Senior Security Engineer, Incident Response Team
Core
Lead complex incident investigations and manage high-severity security events in cloud and corporate environments, combining DFIR expertise with detection engineering and automation.
Role type
Senior IC security engineer (incident response & detection)
Builds
Scalable security workflows, automated response playbooks, and improved detection capabilities
Domain
Cybersecurity, Cloud Security, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Digital Forensics and Incident Response (DFIR), SIEM administration, EDR, cloud security (AWS, GCP), Python scripting, SOAR platforms, threat intelligence analysis, root cause analysis, technical documentation
Preferred skills
AI/ML application in security workflows, Git/GitLab administration, MITRE ATT&CK framework knowledge, mentorship
Technologies
AWS, GCP, SIEM, EDR, SOAR, Python, Git, GitLab
Responsibilities
Lead end-to-end response to high-severity security incidents; Conduct complex security investigations using DFIR methodologies; Develop and enhance automation and AI-assisted workflows; Partner with Detection Engineering to improve SIEM use cases and alerting strategies; Collaborate with Threat Intelligence teams to contextualize emerging threats; Conduct root cause analysis and lead post-incident reviews; Mentor other security engineers and improve team maturity
Seniority
Senior, hands-on IC