This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in United States.
This role is central to strengthening and continuously evolving a global Security Operations and Incident Response program.
You will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats.
The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident response.
You will work across hybrid cloud environments while improving security processes, technologies, and operational resilience.
Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the organization.
You will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows.
This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.
Accountabilities:
- Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
- Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
- Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
- Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
- Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
- Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
- Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
- Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
- Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
- Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
- Support incident response leadership as a backup resource for incident response activities and operational priorities.
- Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.
- Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
- In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
- Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
- Experience serving as an incident commander during security incidents and leading coordinated response efforts.
- Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
- Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
- Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
- Experience with threat intelligence, detection engineering, security automation, and incident response processes.
- Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
- Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
- Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.
- Remote or hybrid work options.
- Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
- Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
- Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
- High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
- Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.
Requirements:
Benefits:

