3 часа назад
Security Incident Response Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Incident Response Engineer (Cybersecurity): Investigating and containing cybersecurity incidents through host analysis, network forensics, log analysis, malware triage, and account takeover investigations with an accent on detection engineering, evidence handling, and incident response operations. Focus on developing alerts and response playbooks, leading root cause analysis and containment, enriching investigations with threat intelligence, and improving SOC automation and response capabilities.
Location: Lansing, Michigan, United States
Company
operates an Information Security and Privacy function supporting cybersecurity incident response, forensic investigations, and security operations.
What you will do
- Investigate and respond to cybersecurity incidents using host analysis, network forensics, log analysis, malware triage, SIEM, SOAR, EDR, and forensic tools.
- Lead immediate containment, root cause analysis, escalation, incident documentation, evidence handling, and chain-of-custody procedures.
- Conduct account takeover investigations and enrich findings with threat intelligence and Security Operations Center data.
- Develop detection alerts, analytics, response playbooks, automation, and security monitoring improvements.
- Train and mentor SOC staff, provide subject matter expertise, and collaborate with Legal, Financial Fraud Investigations, Human Resources, technical teams, and management.
- Lead continuous improvement projects and prepare actionable after-incident reports for security and technical leadership.
Requirements
- Bachelor’s degree or equivalent experience.
- At least 3 years of information security experience.
- Incident Response and/or Forensics certification required within 180 days of hire, such as GCIH, GCFE, or GCFA.
- Experience with authentication, authorization, logging, networking, security fundamentals, and Windows, Linux, and Apple iOS administration.
- Understanding of incident response in SaaS, PaaS, and IaaS environments, plus basic DevSecOps concepts and security automation.
- Experience with scripting or automation using PowerShell, Python, or Bash, along with strong analytical, documentation, and communication skills.
Nice to have
- CISSP certification.
Culture & Benefits
- Participation in an on-call rotation for critical security incidents.
- Availability outside normal working hours may be required for business continuity and emergency response.
- Work across business units to support a coordinated Security Incident Response process.
- Tobacco-free company facilities and campuses.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Microsoft AI
6 дней назад
Sr. Security Operations Engineer (AI)
119 800 - 234 700$
4 дня назад
SOC Engineer (Cybersecurity)
4 дня назад
Sr. SOC Engineer (Google SecOps)
4 дня назад
Cybersecurity Lead (TS/SCI)
Microsoft AI
3 дня назад
Sr. Security Engineer, Operations (AI)
119 800 - 234 700$
5 дней назад