Engineer - Security Operations and Incident Response

Jobgether

United States

Hybrid

USD 125,000 - 190,000

Full time

3 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote or hybrid work

Job summary

Jobgether in the United States seeks an Engineer - Security Operations and Incident Response to strengthen and evolve a global SOC program. You will protect enterprise environments by investigating, containing, and eradicating threats, blending incident response with detection engineering, automation, and threat intelligence.

Collaborate across hybrid cloud environments (GCP, Azure), tune SIEM and SOAR tooling, develop playbooks, and contribute to threat modeling and documentation to improve

Qualifications

  • Bachelor's degree and at least 5 years of relevant professional experience in incident response and SOC tooling.
  • Experience with SIEM and SOAR platforms including Microsoft Sentinel, Cortex XSIAM, and Cortex XSOAR.
  • Strong scripting and query-building skills in Python, PowerShell, Bash, and XQL.

Responsibilities

  • Conduct expert-level investigations into complex security incidents.
  • Develop and refine incident response playbooks and operational guidelines.
  • Design and optimize detection rules and automated remediation workflows.

Skills

Threat intelligence
Detection engineering
Security automation
Incident response
Scripting languages

Education

Bachelor's degree

Tools

Microsoft Sentinel
Cortex XSIAM
Cortex XSOAR

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Engineer - Security Operations and Incident Response based in United States.

This role is central to strengthening and continuously evolving a global Security Operations and Incident Response program.

You will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats.

The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident response.

You will work across hybrid cloud environments while improving security processes, technologies, and operational resilience.

Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the organization.

You will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows.

This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.

Accountabilities
  • Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
  • Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
  • Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
  • Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
  • Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
  • Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
  • Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
  • Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
  • Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
  • Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
  • Support incident response leadership as a backup resource for incident response activities and operational priorities.
  • Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.
Requirements
  • Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
  • In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
  • Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
  • Experience serving as an incident commander during security incidents and leading coordinated response efforts.
  • Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
  • Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
  • Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
  • Experience with threat intelligence, detection engineering, security automation, and incident response processes.
  • Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
  • Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
  • Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.
Benefits
  • Remote or hybrid work options.
  • Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
  • Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
  • Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
  • High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
  • Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - SOC & IR
Engineer - SOC & IR

Pearl Consulting Group • United States

On-site
USD 120,000 - 180,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Lead SOC IR Engineer - Remote/Hybrid
Lead SOC IR Engineer - Remote/Hybrid

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Cybersecurity Operations & Incident Response Manager
Cybersecurity Operations & Incident Response Manager

Jobgether • Town of Texas (WI)

Hybrid
USD 162,000 - 200,000
Competitive salary range: $162,681 – $200,000
Health, dental, and vision coverage
401(k) retirement savings plan
+3
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Security Specialist - Incident.io
Security Specialist - Incident.io

Executive Operations, LLC • South Lyon (MI)

On-site
USD 80,000 - 120,000
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Charlotte (NC)

On-site
USD 140,000 - 210,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000