Lead Engineer, Cyber Security, Incident and Threat Responder
Core
Lead a team in identifying, investigating, and responding to cyber security incidents across the organization's technology environment to reduce impact and improve defensive posture.
Role type
Senior IC Lead Engineer, Cyber Security Incident and Threat Responder
Builds
Incident response processes, detection strategies, and automated remediation workflows
Domain
Cyber Security / Incident Response / Threat Intelligence
Required skills
Incident response leadership, complex technical analysis, threat actor TTPs knowledge, cloud security (AWS), scripting (Python/Go/Ruby), host-based security, network attack identification, SIEM platforms, security frameworks (NIST/ISO/GDPR)
Preferred skills
Forensic certifications (GCFA/GCFE/CFCE/CDFE/CHFI), advanced threat detection research, automation/orchestration integration
Technologies
AWS, RHEL, Ubuntu, Windows Server, SIEM platforms, Python, Go, Ruby
Responsibilities
Lead internal incident response engagements to mitigate and remediate cyber threats; conduct complex technical analysis and develop evidence-based conclusions; monitor and investigate internal/external threats; correlate data sources to determine remediation strategies; establish high standards for incident documentation and post-incident reviews; drive continuous improvement in detection and response approaches; research evolving attacker techniques; communicate incidents effectively to stakeholders
Seniority
Senior, hands-on IC with team leadership