DFIR Engineer II - Incident Response

Northwestern Mutual

Milwaukee (WI)

Hybrid

USD 89,000 - 134,000

Full time

29 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus
Medical plan
Dental plan
Vision plan
401(k) plan
Pension program
Tuition reimbursement
PTO
Holiday pay
Professional training
Work-life balance
Flexible work schedules
Concierge service
Comprehensive benefits
Employee resource groups

Job summary

Northwestern Mutual seeks a DFIR Engineer II to join the Threat Detection & Response team in Milwaukee. You will respond to, investigate, and contain anomalous activity, stay current with cybersecurity threats, and help refine monitoring, detection, and response capabilities across networks and hosts.

The role requires hands-on incident handling, collaboration with security engineers, and participation in on-call rotations.

Qualifications

  • Bachelor’s degree or equivalent in information security, computer science, or related field.
  • Two+ years in an Incident Response or SOC role.
  • IT background with emphasis on network or systems administration.
  • Willingness to obtain security certifications (e.g., GCIH, GCFE, GCFA, GDAT, CISSP).

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity using threat intelligence.
  • Document detailed findings including timelines of events or incidents.
  • continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to improve monitoring and automate response.
  • Keep up to date on evolving cyber threats and detection methods.
  • Participate in on-call rotation with other Incident Response Engineers

Skills

SIEM
EDR
AV
CASB
Next-gen Firewalls
VPN
MITRE ATT&CK
AWS
Azure
O365
Docker
Kubernetes
PowerShell
Python
.NET

Education

Bachelor’s Degree in Information Security, Computer Science, or equivalent

Tools

Scripting languages/frameworks

Job description

At Northwestern Mutual, we believe relationships are built on trust. That our lives and our work matter. These beliefs launched our company nearly 160 years ago. Today, they're just a few of the reasons why people choose to build careers at Northwestern Mutual!

We're strong and growing. In a company with such a long and storied history, this may be the most exciting and important time to be a part of Northwestern Mutual. We're strong, innovative, and growing

We invest in our people. We provide opportunities for employees to grow themselves, their career, and in turn, our business.

About The Job

As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You’ll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity.

What You'll Do
  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident ResponseEngineers
Minimum Qualifications
  • Bachelor’s Degree in Information Security, Computer Science, or equivalent combination of education, training, and experience.
  • Two or more years in an Incident Response or Security Operations Center (SOC) role.
  • Background in information technology with an emphasis on network or systems administration.
  • Hold or willingness to obtain certifications such as GCIH, GCFE, GCFA, GDAT, CISSP or other relevant security certifications.
  • Foundational understanding of networking, Windows, Mac & Linux operating systems, and cybersecurity principles.
What Skills You'll Bring
  • Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes).
  • Functional and practical experience with at least one development or scripting language/framework (e.g. PowerShell, Python, .Net) and regular expressions.
  • Strong analytical, problem-solving, and communication skills.
  • Demonstrated curiosity and passion for cybersecurity.
Our Benefits!
  • We offer highly competitive compensation, including annual bonus opportunities
  • Medical/Dental/Vision plans, 401(k), pension program
  • We provide tuition reimbursement, PTO, and Holiday Pay
  • We provide extensive Professional Training Opportunities
  • We offer an excellent Work/Life Balance
Hybrid
Compensation Range

Pay Range - Start:

$89,360.00

Pay Range - End

$134,040.00

Structure 110
Geographic Specific Pay Structure:
Structure 115

We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable,

Grow your career with a best-in-class company that puts our clients’ interests at the center of all we do.

Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.

FIND YOUR FUTURE

We’re excited about the potential people bring to Northwestern Mutual. You can grow your career here while enjoying first-class perks, benefits, and our commitment to a culture of belonging.

  • Flexible work schedules
  • Concierge service
  • Comprehensive benefits
  • Employee resource groups
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 89,000 - 134,000
Sr Threat Hunt Engineer
Sr Threat Hunt Engineer

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II — Incident Response & Threat Hunting
DFIR Engineer II — Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Annual bonus
Medical plan
Dental plan
+12
DFIR Incident Response Engineer II (Hybrid)
DFIR Incident Response Engineer II (Hybrid)

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 89,000 - 134,000
Sr. Threat Detection & Automation Engineer (with focus on Data Engineering)
Sr. Threat Detection & Automation Engineer (with focus on Data Engineering)

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 131,000 - 196,000
Hybrid work arrangement
Contract, Licensing & Registration Senior Analyst
Contract, Licensing & Registration Senior Analyst

Northwestern Mutual • Milwaukee (WI)

Hybrid
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Software Engineer II
Software Engineer II

Northwestern Mutual • Milwaukee (WI)

On-site
USD 98,000 - 170,000
Technical Business Analyst II
Technical Business Analyst II

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 76,000 - 113,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Field Tech Solutions & Support Cons II
Field Tech Solutions & Support Cons II

Relha LLC • Charleston (WV), Northern (KY)

Hybrid
USD 70,000 - 105,000
Software Engineer II
Software Engineer II

Relha LLC • Milwaukee (WI)

On-site
USD 98,000 - 147,000