Engineer II - Cyber Incident Response
Core
Mid-level technical role in the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents.
Role type
mid-level IC cyber incident response engineer
Builds
incident response playbooks, runbooks, and standard operating procedures
Domain
cybersecurity / incident response
Deliverable
client delivery
Required skills
incident response methodology, log analysis, forensic data analysis, SIEM usage, EDR usage, threat intelligence collaboration, playbook development, escalation management
Preferred skills
GCIH certification, GCIA certification, CompTIA Security+, CEH certification
Technologies
Splunk, CrowdStrike, Wireshark
Responsibilities
Investigate and respond to phishing, malware, ransomware, and unauthorized access attempts; Analyze logs, alerts, and forensic data to determine incident scope and impact; Escalate complex or high-severity incidents to senior staff; Assist in containment, eradication, and recovery activities; Contribute to the development and maintenance of SOC playbooks and runbooks; Collaborate with threat intelligence, vulnerability management, and forensics teams; Support junior analysts by sharing knowledge and providing guidance
Seniority
Mid-level, hands-on IC