Enable job alerts via email!

Cybersecurity Engineer / Incident Commander

TekStream Solutions

United States

Remote

USD 90,000 - 130,000

Full time

8 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled Cybersecurity Engineer to enhance their incident response and threat hunting capabilities. In this pivotal role, you will leverage your expertise in Splunk SPL and automation tools to detect and respond to sophisticated cyber threats. Collaborating with red teams and developing security playbooks, you will significantly improve the organization's security posture. This is an exciting opportunity to work in a dynamic environment where your contributions will directly impact the organization's resilience against cyber threats. If you are passionate about cybersecurity and ready to take on challenging responsibilities, this role is perfect for you.

Benefits

Medical insurance
Vision insurance
401(k)
Paid maternity leave
Paid paternity leave
Tuition assistance

Qualifications

  • 5+ years of experience in cybersecurity focused on incident response and threat hunting.
  • Strong expertise in Splunk SPL and security automation.

Responsibilities

  • Lead investigations of security incidents and conduct forensic analysis.
  • Proactively hunt for cyber threats using advanced analytics.

Skills

Incident Response
Threat Hunting
Splunk SPL
Security Automation
Cloud Security
Malware Analysis
Scripting (Python, PowerShell, Bash)

Education

Relevant Cybersecurity Certifications (GIAC, OSCP, etc.)

Tools

Splunk SOAR
CrowdStrike
SentinelOne
Microsoft Defender

Job description

Cybersecurity Engineer / Incident Commander

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from TekStream Solutions

Location: Eastern or central United States, Remote. Must accommodate meetings in the eastern time zone.

This role is ideal for a highly skilled cybersecurity professional with deep expertise in incident response (IR), threat hunting, and Splunk SPL (Search Processing Language). You will play a pivotal role in detecting, analyzing, and responding to sophisticated cyber threats, leveraging Splunk search, Splunk SOAR, and advanced threat intelligence, as well as refining Splunk searches for automated deployment across multiple customers.

Key Responsibilities

  1. Incident Response & Forensics: Lead Level 3 investigations of security incidents, conduct deep-dive forensic analysis, and develop remediation strategies.
  2. Threat Hunting: Proactively hunt for cyber threats within enterprise environments using advanced analytics and threat intelligence.
  3. Splunk Expertise: Develop and optimize SPL queries, build correlation searches, and fine-tune detections to enhance SIEM capabilities.
  4. Threat Intelligence Integration: Utilize threat intelligence to enrich detection capabilities and improve response workflows.
  5. Automation & SOAR: Leverage Splunk SOAR and other automation tools to streamline incident response processes.
  6. Security Best Practices: Develop playbooks, runbooks, and provide guidance to junior analysts to improve overall security posture.
  7. Red Team Collaboration: Work closely with penetration testers and red teams to enhance detection capabilities and improve security defenses.

Qualifications & Skills

  1. 5+ years of experience in cybersecurity with a focus on incident response, threat hunting, and SOC operations.
  2. Deep understanding of cyber kill chain, MITRE ATT&CK framework, and adversary TTPs.
  3. Strong expertise in Splunk SPL, including writing advanced queries, dashboards, correlation rules, and detections.
  4. Hands-on experience with Splunk SOAR for security automation and orchestration.
  5. Experience with malware analysis, digital forensics, memory analysis, and network traffic analysis.
  6. Knowledge of cloud security (AWS, Azure, or GCP) and detection strategies for cloud-based threats.
  7. Familiarity with endpoint detection and response (EDR) tools such as CrowdStrike, SentinelOne, Microsoft Defender, etc.
  8. Scripting and automation skills in Python, PowerShell, or Bash are a plus.
  9. Relevant certifications such as GIAC GCFA, GCFE, GCIH, OSCP, Splunk Certified Admin/Architect are highly desirable.

Daily Duties

  1. 50% (approximately 20 hours/week) managing the library of searches
  2. 25% (approximately 10 hours/week) performing incident commander duties (based on when incidents occur)
  3. 25% (approximately 10 hours/week) doing proactive threat hunting
Seniority level
  • Mid-Senior level
Employment type
  • Full-time
Job function
  • Information Technology and Consulting
Industries
  • IT Services and IT Consulting

Referrals increase your chances of interviewing at TekStream Solutions by 2x

Inferred from the description for this job
  • Medical insurance
  • Vision insurance
  • 401(k)
  • Paid maternity leave
  • Paid paternity leave
  • Tuition assistance

Get notified about new Cyber Security Engineer jobs in United States.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Cybersecurity Engineer (Incident Response)

Amentum

Remote

USD 80,000 - 110,000

3 days ago
Be an early applicant

Senior Cybersecurity Engineer (Networking)

Amentum

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

Senior Cybersecurity Engineer (Networking)

Amentum

Juneau

Remote

USD 80,000 - 120,000

4 days ago
Be an early applicant

Cybersecurity Engineer

Southwest Airline Career Page

Dallas

Remote

USD 116,000 - 130,000

Yesterday
Be an early applicant

Senior Software Engineer

Bitesize

Remote

USD 100,000 - 120,000

Yesterday
Be an early applicant

NetSuite Developer

Pearson Carter

Remote

USD 120,000 - 150,000

Today
Be an early applicant

Technical Content Developer - Cybersecurity

Udacity

Remote

USD 100,000 - 135,000

Today
Be an early applicant

Senior Field Application Engineer

Set2Recruit

Remote

USD 90,000 - 190,000

Today
Be an early applicant

Senior Information Security Engineer – Cloud - Remote

Caris Life Sciences

Remote

USD 125,000 - 180,000

-1 days ago
Be an early applicant