Threat Response & Remediation Engineer
Core
Act as a trusted partner and virtual boots on the ground for customers, driving investigations, containing threats, and delivering complete remediation in customer environments.
Role type
Threat Response & Remediation Engineer
Builds
Secure customer environments by resolving security incidents and enhancing security posture
Domain
Cybersecurity, Threat Response, Incident Response
Deliverable
client delivery
Required skills
Threat investigation, incident containment, remediation planning, EDR platform usage, Windows/macOS internals, network communications analysis, analytical problem-solving
Preferred skills
Digital Forensics and Incident Response (DFIR), enterprise technology controls, adversary tactics and techniques
Technologies
CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, Palo Alto Cortex, CarbonBlack
Responsibilities
Perform investigations into detected threats using EDR, Network, and Identity telemetry; Identify, scope, and manage ongoing customer incidents; Develop remediation plans and provide clear reports; Collaborate with Detection Engineering, Intelligence, Research, and Product Management teams; Participate in an on-call rotation for 24x7 response
Seniority
Mid-Senior, hands-on IC