DFIR Engineer II - Incident Response

Northwestern Mutual

New York (NY)

Hybrid

USD 89,000 - 134,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Northwestern Mutual seeks a DFIR Engineer II to join the Threat Detection & Response team. You will investigate, triage and contain anomalous activity, study threats, and help refine monitoring and incident response capabilities across endpoints and network logs.

Responsibilities include proactive threat hunting, documenting findings with timelines, and collaborating with Detection Engineering and Red Team to automate responses.

Qualifications

  • Experience with security tooling and incident response.
  • Familiarity with network and host artifacts for threat detection.
  • Working knowledge of MITRE ATT&CK framework.

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity using threat intelligence.
  • Document detailed findings including timelines of events or incidents.
  • Continually improve incident response procedures and documentation.
  • Collaborate with Detection Engineering and Red Team to automate responses.
  • Stay up to date on evolving cyber threats and detection methods.
  • Participate in on-call rotation.

Skills

SIEM
EDR
MITRE ATT&CK
Cloud Awareness
Docker/Kubernetes
PowerShell
Python
Incident response
Analytical thinking
On-call

Tools

SIEM
EDR
VPN
Next-gen Firewalls
Docker
Kubernetes
PowerShell
Python
.NET

Job description

About the Job:

As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You’ll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity.

What You’ll Do:
  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers
What Skills You’ll Bring :
  • Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes).
  • Functional and practical experience with at least one development or scripting language/framework (e.g. PowerShell, Python, .Net) and regular expressions.
  • Strong analytical, problem-solving, and communication skills.
  • Demonstrated curiosity and passion for cybersecurity.

#LI- Hybrid

Compensation Range:

Pay Range - Start:

$89,360.00

Pay Range - End:

$134,040.00

Geographic Specific Pay Structure:

Structure 110:

$98,320.00 USD - $147,480.00 USD

Structure 115:

$102,800.00 USD - $154,200.00 USD

We believe in fairness and transparency. It’s why we share the salary range for most of our roles. However, final salaries are based on a number of factors, including the skills and experience of the candidate; the current market; location of the candidate; and other factors uncovered in the hiring process. The standard pay structure is listed but if you’re living in California, New York City or other eligible location, geographic specific pay structures, compensation and benefits could be applicable, click here to learn more.

Grow your career with a best-in-class company that puts our clients’ interests at the center of all we do. Get started now!

Northwestern Mutual is an equal opportunity employer that welcomes talented individuals of all backgrounds. We are committed to creating and maintaining an environment in which each employee can contribute creative ideas, seek challenges, assume leadership and continue to focus on meeting and exceeding business and personal objectives.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II – Incident Response
DFIR Engineer II – Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • New York (NY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II: Threat Detection & IR Specialist
DFIR Engineer II: Threat Detection & IR Specialist

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
Sr Threat Hunt Engineer
Sr Threat Hunt Engineer

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR – Engagement Manager
DFIR – Engagement Manager

Socket.dev • United States

On-site
USD 132,000 - 160,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Medical/dental/vision coverage
+1
Consulting Director, DFIR, Reactive Services (Unit 42)
Consulting Director, DFIR, Reactive Services (Unit 42)

Palo Alto Networks, Inc. • Burbank (CA)

On-site
USD 183,000 - 252,000
Staff Information Security Engineer - Threat Defense & Automation
Staff Information Security Engineer - Threat Defense & Automation

Proofpoint • Sunnyvale (CA)

Hybrid
USD 188,000 - 275,000
Competitive compensation
Comprehensive benefits
Career growth on your terms
+4
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan