Engineer II - Cyber Incident Response
Core
Mid-level technical role in the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents.
Role type
mid-level IC cybersecurity incident responder
Builds
incident response playbooks, runbooks, and standard operating procedures
Domain
Cybersecurity / Security Operations
Deliverable
client delivery
Required skills
incident response methodology, log analysis, forensic data analysis, threat containment, playbook development, stakeholder briefing
Preferred skills
GCIH, GCIA, CySA+, CEH, Endpoint Forensics, Cloud Security
Technologies
Splunk, CrowdStrike, Wireshark
Responsibilities
Investigate and respond to incidents (phishing, malware, ransomware), analyze logs and alerts, escalate complex cases, assist in containment and recovery, contribute to SOC process improvements, support junior analysts
Seniority
Mid-level, hands-on IC