10 часов назад
Security Incident Response Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Incident Response Engineer (Cybersecurity): Detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across endpoints, identities, cloud platforms, applications, data, and network infrastructure with an accent on threat hunting, digital forensics, detection engineering, and security automation. Focus on analyzing EDR and SIEM alerts, reconstructing attack timelines, improving incident response playbooks and SOAR workflows, and reducing response times and operational risk.
Location: Atlanta, GA; on-site presence required
Company
is a global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related services.
What you will do
- Investigate and respond to incidents affecting endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
- Perform incident triage, severity classification, impact analysis, containment, eradication, recovery, and escalation according to the Cyber Incident Response Plan.
- Analyze EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence alerts; validate suspicious activity and investigate root causes.
- Conduct threat hunting, malware investigation, forensic triage, log analysis, evidence collection, and incident timeline reconstruction.
- Develop response playbooks, detection improvements, automations, SOAR workflows, and operational runbooks.
- Track MTTD, MTTR, incident volume, severity, containment effectiveness, and detection fidelity; provide reports, executive summaries, and post-incident reviews.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent experience.
- At least 3 years of progressive information security experience.
- Strong knowledge of incident response methodologies, attack lifecycles, containment strategies, threat intelligence, threat hunting, and MITRE ATT&CK.
- Experience with EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, or CrowdStrike, and SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or QRadar.
- Knowledge of Microsoft 365, Entra ID, Active Directory, cloud security, and Windows, Linux, and macOS environments.
- Experience analyzing logs and indicators of compromise, using PowerShell, Python, KQL, or other scripting and query languages; availability for after-hours response and on-call rotations is required.
Culture & Benefits
- Cross-functional collaboration with Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
- Opportunities to provide technical leadership, mentor analysts and junior responders, and participate in tabletop exercises, incident simulations, and purple team activities.
- Medical, dental, vision, life, disability, fertility, wellness, paid sick time, paid time off, and holidays.
- Employee Assistance Program, Calm subscription, immediate 401(k) vesting, HSA, FSA, commuter benefits, and employee discounts.
- Paid maternity and paternity leave, including for adoptive parents, legal plan options, and pet insurance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Security Operations Lead (Cybersecurity)
18 часов назад
Cyber Security Analyst Leads (Cyber Threat Hunting)
56 минут назад
Staff Security Operations Engineer (Cybersecurity)
128 000 - 200 000$
1 день назад
Manager, Incident Response (Cybersecurity)
132 410 - 165 510$
3 дня назад
Incident Response Leader
275 000 - 344 000$
2 дня назад