • Medical, dental, vision, life, disability, fertility, wellness, and paid sick-time benefits.
  • Paid time off, holidays, an Employee Assistance Program, and a Calm app subscription.
  • 401(k) with immediate vesting, HSA and FSA options, commuter benefits, and employee discounts.
  • Paid maternity and paternity leave, legal plan options, and pet insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →