Engineer - Security Operations and Incident Response
New
J
JobgetherCybersecurity
Based in United StatesFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- At least 5 years
- Required Skills
- PythonBash
Requirements
- Bachelor's degree.
- At least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
- In-depth knowledge of SIEM and SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM, Cortex XSOAR).
- Understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
- Experience serving as an incident commander during security incidents.
- Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools and detection capabilities.
- Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
- Understanding of cybersecurity frameworks and regulatory requirements (MITRE ATT&CK, NIST, ISO).
- Experience with threat intelligence, detection engineering, and security automation.
- Ability to prioritize effectively and work independently as well as collaboratively.
- Excellent written and verbal communication skills.
Responsibilities
- Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
- Develop, author, and continuously refine incident response playbooks and operational guidelines.
- Develop and maintain threat models, incorporating penetration testing findings into detection strategies.
- Design, implement, and optimize sophisticated detection rules and automated remediation workflows.
- Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps.
- Maintain comprehensive documentation covering detection strategies, investigations, and response activities.
- Partner with SIEM teams to tune detection rules and minimize false positives.
- Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash.
- Implement and maintain automation and orchestration capabilities through SOAR tools.
View Full Description & ApplyYou'll be redirected to the employer's site