Incident Responder I — Detection & Automation Oversight

Bentley Systems

Philadelphia (Philadelphia County)

Hybrid

USD 70,000 - 100,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Bentley Impact Day
Colleague recognition program
Bentley Achievers platform
Inclusion & wellbeing initiatives

Job summary

Bentley Systems, a leader in infrastructure software, seeks an Incident Responder I to join its Security Operations Center. In this hybrid role, you will validate automated verdicts, contain threats within defined autonomy, and drive improvements across detections and playbooks in a global cloud environment.

Ideal candidates have 1–2 years in security or IT, familiarity with automation, and a proactive approach to learning.

Qualifications

  • 1–2 years of education or training in a security-related field, or equivalent IT experience.
  • Familiarity with operating systems, auth protocols, networks, email systems and cloud models (IaaS/PaaS/SaaS).
  • Basic understanding of cyberattacks, MITRE ATT&CK as reference.

Responsibilities

  • Monitor and respond to SIEM, SOAR, endpoint, and cloud security alerts.
  • Review automated verdicts and take action (close, escalate, contain).
  • Own inconclusive queue and document outcomes for automation improvements.
  • Handoffs between shifts with complete notes; follow incident response procedure.

Skills

Security basics
MITRE ATT&CK
Automation familiarity
Documentation habits
24x7 shift readiness

Education

Security-related field or IT experience

Tools

CrowdStrike
Wiz
Microsoft Sentinel

Job description

Location: Hybrid - Philadelphia, PA preferred. Home-based arrangements will be considered for exceptional candidates where business needs permit.Position Summary:Bentley’s Information Security team is building a security operation where automation does the first pass and people do the judgment. Automated investigation agents already triage most of our alerts, investigate cloud risks, and test our own defenses around the clock. What they cannot do is decide whether they were right, handle the cases they could not resolve, or make the next detection better.As an Incident Responder I, you join the Security Operations Center at the point where an alert becomes a decision. You will verify what automation concluded, own the cases it hands back, take containment actions within clearly defined limits, and feed what you learn back into detections and playbooks. You will work with modern tooling — CrowdStrike, Wiz, a cloud-native SIEM and SOAR platform — across a global engineering and SaaS environment spanning three public clouds.This is an entry point, not a destination. The role is designed so that the share of your time spent on routine response falls as your share of engineering and improvement work grows, and it sits on a defined career path into detection engineering, security engineering, architecture, or governance.Responsibilities:Keep us safe todayMonitor and respond to alerts and cases from the SIEM, SOAR, endpoint, and cloud security platforms, including the output of automated investigation agents.Review automated verdicts — malicious, not malicious, inconclusive — and act on them: confirm and close, escalate, or contain within the approved autonomy tier (isolate a host, revoke a session, block an indicator).Own the inconclusive queue: investigate what automation could not resolve and document the outcome so the same class of case can be automated next time.Hand off and receive incidents cleanly across shifts with complete, structured notes; escalate to senior responders and management per the incident response procedure.Sharpen what we haveSample automated verdicts for accuracy (false positives and false negatives) and report findings; your sampling doubles as audit evidence for our compliance program.Tune existing detections and playbooks based on what your shift observed; keep runbooks current.Watch the health of the tooling the SOC depends on — sensor coverage, connector status, log sources — and raise gaps before they become blind spots.Help build what’s nextContribute to detection-as-code: propose new detections and playbook steps, version them, and test them with a senior engineer.Learn the behavioral baselines of AI agents operating in our environment and flag abnormal agent activity — a new class of alert this SOC owns.Take part in post-incident reviews and turn lessons into automation requests for the engineering team.Qualifications:1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration.Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS).A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference.Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why.Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system.Availability for a shift rotation as part of a 24×7 operation.This is a full-time role expected to work 40 hours per week, based in the USA and does not require travel.Requires sitting or standing at will while performing work on a computer.Applicants must be authorized to work in the U.S. without current or future employer sponsorship.Preferred Qualifications:Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL.Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM.Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications.#LI-MG1#LI-REMOTE#LI-HYBRIDThis is a Hybrid role.What We Offer:Step into a collaborative work environment where ideas flourish, and teamwork propels us forward towards shared success.An attractive salary and benefits package.Bentley Impact Day: take a day off from work to volunteer with an organization of your choice.Celebrate milestone achievements and moments that matter through our colleague recognition award programs and our Bentley Achievers platform.A commitment to inclusion, belonging and colleague wellbeing through global initiatives and resource groups.Be part of a company committed to making a real difference by advancing the world’s infrastructure for better quality of life, where your contributions help build a more sustainable, connected, and resilient world. Discover our latest user success stories for an insight into our global impact.Who We Are:Bentley Systems (Nasdaq: BSY) is the infrastructure engineering software company. We provide innovative software to advance the world’s infrastructure – sustaining both the global economy and environment. Our industry-leading software solutions are used by professionals, and organizations of every size, for the design, construction, and operations of roads and bridges, rail and transit, water and wastewater, public works and utilities, buildings and campuses, mining, and industrial facilities. Our offerings, powered by the iTwin Platform for infrastructure digital twins, include MicroStation and Bentley Open applications for modeling and simulation, Seequent’s software for geoprofessionals, and Bentley Infrastructure Cloud encompassing ProjectWise for project delivery, SYNCHRO for construction management, and AssetWise for asset operations. Bentley Systems’ 5,200 colleagues generate annual revenues of more than $1 billion in 194 countries.Equal Opportunity Employer:Bentley is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, sex, sexual orientation, gender identity, disability, pregnancy, protected veteran status, religion, national origin, age, genetic information or any other protected characteristic. This commitment extends to all aspects of employment, including, but not limited to, hiring, placement, promotion, compensation, and training. Know Your Rights as an applicant under the law.Bentley Policy on EEO, Affirmative Action and Pay Transparency Non-DiscriminationBentley participates in e-Verify / Bentley participate in e-Verify / Right to Work NoticeRequest an Accommodation:As an Equal Opportunity Employer, Bentley is committed to providing reasonable accommodations to applicants with disabilities. We encourage you to request a reasonable accommodation if you are not able to fully use or access our online application system. You can make an accommodation request by calling 610-458-5000 or sending us an email at disabilityrequest@bentley.com
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Responder I — Detection & Automation Oversight
Incident Responder I — Detection & Automation Oversight

