Senior/Lead Cyber Security - Incident Response Engineer
Core
Lead defensive security operations by designing and facilitating incident response tabletop exercises and owning the full incident lifecycle from detection to recovery.
Role type
Senior/Lead Cyber Security Incident Response Engineer
Builds
Organizational readiness for security incidents, IR plans, playbooks, and runbooks
Domain
Cybersecurity, Cloud Security, AI Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response lifecycle management, Tabletop exercise design and facilitation, Digital forensics, Cloud security fundamentals, AI security concepts, SIEM usage, CSPM usage, PICERL framework application, NIST framework application
Preferred skills
Cross-functional stakeholder engagement, Coaching and mentoring, Automation in IR workflows
Technologies
Magnet Axiom, Velociraptor, Volatility, FTK, Autopsy, AWS, SIEM, CSPM
Responsibilities
Design and facilitate incident response tabletop exercises across security, IT, engineering, legal, and business teams; Own the full incident lifecycle including detection, triage, containment, eradication, recovery, and post-incident review; Build and maintain IR plans, playbooks, and runbooks; Partner with threat intelligence, SOC, and engineering to improve detection and controls; Support digital forensics investigations; Lead IR activities in cloud environments using cloud security tooling
Seniority
Senior, hands-on IC with leadership responsibilities