IT Security Engineer
Core
Hands-on security investigator supporting the Security Operations Center (SOC) within Threat Operations, focusing on detecting, investigating, and responding to security incidents from triage to closure.
Role type
Senior IC IT Security Engineer (Incident Response)
Builds
Incident response playbooks, runbooks, and detection tuning for the SOC
Domain
Cybersecurity / Incident Response / Threat Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response, digital forensics, host/network/cloud forensics, SIEM analysis, EDR analysis, threat detection, vulnerability assessment, automation tool usage, AI-assisted security platform usage, stakeholder communication, post-incident review, metrics development
Preferred skills
Experience with attacker tactics and methodologies, familiarity with modern automation tools, experience with AI-assisted security platforms
Technologies
AI, Cloud, ServiceNow, LESS
Responsibilities
Detect, investigate, and respond to security incidents; lead escalated and critical incidents; perform host, network, and cloud forensic analysis; analyze and correlate data from SIEM, EDR, and logs; create and maintain incident response playbooks and runbooks; identify detection gaps and false-positive trends; use Mate AI SOC platform outputs to guide investigations; partner with Compliance, Legal, and Risk; assess vulnerabilities and recommend remediation; train and mentor incident responders; contribute to post-incident reviews.
Seniority
Senior, hands-on IC