1000 Bentley Systems, Incorporated • Philadelphia

Hybrid
USD 65,000 - 95,000
Bentley Impact Day
Colleague recognition program
Inclusion and wellbeing programs
Senior Site Reliability Engineer
Senior Site Reliability Engineer

1000 Bentley Systems, Incorporated • Exton (PA)

Hybrid
USD 130,000 - 185,000
Salary and benefits package
Bentley Impact Day
Colleague recognition programs
+2
Senior Software Engineer
Senior Software Engineer

Bentley Systems • Eagleview (PA)

Hybrid
USD 120,000 - 170,000
Bentley Impact Day
Colleague recognition program
Inclusion and wellbeing programs
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Bentley Systems • Philadelphia

Hybrid
USD 150,000 - 190,000
Bentley Impact Day
Colleague recognition programs
Bentley Achievers platform
Senior Technical Support Engineer
Senior Technical Support Engineer

1000 Bentley Systems, Incorporated • United States

Hybrid
USD 120,000 - 170,000
Collaborative culture
Salary & benefits
Bentley Impact Day
+3
Senior Software Engineer
Senior Software Engineer

Bentley Systems • Exton (PA)

Hybrid
USD 120,000 - 180,000
Bentley Impact Day
Recognition programs
Inclusion and wellbeing initiatives
+1
Director, Corporate Crisis & Risk Readiness
Director, Corporate Crisis & Risk Readiness

Bentley Systems • Eagleview (PA)

Hybrid
USD 140,000 - 230,000
Bentley Impact Day
Recognition programs and Bentley Achie
Division Security Champion
Division Security Champion

1000 Bentley Systems, Incorporated • Exton (PA)

Remote
USD 180,000 - 240,000
Bentley Impact Day
Recognition programs
Inclusion & wellbeing initiatives
+1
Senior Engineer, AI Code Modernization
Senior Engineer, AI Code Modernization

Bentley Systems • Eagleview (PA)

Hybrid
USD 150,000 - 230,000
Bentley Impact Day
Bentley Achievers platform
Division Security Champion
Division Security Champion

Bentley Systems • United States

Remote
USD 180,000 - 260,000
Bentley Impact Day
Colleague recognition program
Inclusion initiatives