Назад
Company hidden
10 часов назад

Security Incident Response Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Incident Response Engineer (Cybersecurity): Detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across endpoints, identities, cloud platforms, applications, data, and network infrastructure with an accent on threat hunting, digital forensics, detection engineering, and security automation. Focus on analyzing EDR and SIEM alerts, reconstructing attack timelines, improving incident response playbooks and SOAR workflows, and reducing response times and operational risk.

Location: Atlanta, GA; on-site presence required

Company

hirify.global is a global fintech company providing insurance, reinsurance, payroll, benefits, cybersecurity, mortgage, and related services.

What you will do

  • Investigate and respond to incidents affecting endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
  • Perform incident triage, severity classification, impact analysis, containment, eradication, recovery, and escalation according to the Cyber Incident Response Plan.
  • Analyze EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence alerts; validate suspicious activity and investigate root causes.
  • Conduct threat hunting, malware investigation, forensic triage, log analysis, evidence collection, and incident timeline reconstruction.
  • Develop response playbooks, detection improvements, automations, SOAR workflows, and operational runbooks.
  • Track MTTD, MTTR, incident volume, severity, containment effectiveness, and detection fidelity; provide reports, executive summaries, and post-incident reviews.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a related discipline, or equivalent experience.
  • At least 3 years of progressive information security experience.
  • Strong knowledge of incident response methodologies, attack lifecycles, containment strategies, threat intelligence, threat hunting, and MITRE ATT&CK.
  • Experience with EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, or CrowdStrike, and SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or QRadar.
  • Knowledge of Microsoft 365, Entra ID, Active Directory, cloud security, and Windows, Linux, and macOS environments.
  • Experience analyzing logs and indicators of compromise, using PowerShell, Python, KQL, or other scripting and query languages; availability for after-hours response and on-call rotations is required.

Culture & Benefits

  • Cross-functional collaboration with Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
  • Opportunities to provide technical leadership, mentor analysts and junior responders, and participate in tabletop exercises, incident simulations, and purple team activities.
  • Medical, dental, vision, life, disability, fertility, wellness, paid sick time, paid time off, and holidays.
  • Employee Assistance Program, Calm subscription, immediate 401(k) vesting, HSA, FSA, commuter benefits, and employee discounts.
  • Paid maternity and paternity leave, including for adoptive parents, legal plan options, and pet insurance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →