Principal Incident Response Engineer
Core
Lead high-severity security incidents, conduct digital forensics, and perform threat hunting to ensure the confidentiality, integrity, and availability of IT assets.
Role type
Principal Incident Response Engineer (Threat Detection & Response)
Builds
Incident response playbooks, forensic evidence packages, and AI/LLM workflows for enhanced detection
Domain
Cybersecurity, Digital Forensics, Cloud Security
Deliverable
client delivery | production ML models
Required skills
digital forensics, incident response methodologies, threat hunting, forensic tool usage, cloud workload analysis, AI/LLM workflow development
Preferred skills
SIEM, IDS/IPS, EDR, cloud monitoring, MITRE ATT&CK framework, NIST/SANS/CSA frameworks
Technologies
Encase, FTK, Axiom, Cellebrite, SIEM, IDS/IPS, EDR
Responsibilities
Analyze security events and indicators to determine incident nature and severity; Respond to and contain high-severity security incidents; Perform forensic investigations to identify root causes; Lead intelligence-driven threat hunt activities; Develop AI/LLM workflows to enhance detection capabilities; Collaborate with legal experts on evidence preservation and presentation
Seniority
Principal, hands-on IC with strategic leadership