Security Incident Response Engineer
Core
Detect, analyze, and respond to security incidents involving endpoints using EDR, SIEM, and Cloud Security tooling.
Role type
Security Incident Response Engineer (EDR)
Builds
Incident response playbooks, runbooks, and containment strategies for endpoint threats.
Domain
Cybersecurity / Endpoint Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Endpoint Detection and Response (EDR) platforms, digital forensics, threat hunting, Windows/macOS/Linux OS, scripting (PowerShell/Python/Bash), log analysis, root cause determination
Preferred skills
Microsoft M365 security (Entra ID, Defender), Infrastructure Security (Active Directory, PAM), GCFA/GCIH/CHFI/CySA+ certifications
Technologies
SentinelOne, Microsoft Defender, CrowdStrike, SIEM, Entra ID, Microsoft Defender for M365
Responsibilities
Detect, analyze, and respond to security incidents; lead investigation and containment of endpoint and identity threats; develop incident response playbooks; conduct forensic data acquisition and log analysis; monitor and tune EDR alerting rules; maintain EDR integration with SIEM
Seniority
Mid-level, hands-on IC