DFIR Engineer II: Threat Detection & IR Specialist

Northwestern Mutual

Milwaukee (WI)

Hybrid

USD 89,000 - 134,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Concierge service
Employee resource groups

Job summary

Northwestern Mutual in Milwaukee is seeking a DFIR Engineer II on the Threat Detection & Response team to respond to, investigate and contain anomalous activity indicating security threats. You will stay current on cyber threats and help refine monitoring, detection and response to abnormal network and host activity.

You will collaborate with Detection Eng and Red Team to improve monitoring and automate responses, while participating in an on-call rotation.

Qualifications

  • Experience with security tools including SIEM, EDR, AV, CASB, next-gen firewalls and VPN.
  • Experience with system and network artifacts.
  • Working knowledge of the MITRE ATT&CK framework.
  • Familiarity with cloud environments and containerization (AWS, Azure, O365, Docker, Kubernetes).
  • Development or scripting language/framework (PowerShell, Python, .Net) and regular expressions.

Responsibilities

  • Triage, pivot and correlate across multiple network and host-based log sources.
  • Analyze system artifacts and memory for evidence of compromise.
  • Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise.
  • Document detailed findings including timelines of events or incidents.
  • Continually improve incident response procedures and documentation.
  • Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities.
  • Keep up to date on evolving cyber threats and identify methods to detect them.
  • Participate in an on-call rotation with other Incident Response Engineers

Skills

SIEM
EDR
Cloud environments
Docker
Kubernetes
PowerShell
Python
Regex
MITRE ATT&CK
Analytical thinking
Communication
Threat hunting

Tools

Docker
Kubernetes
PowerShell
Python

Job description

Northwestern Mutual in Milwaukee is seeking a DFIR Engineer II on the Threat Detection & Response team to respond to, investigate and contain anomalous activity indicating security threats. You will stay current on cyber threats and help refine monitoring, detection and response to abnormal network and host activity.

You will collaborate with Detection Eng and Red Team to improve monitoring and automate responses, while participating in an on-call rotation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engineer II: Incident Response & Threat Hunting
DFIR Engineer II: Incident Response & Threat Hunting

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
DFIR Incident Response Engineer II (Hybrid)
DFIR Incident Response Engineer II (Hybrid)

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 89,000 - 134,000
DFIR Engineer II – Incident Response
DFIR Engineer II – Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Concierge service
Employee resource groups
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Relha LLC • Milwaukee (WI), Northern (KY)

On-site
USD 89,000 - 134,000
DFIR Engineer II - Incident Response
DFIR Engineer II - Incident Response

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 89,000 - 134,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Senior Threat Detection & Automation Architect
Senior Threat Detection & Automation Architect

Relha LLC • Milwaukee (WI), Northern (KY)

Hybrid
USD 131,000 - 196,000
Hybrid work arrangement
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections
Senior Threat Hunt Engineer - Hybrid, AI-Driven Detections

Northwestern Mutual • Milwaukee (WI)

Hybrid
USD 118,000 - 179,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5
Cyber Threat Analyst
Cyber Threat Analyst

Donnelley Financial, LLC • Rockville (MD)

On-site
USD 90,000 - 120,000
Competitive compensation
Flexible workplace
Professional growth opportunities