DFIR Engineer II – Incident Response

Northwestern Mutual

Milwaukee (WI)

Hybrid

USD 89,000 - 134,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Concierge service
Employee resource groups

Job summary

Northwestern Mutual in Milwaukee is seeking a DFIR Engineer II on the Threat Detection & Response team to respond to, investigate and contain anomalous activity indicating security threats. You will stay current on cyber threats and help refine monitoring, detection and response to abnormal network and host activity.

You will collaborate with Detection Eng and Red Team to improve monitoring and automate responses, while participating in an on-call rotation.

Qualifications

  • Experience with security tools including SIEM, EDR, AV, CASB, next-gen firewalls and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with cloud environments and containerization (AWS, Azure, O365, Docker, Kubernetes).
  • Development or scripting language/framework (PowerShell, Python, .Net) and regular expressions.

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents.
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers

Skills

SIEM
EDR
Cloud environments
Docker
Kubernetes
PowerShell
Python
Regex
MITRE ATT&CK
Analytical thinking
Communication
Threat hunting

Tools

Docker
Kubernetes
PowerShell
Python

Job description

About the Job:

As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You’ll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity.

What You’ll Do:
  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers
What Skills You’ll Bring :
  • Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes).
  • Functional and practical experience with at least one development or scripting language/framework (e.g. PowerShell, Python, .Net) and regular expressions.
  • Strong analytical, problem-solving, and communication skills.
  • Demonstrated curiosity and passion for cybersecurity.
#LI- Hybrid
Compensation Range:

Pay Range – Start:
$89,360.00

Pay Range – End:
$134,040.00

Geographic Specific Pay Structure:

Structure 110:
$98,320.00 USD – $147,480.00 USD

Structure 115:

$102,800.00 USD – $154,200.00 USD
We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable.

Grow your career with a best-in-class company that puts our clients’ interests at the center of all we do.

Northwestern Mutual is an that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.

FIND YOUR FUTURE

We’re excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.

  • Concierge service
  • Employee resource groups PandoLogic. Keywords: Information Security Engineer, Location: Milwaukee, WI – 53205
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Relha LLC • Milwaukee (WI), Northern (KY)

On-site
USD 89,000 - 134,000
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Incident Response Engineer II (Hybrid)
DFIR Incident Response Engineer II (Hybrid)

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II: Threat Detection & IR Specialist
DFIR Engineer II: Threat Detection & IR Specialist

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
Cyber Threat Analyst
Cyber Threat Analyst

Donnelley Financial, LLC • Rockville (MD)

On-site
USD 90,000 - 120,000
Competitive compensation
Flexible workplace
Professional growth opportunities
Sr Threat Hunt Engineer
Sr Threat Hunt Engineer

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • San Francisco (CA)

On-site
USD 237,000 - 297,000
Health benefits
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2