DFIR Engineer II - Incident Response - northwesternmutual

OpenTalent

Milwaukee (WI)

On-site

USD 110,000 - 140,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Northwestern Mutual is seeking a DFIR Engineer II to join the Threat Detection & Response team. You will respond to and investigate anomalous or malicious activity, stay updated on cyber threats, and help refine monitoring, detecting, and responding to incidents across networks and hosts.

You will triage across log sources, analyze artifacts, hunt for threats, document timelines, and collaborate with Detection Engineering and Red Team to automate responses.

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, or equivalent combination of education, training, and experience.
  • Two or more years in an Incident Response or Security Operations Center (SOC) role.
  • Background in information technology with an emphasis on network or systems administration.
  • Hold or willingness to obtain certifications such as GCIH, GCFE, GCFA, GDAT, CISSP or other relevant security certifications.
  • Foundational understanding of networking, Windows, Mac & Linux operating systems, and cybersecurity principles.

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers

Skills

SIEM
EDR
VPN
Next-gen Firewalls
CASB
AV
Windows
Linux
MITRE ATT&CK
Cloud environments
Docker
Kubernetes

Education

Bachelor's Degree (Information Security / CS or equivalent)

Tools

Docker
Kubernetes
AWS
Azure
Office 365 (O365)

Job description

At Northwestern Mutual, we believe relationships are built on trust. That our lives and our work matter. These beliefs launched our company nearly 160 years ago. Today, they're just a few of the reasons why people choose to build careers at Northwestern Mutual!

We're strong and growing. In a company with such a long and storied history, this may be the most exciting and important time to be a part of Northwestern Mutual. We're strong, innovative, and growing

We invest in our people. We provide opportunities for employees to grow themselves, their career, and in turn, our business.

About the Job:

As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You'll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity.

What You'll Do:

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers

Minimum Qualifications:

  • Bachelor's Degree in Information Security, Computer Science, or equivalent combination of education, training, and experience.
  • Two or more years in an Incident Response or Security Operations Center (SOC) role.
  • Background in information technology with an emphasis on network or systems administration.
  • Hold or willingness to obtain certifications such as GCIH, GCFE, GCFA, GDAT, CISSP or other relevant security certifications.
  • Foundational understanding of networking, Windows, Mac & Linux operating systems, and cybersecurity principles.

What Skills You'll Bring:

  • Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II – Incident Response
DFIR Engineer II – Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • New York (NY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • New York (NY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II: Threat Detection & IR Specialist
DFIR Engineer II: Threat Detection & IR Specialist

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work