7 дней назад
Incident Response Engineer 2 (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Incident Response Engineer 2 (Cybersecurity): Performing advanced investigative, forensic, and containment activities for active cyber incidents across endpoints, network logs, and cloud telemetry with an accent on threat analysis, incident scoping, and customer-facing technical findings. Focus on validating indicators of compromise, determining root cause, mentoring junior analysts, and maintaining high-quality incident documentation during time-sensitive response engagements.
Location: Remote in the United Kingdom; applicants must have legal authorization to work in the United Kingdom without employer sponsorship
Company
Cybersecurity company providing AI-driven managed detection and response, threat monitoring, detection, and response services.
What you will do
- Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry.
- Execute containment and response actions during active cyber incidents.
- Validate indicators of compromise and correlate alerts, artifacts, and telemetry to determine incident scope and root cause.
- Maintain engagement documentation, including timelines, trailheads, and playbooks.
- Mentor junior incident response and SOC analysts and contribute technical findings to customer updates and post-incident reports.
- Identify detection and response gaps and participate in handovers, debriefs, and post-incident reviews.
Requirements
- 2+ years of experience in incident response, MDR, SOC, or security operations.
- Technical understanding of endpoint forensics, log analysis, and common attack techniques.
- Experience investigating malware, credential theft, ransomware, or similar threats.
- Ability to correlate alerts and telemetry, document findings, and communicate effectively with customers.
- Experience mentoring or guiding junior analysts and working in high-pressure incident environments.
- Willingness to work some weekends and holidays as part of a rotation.
Nice to have
- Hands-on experience with EDR, SIEM, and forensic collection tools.
- Familiarity with OSQuery, SQL, or KQL.
- Knowledge of MITRE ATT&CK and incident response frameworks.
- GCIH, GCED, CompTIA Security+, or equivalent certification.
- Experience contributing to playbooks, detection tuning, or service improvement initiatives.
Culture & Benefits
- Remote-first working model.
- Diversity and inclusion networks and community initiatives.
- Volunteer days, charity activities, and sustainability initiatives.
- Wellbeing days, webinars, training, and global fitness and trivia activities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Threat Hunter (Cybersecurity)
9 дней назад
Cybersecurity Analyst I (Cybersecurity)
80 000 - 90 000$
14 дней назад
Senior SOC Analyst (Cloud Security & Threat Detection)
Writer
10 дней назад
Staff Detection and Response Engineer (AI Security)
146 000 - 240 000$
11 дней назад
Senior Tactical Response Analyst (Cybersecurity)
125 000 - 135 000$
10 дней назад
Security Engineer - Incident Response (Cybersecurity)
70 000 - 107 800€