Engineer III - Cyber Incident Response
Core
Senior technical role leading complex cyber incident investigations, forensic analysis, and response capability improvement within a Security Operations Center.
Role type
Senior IC cyber incident response engineer
Builds
Incident response playbooks, runbooks, detection use cases, and improved SOC processes
Domain
Cybersecurity / Incident Response / Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response methodologies, digital forensics, adversary tactics analysis, SIEM operations, EDR operations, SOAR operations, forensic tool usage, threat investigation, technical escalation, mentorship
Preferred skills
Security framework implementation (NIST, MITRE ATT&CK, ISO 27035), red team/purple team exercise participation, after-action review facilitation
Technologies
Splunk, CrowdStrike, EnCase, Wireshark
Responsibilities
Lead investigation and resolution of complex security incidents including APTs, ransomware, and phishing; Perform forensic analysis across endpoints, networks, and cloud environments; Develop and enhance incident response playbooks and detection use cases; Act as technical escalation point for junior analysts; Mentor and train junior engineers on incident response best practices
Seniority
Senior, hands-on IC