Senior Incident Response Engineer
Core
Leading the management, investigation, and containment of security incidents in a 100% cloud environment, focusing on advanced threat response and digital forensics.
Role type
Senior Incident Response Engineer (DFIR)
Builds
Automated IR playbooks integrating AI/ML, optimized SOAR platforms, and improved detection coverage.
Domain
Cybersecurity, Cloud Security, Digital Forensics
Deliverable
production ML models | infrastructure
Required skills
Incident Response, Digital Forensics (DFIR), Cloud Forensics (AWS, GCP, Azure), Container Forensics (Kubernetes, Docker), Malware Analysis, Threat Hunting, SOAR implementation, Python scripting, Bash scripting, PowerShell scripting, MITRE ATT&CK frameworks, NIST IR frameworks, SIEM/SOAR tooling (Splunk, Elastic, Google Chronicle, Palo Alto XSIAM, IBM QRadar), Volatility, Autopsy, OSQuery, Velociraptor, AI/ML for security triage.
Preferred skills
GCFE, GCFA, GCIH, GREM, AWS Security Specialty certifications, Threat Intelligence Platforms (MISP, OpenCTI, ThreatConnect), APT/Ransomware response experience, SOC2/ISO 27001/PCI-DSS/GDPR compliance knowledge.
Responsibilities
Lead response to high-criticality security incidents in cloud environments (detection, containment, eradication, recovery), Perform digital forensics analysis on cloud infrastructure, containers, and endpoints, Develop and maintain automated IR playbooks integrating AI/ML, Implement and optimize SOAR platforms with generative AI capabilities, Collaborate with Blue Team and Red Team to correlate indicators, Execute malware analysis (static and dynamic) and proactive threat hunting, Mentor junior engineers and participate in on-call rotation.
Seniority
Senior, hands-on IC