Jobgether

Engineer - Security Operations and Incident Response

Jobgether United States

Internet Marketplace Platforms · 11-50 employees

12 h ago
Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will conduct expert-level investigations into complex security incidents and develop incident response playbooks to mitigate evolving threats. Additionally, you will design automated remediation workflows and optimize detection strategies using threat intelligence and security frameworks.

What they look for

Incident Response Security Operations Digital Forensics Threat Intelligence Detection Engineering SIEM SOAR Python PowerShell Bash XQL Microsoft Sentinel Palo Alto Cortex XSIAM MITRE ATT&CK Cloud Security

Requirements

Candidates must have a bachelor's degree and at least 5 years of professional experience in incident response and SOC tooling. Proficiency in SIEM/SOAR platforms, hybrid cloud environments, and scripting languages like Python or PowerShell is required.

Benefits

Remote or hybrid work options Exposure to advanced cybersecurity technologies Opportunity to work with modern security frameworks High-impact role Continuous process improvement

Full description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in United States.

This role is central to strengthening and continuously evolving a global Security Operations and Incident Response program. You will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats. The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident response. You will work across hybrid cloud environments while improving security processes, technologies, and operational resilience. Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the organization. You will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows. This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.

\n

Accountabilities:

  • Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
  • Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
  • Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
  • Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
  • Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
  • Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
  • Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
  • Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
  • Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
  • Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
  • Support incident response leadership as a backup resource for incident response activities and operational priorities.
  • Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.

Requirements:

  • Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
  • In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
  • Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
  • Experience serving as an incident commander during security incidents and leading coordinated response efforts.
  • Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
  • Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
  • Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
  • Experience with threat intelligence, detection engineering, security automation, and incident response processes.
  • Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
  • Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
  • Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.

Benefits:

  • Remote or hybrid work options.
  • Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
  • Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
  • Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
  • High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
  • Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.

\nHow Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1