Senior Incident Response Engineer
Core
Lead detection and remediation efforts as the primary technical liaison to the MSSP, translating alerts into actionable responses while ensuring NIST SP 800-171 compliance.
Role type
Senior Incident Response Engineer (Security Operations)
Builds
Incident response playbooks, SOAR workflows, and detection rules mapped to MITRE ATT&CK
Domain
Cybersecurity, Incident Response, Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident Response, Security Operations, Digital Forensics, Threat Hunting, SIEM, SOAR, Scripting (Python/PowerShell/Bash), OS Internals (Windows/Mac/Linux), Cyber Threat Intelligence, Tabletop Exercises, Technical Writing
Preferred skills
Malware Analysis (static/dynamic), Email Security Administration, NIST SP 800-171 and CMMC Level 2 expertise, Aerospace/Startup environment familiarity
Technologies
Google SecOps/Chronicle, Splunk, Microsoft Sentinel, Palo Alto Cortex XSOAR, Splunk Phantom SOAR, IDA Pro, Ghidra, Cuckoo Sandbox, Material Security, ProofPoint, Check Point Harmony, AWS, Azure, GCP
Responsibilities
Triage and validate security alerts; lead technical response to incidents (identification, containment, eradication, recovery); conduct deep-dive forensic investigations; execute proactive threat hunts; develop and validate custom detection rules; design and maintain IR playbooks and SOAR workflows; manage endpoint detection policies and live response actions; consume and operationalize cyber threat intelligence; own IR documentation architecture; evolve IR program strategy and metrics; provide technical guidance and facilitate tabletop exercises.
Seniority
Senior, hands-on IC