8 дней назад
Security Incident Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Incident Response Engineer (Cybersecurity): Detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across endpoints, identities, cloud environments, applications, and data with an accent on threat detection, digital forensics, and response engineering. Focus on threat hunting, attack-vector analysis, MITRE ATT&CK investigations, detection tuning, SOAR automation, and reducing incident response times and severity.
Location: Atlanta, Georgia, United States; on-site presence required
Company
A global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related solutions across more than 20 countries.
What you will do
- Investigate and respond to incidents affecting endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
- Perform triage, severity classification, impact analysis, containment, eradication, recovery, and major incident coordination.
- Analyze EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence alerts.
- Conduct threat hunting, root cause analysis, malware investigation, forensic triage, evidence collection, and timeline reconstruction.
- Develop incident response playbooks, detection improvements, SOAR workflows, and automated response capabilities.
- Track MTTD, MTTR, incident trends, containment effectiveness, and detection fidelity; produce incident reports and post-incident reviews.
Requirements
- Comfort with on-site work in Atlanta is required to support collaboration, team leadership, and cross-functional partnership.
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent experience.
- At least 3 years of progressive information security experience.
- Experience with EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, or CrowdStrike, and SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or QRadar.
- Knowledge of Microsoft 365, Entra ID, Active Directory, cloud security, MITRE ATT&CK, threat intelligence, and threat hunting.
- Experience with Windows, Linux, macOS, log and IOC analysis, and PowerShell, Python, KQL, or other scripting and query languages.
Culture & Benefits
- Cross-functional collaboration with Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
- Participation in after-hours incident response and on-call rotations.
- Medical, dental, vision, life, disability, fertility, wellness, and paid sick-time benefits.
- Paid time off, holidays, an Employee Assistance Program, and a Calm app subscription.
- 401(k) with immediate vesting, HSA and FSA options, commuter benefits, and employee discounts.
- Paid maternity and paternity leave, legal plan options, and pet insurance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Associate Solution Consultant – Security Incident Handler (Cybersecurity)
10 дней назад
Security Analyst (Cybersecurity)
50 - 65$
10 дней назад
Sr. Staff Security Analyst - Incident Commander (Cybersecurity)
145 600 - 209 300$
13 дней назад
Incident Response Analyst (Cybersecurity)
140 000 - 160 000$
9 дней назад
Senior CERT Analyst (Cybersecurity)
13 дней назад