Sr. Security Engineer, Incident Response
Core
Technical lead for incident response lifecycle, driving containment and remediation of security threats across multi-cloud infrastructure and a global travel/expense platform.
Role type
Senior IC security engineer (incident response & automation)
Builds
Automated triage, enrichment, and containment workflows using Tines; detection rules in CrowdStrike EDR/SIEM
Domain
Cybersecurity, Cloud Security, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Incident response leadership, Tines workflow design, CrowdStrike Falcon tuning, SIEM/SOAR management, MITRE ATT&CK framework knowledge, SaaS security defense, IAM gap analysis, vulnerability management, emergent threat strategy, on-call rotation management
Preferred skills
Cross-functional coordination, technical risk communication
Technologies
Tines, CrowdStrike Falcon, SIEM, SOAR, Cyberhaven DLP
Responsibilities
Lead high-severity incident containment and post-incident root-cause analysis; design and automate response workflows; manage detection rule lifecycles; monitor data risks across endpoints and SaaS; partner with infrastructure teams on security telemetry and playbooks; evaluate response strategies for automated agents/bots; participate in on-call rotation
Seniority
Senior, hands-on IC