Security Incident Response Engineer
Core
Detect, investigate, contain, eradicate, and recover from cybersecurity incidents across global endpoints, identities, cloud, and data environments.
Role type
Senior IC Security Incident Response Engineer
Builds
Incident response playbooks, detection logic, SOAR workflows, and forensic evidence
Domain
Cybersecurity / Incident Response / Threat Detection
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Incident response methodologies, threat hunting, digital forensics, log analysis, MITRE ATT&CK, EDR platforms, SIEM technologies, cloud security, scripting (PowerShell/Python/KQL)
Preferred skills
Threat intelligence, malware investigation, automation tooling, table-top exercise facilitation
Technologies
Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, Microsoft Sentinel, Google SecOps, Splunk, QRadar, Microsoft 365, Entra ID, Active Directory
Responsibilities
Investigate and respond to security incidents across endpoints, identities, cloud, and data; Perform triage, containment, eradication, and recovery; Conduct proactive threat hunting and root cause analysis; Develop and maintain incident response playbooks and runbooks; Analyze alerts from EDR, SIEM, and threat intelligence platforms; Provide technical leadership during major incidents; Mentor junior responders
Seniority
Senior, hands-on IC