Engineer I - Cyber Incident Response
Core
Junior-level technical role in the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents.
Role type
Junior IC cybersecurity incident responder
Builds
SOC playbooks, runbooks, and standard operating procedures
Domain
Cybersecurity / Incident Response
Deliverable
client delivery
Required skills
incident response methodology, log analysis, alert triage, forensic data analysis, threat containment, playbook development, collaboration with threat intelligence teams
Preferred skills
SIEM/EDR tool usage, knowledge of adversary tactics, NIST/MITRE ATT&CK/ISO 27035 frameworks
Technologies
Splunk, CrowdStrike, Wireshark
Responsibilities
Investigate and respond to incidents (phishing, malware, ransomware, unauthorized access); Analyze logs, alerts, and forensic data to determine incident scope; Escalate complex/high-severity incidents with documentation; Assist in containment, eradication, and recovery; Contribute to SOC playbook and SOP maintenance; Participate in lessons-learned sessions
Seniority
Junior, hands-on IC