DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual

Milwaukee (WI)

Hybrid

USD 89,000 - 134,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Flexible work schedules
Concierge service
Comprehensive benefits
Employee resource groups

Job summary

Northwestern Mutual is seeking an experienced DFIR Engineer II to join the Threat Detection & Response team. You will respond to, investigate, and contain anomalous activity, staying current on cybersecurity threats and refining monitoring and response capabilities.

The role requires collaboration with Detection Engineering and Red Team, and participation in on-call rotations. A strong foundation in security operations and cross-platform environments is essential.

Qualifications

  • Bachelor's Degree in Information Security, Computer Science, or equivalent combination of education, training, and experience.

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident ResponseEngineers

Skills

SIEM
EDR
VPN
Next-gen Firewalls
CASB
AWS
Azure
O365
Docker
Kubernetes
PowerShell
Python

Education

Bachelor's Degree in Information Security, Computer Science, or equivalent

Tools

Windows
Mac
Linux

Job description

Northwestern Mutual is seeking an experienced DFIR Engineer II to join the Threat Detection & Response team. You will respond to, investigate, and contain anomalous activity, staying current on cybersecurity threats and refining monitoring and response capabilities.

The role requires collaboration with Detection Engineering and Red Team, and participation in on-call rotations. A strong foundation in security operations and cross-platform environments is essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • New York (NY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II: Threat Detection & IR Specialist
DFIR Engineer II: Threat Detection & IR Specialist

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
DFIR Engineer II – Incident Response
DFIR Engineer II – Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • New York (NY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Cyber Defense Incident Responder II: DFIR & Threat Hunting
Cyber Defense Incident Responder II: DFIR & Threat Hunting

Socket.dev • Chicago (IL)

On-site
USD 94,000 - 157,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5
Network DFIR Analyst III – Incident Response
Network DFIR Analyst III – Incident Response

Solutions³ LLC • Arlington (VA)

On-site
USD 120,000 - 180,000