Summary
What you’ll impact
The Security Engineer – Incident Response will join a global information security team to investigate, analyze, and respond to cybersecurity incidents affecting third-party vendors, suppliers, and business partners. The role requires hands-on incident response, digital forensics, and threat hunting expertise, and involves communicating risk and findings to technical and non-technical stakeholders.
Responsibilities
What you'll do
- Investigate and respond to third-party cybersecurity incidents
- Perform incident triage, containment, eradication, remediation, and root cause analysis
- Conduct in-depth technical investigations, including log analysis and digital forensic analysis
- Evaluate the potential business and security impact of incidents
- Determine residual risk and appropriate remediation steps
- Document and track incident response activities
- Prepare incident reports, briefings, and presentations for leadership and security partners
- Work closely with Incident Response, Information Security, engineering, technology, and business teams
- Follow established Incident Response processes and procedures
Requirements
What you’ll bring
- 5+ years of overall technology experience
- 3+ years of information security experience
- Hands-on experience within Incident Response, SOC, Digital Forensics, Threat Hunting, or Detection
- Strong understanding of information security principles, practices, and procedures
- Experience performing log analysis, digital investigations, or digital forensics
- Understanding of:
- Web application security
- Infrastructure and Internet security
- Operating systems
- Networking protocols
- Databases
- Application development
- Ability to quickly assess security incidents and identify, isolate, and communicate risks
- Strong technical writing and documentation skills
- Excellent written and verbal communication skills
- Ability to manage multiple incidents and priorities in a fast-paced environment
- Experience with EDR tools such as CrowdStrike, SentinelOne, Cortex XDR, or Tanium
- Experience with SIEM and/or SOAR platforms
- Experience responding to incidents within AWS, Azure, or GCP
- Python or other scripting experience
- CISSP certification
- SANS/GIAC certifications such as GCIH, GCFA, GCIA, GCED, or GSEC