Engineer - Security Operations and Incident Response

Pearl Consulting Group.

Northern (KY)

Hybrid

USD 110,000 - 170,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Pearl Consulting Group is seeking an Engineer in Security Operations and Incident Response. The role focuses on maturing the organization's SOC and IR program, with responsibilities spanning digital forensics, playbook development, threat modeling, and detection engineering in hybrid cloud environments.

Ideal candidates bring 5+ years in IR, strong SIEM/SOAR experience, and proficiency in scripting. This position supports remote and hybrid work arrangements across North America.

Qualifications

  • Bachelor’s degree with 5+ years in incident response and SOC tooling.

Responsibilities

  • Provide expert support for deep‑dive investigations including digital forensics.
  • Author IR playbooks and guidelines to keep the team agile.
  • Develop threat models and incorporate pen-test findings into detection strategies.
  • Design complex detection rules and automated remediation workflows.
  • Utilize threat intel and MITRE ATT&CK to identify visibility gaps.
  • Maintain docs of detection strategies and incident timelines.
  • Tune SIEM rules to maximize detection and minimize alert fatigue.
  • Review threat intel and dark web monitoring systems.
  • Script and query using Python/PowerShell/Bash/XQL; leverage SOAR.
  • Support IR leadership as backup on IR activities.

Skills

Incident response
SOC tooling
Threat modeling
Scripting languages
Python
PowerShell
Bash
XQL
Communication
Hybrid cloud ops

Education

Bachelor’s degree

Tools

Microsoft Sentinel
Cortex XSIAM
XSOAR

Job description

Job Title:Engineer - Security Operations and Incident Response

Location:USA or Canada (Remote or Hybrid)

Description

This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.

Primary Responsibilities
  • Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
  • Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
  • Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
  • Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
  • Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
  • Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
  • Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
  • Review and tune threat intelligence systems, including brand protection and dark web monitoring.
  • Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
  • Support IR leadership as backup on IR-related activities.
Qualifications
  • Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
  • In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
  • Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
  • Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
  • Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
  • Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
  • Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Incident Response Manager
Incident Response Manager

Infinite Ranges • United States

On-site
USD 165,000 - 248,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Charlotte (NC)

On-site
USD 140,000 - 210,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Security Specialist - Incident.io
Security Specialist - Incident.io

Executive Operations, LLC • South Lyon (MI)

On-site
USD 80,000 - 120,000