Incident Response Engineer 2
Core
Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry to neutralize active threats and determine incident scope and root cause.
Role type
Senior IC incident response engineer
Builds
Incident response outcomes and containment actions for global organizations
Domain
Cybersecurity / Incident Response
Deliverable
client delivery
Required skills
Endpoint forensics, log analysis, malware investigation, credential theft analysis, ransomware investigation, alert correlation, telemetry analysis, incident documentation, junior analyst mentorship
Preferred skills
EDR usage, SIEM usage, forensic collection tools, OSQuery, SQL, KQL, MITRE ATT&CK frameworks, incident response frameworks, playbook development, detection tuning
Technologies
EDR, SIEM, forensic collection tools, OSQuery, SQL, KQL
Responsibilities
Perform advanced investigative and forensic analysis across endpoints, network logs, and cloud telemetry; Execute containment and response actions to neutralize active threats; Validate indicators of compromise (IOCs) and correlate alerts, artifacts, and telemetry; Provide guidance and mentorship to junior IR and SOC analysts; Prepare technical findings and summaries for customer updates and post-incident reports; Identify and communicate detection or response gaps observed during investigations.
Seniority
Mid-level, hands-on IC