Назад
Company hidden
3 часа назад

Security Incident Response Engineer

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Incident Response Engineer (Cybersecurity): Investigating and containing cybersecurity incidents through host analysis, network forensics, log analysis, malware triage, and account takeover investigations with an accent on detection engineering, evidence handling, and incident response operations. Focus on developing alerts and response playbooks, leading root cause analysis and containment, enriching investigations with threat intelligence, and improving SOC automation and response capabilities.

Location: Lansing, Michigan, United States

Company

hirify.global operates an Information Security and Privacy function supporting cybersecurity incident response, forensic investigations, and security operations.

What you will do

  • Investigate and respond to cybersecurity incidents using host analysis, network forensics, log analysis, malware triage, SIEM, SOAR, EDR, and forensic tools.
  • Lead immediate containment, root cause analysis, escalation, incident documentation, evidence handling, and chain-of-custody procedures.
  • Conduct account takeover investigations and enrich findings with threat intelligence and Security Operations Center data.
  • Develop detection alerts, analytics, response playbooks, automation, and security monitoring improvements.
  • Train and mentor SOC staff, provide subject matter expertise, and collaborate with Legal, Financial Fraud Investigations, Human Resources, technical teams, and management.
  • Lead continuous improvement projects and prepare actionable after-incident reports for security and technical leadership.

Requirements

  • Bachelor’s degree or equivalent experience.
  • At least 3 years of information security experience.
  • Incident Response and/or Forensics certification required within 180 days of hire, such as GCIH, GCFE, or GCFA.
  • Experience with authentication, authorization, logging, networking, security fundamentals, and Windows, Linux, and Apple iOS administration.
  • Understanding of incident response in SaaS, PaaS, and IaaS environments, plus basic DevSecOps concepts and security automation.
  • Experience with scripting or automation using PowerShell, Python, or Bash, along with strong analytical, documentation, and communication skills.

Nice to have

  • CISSP certification.

Culture & Benefits

  • Participation in an on-call rotation for critical security incidents.
  • Availability outside normal working hours may be required for business continuity and emergency response.
  • Work across business units to support a coordinated Security Incident Response process.
  • Tobacco-free company facilities and campuses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →