Enable job alerts via email!

Cybersecurity Engineer / Incident Commander

TekStream Solutions

United States

Remote

USD 85,000 - 110,000

Full time

Yesterday
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Cybersecurity Engineer / Incident Commander to enhance their security posture. The ideal candidate will have extensive experience in incident response and threat hunting, utilizing Splunk for advanced threat detection. You'll collaborate with teams to improve security practices and automate incident response processes. This remote role requires strong analytical skills and a proactive approach to cybersecurity challenges.

Benefits

Medical Insurance
Vision Insurance
401(k)
Paid Maternity Leave
Paid Paternity Leave
Tuition Assistance

Qualifications

  • 5+ years of experience in cybersecurity focused on incident response and threat hunting.
  • Strong expertise in Splunk SPL and automation tools.

Responsibilities

  • Lead Level 3 investigations and develop remediation strategies.
  • Proactively hunt for cyber threats using advanced analytics.

Skills

Incident Response
Threat Hunting
Splunk SPL
Cyber Kill Chain
Automation
Cloud Security
Scripting

Education

Relevant Certifications

Tools

Splunk SOAR
EDR Tools

Job description

Cybersecurity Engineer / Incident Commander

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from TekStream Solutions

Location: Eastern or central United States, Remote. Must accommodate meetings in the eastern time zone.

This role is ideal for a highly skilled cybersecurity professional with deep expertise in incident response (IR), threat hunting, and Splunk SPL (Search Processing Language). You will play a pivotal role in detecting, analyzing, and responding to sophisticated cyber threats, leveraging Splunk search, Splunk SOAR, and advanced threat intelligence, as well as refining Splunk searches for automated deployment across multiple customers.

Key Responsibilities

  • Incident Response & Forensics: Lead Level 3 investigations of security incidents, conduct deep-dive forensic analysis, and develop remediation strategies.
  • Threat Hunting: Proactively hunt for cyber threats within enterprise environments using advanced analytics and threat intelligence.
  • Splunk Expertise: Develop and optimize SPL queries, build correlation searches, and fine-tune detections to enhance SIEM capabilities.
  • Threat Intelligence Integration: Utilize threat intelligence to enrich detection capabilities and improve response workflows.
  • Automation & SOAR: Leverage Splunk SOAR and other automation tools to streamline incident response processes.
  • Security Best Practices: Develop playbooks, runbooks, and provide guidance to junior analysts to improve overall security posture.
  • Red Team Collaboration: Work closely with penetration testers and red teams to enhance detection capabilities and security defenses.

Qualifications & Skills

  • 5+ years of experience in cybersecurity with a focus on incident response, threat hunting, and SOC operations.
  • Deep understanding of the cyber kill chain, MITRE ATT&CK framework, and adversary TTPs.
  • Strong expertise in Splunk SPL, including writing advanced queries, dashboards, correlation rules, and detections.
  • Hands-on experience with Splunk SOAR for security automation and orchestration.
  • Experience with malware analysis, digital forensics, memory analysis, and network traffic analysis.
  • Knowledge of cloud security (AWS, Azure, or GCP) and detection strategies for cloud-based threats.
  • Familiarity with endpoint detection and response (EDR) tools such as CrowdStrike, SentinelOne, Microsoft Defender, etc.
  • Scripting and automation skills in Python, PowerShell, or Bash are a plus.
  • Relevant certifications such as GIAC GCFA, GCFE, GCIH, OSCP, Splunk Certified Admin/Architect are highly desirable.

Daily Duties

  • Approximately 50% (about 20 hours/week) managing the library of searches.
  • Approximately 25% (about 10 hours/week) performing incident commander duties (based on incident occurrence).
  • Approximately 25% (about 10 hours/week) engaging in proactive threat hunting.
Seniority level

Not Applicable

Employment type

Full-time

Job function

Information Technology and Consulting

Industries

IT Services and IT Consulting

Referrals increase your chances of interviewing at TekStream Solutions by 2x

Inferred from the description for this job

Medical insurance

Vision insurance

401(k)

Paid maternity leave

Paid paternity leave

Tuition assistance

Get notified about new Cyber Security Engineer jobs in United States.

United States $85,000.00-$110,000.00 11 hours ago

San Francisco, CA $139,100.00-$206,000.00 2 weeks ago

North Carolina, United States $92,558.61-$120,326.20 3 weeks ago

Other similar jobs

Cyber Security Detection Engineer - (Fulltime) 100% Remote, United States, $65,000.00-$75,000.00, 3 days ago

Cyber Security Engineer (Remote Opportunity), Home, KS, $105,000.00-$125,000.00, 3 months ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Cybersecurity Engineer / Incident Commander

TekStream Solutions

Remote

USD 90,000 - 130,000

13 days ago

Software Engineer (React, TypeScript)

Acceler8 Talent

Remote

USD 100,000 - 720,000

Today
Be an early applicant

Cyber Security Engineer

WhoisXML API

Remote

USD 85,000 - 110,000

2 days ago
Be an early applicant

ADMS / SCADA Application Engineer (GE eTerra or Power On Reliance Experience)

WT Partners

Remote

USD 100,000 - 720,000

Today
Be an early applicant

AWS Senior Solutions Architect - Pre-sales - REMOTE

Perficient

Remote

USD 92,000 - 203,000

Today
Be an early applicant

Junior Frontend Software Engineer (Remote - US)

Jobgether

Remote

USD 50,000 - 120,000

Today
Be an early applicant

Solutions Architect I

Planet

Remote

USD 93,000 - 127,000

Today
Be an early applicant

Software Engineer - Growth Team

Wikimedia Foundation

San Francisco

Remote

USD 89,000 - 139,000

Today
Be an early applicant

Software Engineer - Growth Team

Wikimedia Foundation

Remote

USD 89,000 - 139,000

Today
Be an early applicant