Назад
Company hidden
7 дней назад

Incident Response Engineer 2 (Cybersecurity)

Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Incident Response Engineer 2 (Cybersecurity): Performing advanced investigative, forensic, and containment activities for active cyber incidents across endpoints, network logs, and cloud telemetry with an accent on threat analysis, incident scoping, and customer-facing technical findings. Focus on validating indicators of compromise, determining root cause, mentoring junior analysts, and maintaining high-quality incident documentation during time-sensitive response engagements.

Location: Remote in the United Kingdom; applicants must have legal authorization to work in the United Kingdom without employer sponsorship

Company

Cybersecurity company providing AI-driven managed detection and response, threat monitoring, detection, and response services.

What you will do

  • Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry.
  • Execute containment and response actions during active cyber incidents.
  • Validate indicators of compromise and correlate alerts, artifacts, and telemetry to determine incident scope and root cause.
  • Maintain engagement documentation, including timelines, trailheads, and playbooks.
  • Mentor junior incident response and SOC analysts and contribute technical findings to customer updates and post-incident reports.
  • Identify detection and response gaps and participate in handovers, debriefs, and post-incident reviews.

Requirements

  • 2+ years of experience in incident response, MDR, SOC, or security operations.
  • Technical understanding of endpoint forensics, log analysis, and common attack techniques.
  • Experience investigating malware, credential theft, ransomware, or similar threats.
  • Ability to correlate alerts and telemetry, document findings, and communicate effectively with customers.
  • Experience mentoring or guiding junior analysts and working in high-pressure incident environments.
  • Willingness to work some weekends and holidays as part of a rotation.

Nice to have

  • Hands-on experience with EDR, SIEM, and forensic collection tools.
  • Familiarity with OSQuery, SQL, or KQL.
  • Knowledge of MITRE ATT&CK and incident response frameworks.
  • GCIH, GCED, CompTIA Security+, or equivalent certification.
  • Experience contributing to playbooks, detection tuning, or service improvement initiatives.

Culture & Benefits

  • Remote-first working model.
  • Diversity and inclusion networks and community initiatives.
  • Volunteer days, charity activities, and sustainability initiatives.
  • Wellbeing days, webinars, training, and global fitness and trivia activities.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →