Назад
Company hidden
1 час назад

Principal Incident Response Security Engineer (AI)

138 000 - 200 100$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Incident Response Security Engineer (AI): Leading enterprise cybersecurity incident response from detection through recovery while advancing EDR, SIEM, threat hunting, and automated response capabilities with an accent on forensic investigation, cloud security, and AI/ML-supported detection. Focus on handling high-severity incidents, designing Python, PowerShell, and AWS Lambda automation, and improving monitoring and response workflows across networks, cloud, and endpoints.

Location: Remote - Nationwide within the United States; applicants must be authorized to work for any employer in the U.S.

Base salary: $138,000–$200,100 per year, with eligibility for a bonus program.

Company

hirify.global provides financial services focused on helping customers achieve financial freedom and supporting employees through flexible career paths, inclusion, and work-life balance.

What you will do

  • Lead major cybersecurity incidents through detection, containment, eradication, recovery, and post-incident review, including participation in an on-call rotation.
  • Act as the escalation point for complex, high-severity incidents and communicate incident status, findings, and recommendations to executives and technical teams.
  • Develop and optimize incident response playbooks, runbooks, escalation procedures, policies, and standards.
  • Oversee enterprise monitoring across networks, cloud environments, and endpoints, advancing EDR and SIEM detection capabilities aligned with MITRE ATT&CK.
  • Build response automation using Python, PowerShell, and AWS Lambda, and integrate AI/ML into monitoring, prioritization, anomaly detection, and threat response.
  • Conduct forensic investigations and threat hunting, collaborate with infrastructure, application, and network teams, and mentor incident response analysts.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Current and active CISSP certification.
  • 6+ years of enterprise cybersecurity experience at scale, including 5+ years with EDR, SIEM, email security, and network security.
  • 3+ years of experience securing cloud environments and using scripting or coding.
  • Extensive knowledge of the incident response lifecycle, including driving alerts and incidents from detection through resolution and documenting policies and procedures.
  • Strong analytical, written, verbal, communication, and leadership skills, including the ability to influence technical and executive stakeholders.

Nice to have

  • Additional certifications such as SANS, GIAC, CCSP, AWS, CEH, or OSCP.
  • DevSecOps experience with infrastructure as code, Terraform, and Git.
  • Experience automating enrichment, correlation, containment, and other repetitive response tasks with Python, PowerShell, Bash, or AWS Lambda.
  • Experience integrating AI and machine learning for anomaly detection, behavioral analysis, log analysis, phishing detection, and threat intelligence enrichment.
  • Strong Linux, Windows, network, and database skills, plus experience in regulated environments involving SOX, HIPAA, GLBA, or PCI.

Culture & Benefits

  • Remote work with reliable high-speed wired internet and a dedicated home workspace required.
  • Medical, dental, vision, and life insurance.
  • 401(k) plan with company matching contributions of up to 6% and financial advisory services.
  • Tuition reimbursement of up to $5,250 per year.
  • Paid time off upon hire, company holidays, floating holidays, paid volunteer time, and parental and disability leave programs.
  • Inclusive Business Resource Groups and a business-casual work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →