Engineer - Security Operations and Incident Response

New
J
JobgetherCybersecurity
Based in United StatesFull-TimeMiddle
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
At least 5 years
Required Skills
PythonBash

Requirements

  • Bachelor's degree.
  • At least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
  • In-depth knowledge of SIEM and SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM, Cortex XSOAR).
  • Understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
  • Experience serving as an incident commander during security incidents.
  • Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools and detection capabilities.
  • Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
  • Understanding of cybersecurity frameworks and regulatory requirements (MITRE ATT&CK, NIST, ISO).
  • Experience with threat intelligence, detection engineering, and security automation.
  • Ability to prioritize effectively and work independently as well as collaboratively.
  • Excellent written and verbal communication skills.

Responsibilities

  • Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
  • Develop, author, and continuously refine incident response playbooks and operational guidelines.
  • Develop and maintain threat models, incorporating penetration testing findings into detection strategies.
  • Design, implement, and optimize sophisticated detection rules and automated remediation workflows.
  • Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps.
  • Maintain comprehensive documentation covering detection strategies, investigations, and response activities.
  • Partner with SIEM teams to tune detection rules and minimize false positives.
  • Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash.
  • Implement and maintain automation and orchestration capabilities through SOAR tools.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now