Cyber Defense & Incident Response
Core
CSIRT Engineer building a 'SOCless' future through high-level automation and sophisticated detection engineering to proactively hunt threats and respond to security breaches.
Role type
Senior IC Cyber Defense & Incident Response Engineer
Builds
Automated incident response tooling, detection playbooks, and threat-hunting frameworks
Domain
Cloud-native security (AWS), Digital Forensics, Incident Response (DFIR)
Deliverable
production ML models | product features | infrastructure
Required skills
Incident Response, Digital Forensics, Cloud Proficiency (AWS), Python or Golang, Detection Engineering, Threat Hunting, SIEM management, Log ingestion tool management
Preferred skills
GCIH, GCFA, GNFA, AWS Certified Security - Specialty, SOAR platforms, Data privacy regulations knowledge
Technologies
AWS, Python, Golang, SIEM, SOAR, MITRE ATT&CK
Responsibilities
Conduct deep-dive investigations into security breaches and anomalies following the Cyber Incident Response Cycle; Design and maintain playbooks and investigation methodologies; Create, validate, and fine-tune alerts to ensure high fidelity and low noise; Build tooling and automation for incident response; Proactively conduct threat-hunting exercises across infrastructure; Cooperate with the management of security log ingestion tools and SIEM
Seniority
Senior, hands-on IC