AI-Driven Incident Response Lead (Hybrid)

DocuSign

Seattle (WA)

Hybrid

USD 140,000 - 207,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DocuSign is seeking a seasoned CSIRT Investigator in the United States to lead incident response activities and improve detection capabilities. The role requires heavy experience with SIEM/EDR, digital forensics, and scripting for automation, with hybrid in-office expectations and security-focused collaboration across teams.

You will participate in on-call rotations, investigate complex incidents, and contribute to post-incident analyses while staying current on threat intelligence and emerging

Qualifications

  • 8+ years in cybersecurity focused on SOC/IR.
  • Must be a U.S. citizen/national/person.
  • Experience leading incident responses.
  • Experience with crisis management.
  • Experience with SIEM (Splunk/QRadar/Sentinel) for alert analysis & log correlation.
  • Experience with EDR and incident investigation.
  • Experience with digital forensics principles and enterprise tools.
  • Experience with scripting (Python/PowerShell/Bash) for automation.

Responsibilities

  • Leverage AI and ML tools to enhance log analysis, alert triage, and threat hunting.
  • Monitor for and investigate security incidents involving AI/ML models.
  • Collaborate with detection engineering to develop AI-based detection logic to improve SOC visibility.
  • Research and adopt emerging AI-driven security technologies to evolve CSIRT's proactive defense capabilities.
  • Perform initial triage and in-depth analysis of security alerts generated from our SIEM and other security monitoring tools.
  • Correlate events from various log sources to identify potential security incidents.
  • Determine the scope, severity, and potential impact of detected threats.
  • Conduct technical investigations into cybersecurity incidents, including malware analysis, phishing attacks, web app compromises, and insider threats.
  • Utilize digital forensics techniques on data and endpoints to gather evidence and understand incident timelines and methods.
  • Support incident containment, eradication, and recovery efforts under the CSIRT Manager guidance.
  • Document incident findings, actions taken, and lessons learned.
  • Assist in the development and refinement of threat detection rules to improve SOC visibility.
  • Participate in proactive threat hunting activities to uncover hidden threats within the enterprise environment.
  • Stay informed about the latest threat intelligence and emerging attack techniques.
  • Work with SIEM and SOAR platforms to optimize alert processing and incident workflows.
  • Contribute to the creation and refinement of automated solutions for efficient incident response and reporting.
  • Identify opportunities for automation to streamline security operations.
  • Collaborate with other security teams, IT, and business units during incident response.
  • Provide clear and concise updates on incident status to the CSIRT Manager.
  • Contribute to post-incident reports and analysis.
  • Maintain working relationships with law enforcement when required.

Skills

SOC Operations
Incident Response
Python scripting
EDR experience
Digital Forensics
Log analysis
Threat hunting
Crisis management
AI/ML security

Education

Bachelor's degree in CS/InfoSec
Security certifications (CompTIA Security+, CySA+, GCIH, GCFA, CEH)

Tools

Splunk/QRadar/Sentinel
EDR solutions
Digital forensics tools
Automation tooling

Job description

DocuSign is seeking a seasoned CSIRT Investigator in the United States to lead incident response activities and improve detection capabilities. The role requires heavy experience with SIEM/EDR, digital forensics, and scripting for automation, with hybrid in-office expectations and security-focused collaboration across teams.

You will participate in on-call rotations, investigate complex incidents, and contribute to post-incident analyses while staying current on threat intelligence and emerging

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst (Hybrid)
Senior Incident Response Analyst (Hybrid)

DocuSign, Inc. • San Francisco (CA)

Hybrid
USD 146,000 - 235,000
Bonus
RSUs
Health benefits
+1
Senior Incident Response Analyst — AI-Driven SOC (Hybrid)
Senior Incident Response Analyst — AI-Driven SOC (Hybrid)

Docusign • San Francisco (CA)

Hybrid
USD 146,000 - 235,000
Health benefits plans
Paid time off
Parental leave
+1
Senior Cybersecurity Incident Response Leader (Hybrid)
Senior Cybersecurity Incident Response Leader (Hybrid)

Socket.dev • Pleasanton (CA)

Hybrid
USD 216,000 - 324,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Hybrid Cyber Security Analyst: SIEM & Incident Response
Hybrid Cyber Security Analyst: SIEM & Incident Response

Request Technology, LLC • Chicago (IL)

Hybrid
USD 90,000 - 130,000
Senior Incident Response Lead: Forensics, Automation & AI
Senior Incident Response Lead: Forensics, Automation & AI

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Hybrid Cyber Defense Lead: Incident Response & Pen Testing
Hybrid Cyber Defense Lead: Incident Response & Pen Testing

Eliassen Group • Alexandria (VA)

Hybrid
Confidential
Medical, Dental, Vision benefits
401k with company matching
Life insurance
AI-Driven Incident Response Analyst | Hybrid in TX | MDR
AI-Driven Incident Response Analyst | Hybrid in TX | MDR

TrendAI • Irving (TX)

Hybrid
USD 110,000 - 150,000
Health benefits
401(k) plan
Parental leave
+2
Cyber Incident Response Lead (Hybrid)
Cyber Incident Response Lead (Hybrid)

EY • Washington

Hybrid
USD 91,000 - 171,000
Hybrid work model
Total Rewards package
Senior SOC Analyst — AI-Driven Incident Response
Senior SOC Analyst — AI-Driven Incident Response

BeyondTrust • United States

On-site
USD 90,000 - 130,000