Incident Response Engineer - Cyber Defense

Career Techniques

Dallas (TX)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Career Techniques is seeking an experienced Incident Response Lead to execute end-to-end IR lifecycle with AI-assisted tooling and threat intel. You will act as both hands-on responder and incident leader, coordinating cross-functional teams to rapidly mitigate incidents and improve detection fidelity and response speed.

The role requires 6+ years in security operations, strong Microsoft ecosystem experience, and proficiency with KQL.

Qualifications

  • 6+ years in Cybersecurity Operations / Incident Response.
  • Strong experience within Microsoft Security Ecosystem.
  • Proven experience investigating incidents across cloud, identity, endpoint, and email.
  • Demonstrated experience integrating or leveraging AI/automation in security operations.
  • Strong proficiency in KQL for threat hunting and investigation.
  • Excellent written and verbal communication, including executive-level reporting.
  • Bachelor’s degree in Cybersecurity/IT or related field (or equivalent).
  • Certifications: CISSP, CISM, CISA, or SANS GIAC.

Responsibilities

  • Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts.
  • Lead the full Incident Response lifecycle with focus on rapid detection and containment.
  • Leverage MITRE ATT&CK and Cyber Kill Chain to guide investigations and response.
  • Lead real-time decision-making during active incidents and communicate risk clearly.
  • Utilize AI-assisted platforms to pre-triage alerts and prioritize high-risk activity.
  • Drive AI-based correlation and context aggregation across SIEM/XDR and threat intel sources.
  • Conduct deep-dive investigations across endpoints, identities, email, network, and cloud.
  • Perform host forensics, log analysis, and malware triage to determine scope and persistence.
  • Provide technical leadership and mentorship to junior analysts.
  • Collaborate with IT, Legal, HR, and business stakeholders during investigations.
  • Deliver executive-ready incident reports with impact assessments and actions.
  • Conduct post-incident reviews and root cause analysis to improve controls.

Education

Bachelor’s degree in Cybersecurity/Information Technology or related field
CISSP/CISM/CISA or SANS GIAC certifications

Tools

Microsoft Security Ecosystem
Azure
AWS

Job description

About the Role

This role is responsible for the end-to-end execution of the Incident Response lifecycle, leveraging AI-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment. You will operate as both a hands-on technical responder and incident leader, driving rapid mitigation actions while improving detection fidelity, response speed, and operational efficiency.

Responsibilities
  • Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts and driving containment, eradication, and recovery actions
  • Execute the full Incident Response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain
  • Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain to guide investigations and response strategies
  • Lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated
  • Utilize AI-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue
  • Drive the adoption of AI-based correlation and context aggregation across SIEM/XDR, case management, and threat intelligence sources
  • Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments
  • Perform host forensics, log analysis, and malware triage to determine scope, impact, and persistence mechanisms
  • Drive operational efficiency by reducing manual touchpoints and enabling automated containment and remediation actions
  • Provide technical leadership and mentorship to junior and mid-level analysts, elevating team capability and consistency
  • Collaborate with IT, Engineering, Legal, HR, and business stakeholders during investigations and incident response activities
  • Serve as a key contributor across multiple concurrent initiatives, including tool enablement, process improvement, and security strategy
  • Deliver clear, concise, and executive-ready incident reports, including impact assessments and recommended actions
  • Conduct post-incident reviews and root cause analysis, driving improvements to detection, response, and prevention controls
Requirements and Qualifications
  • 6+ years of hands-on experience in Cybersecurity Operations / Incident Response
  • Strong experience within Microsoft Security Ecosystem
  • Proven experience investigating incidents across cloud (Azure/AWS), identity, endpoint, and email platforms
  • Demonstrated experience integrating or leveraging AI/automation in security operations (e.g., security copilots, ML-based detections, automated triage)
  • Strong proficiency in KQL (Kusto Query Language) for threat hunting and investigation
  • Strong analytical and critical thinking skills with the ability to operate under pressure
  • Excellent written and verbal communication skills, including executive-level reporting
  • Ability to lead incidents, influence stakeholders, and drive rapid decision-making
  • Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience)
  • Certified in one or more of the following: CISSP, CISM, CISA, SANS GIAC Security Certifications.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Manager
Incident Response Manager

Jobtailor • Colorado

On-site
USD 140,000 - 210,000
Cybersecurity Incident Responder
Cybersecurity Incident Responder

DivIHN Integration Inc • Saint Paul (MN)

On-site
USD 70,000 - 100,000
Security Incident Response Engineer
Security Incident Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 125,000 - 165,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Atlas Search • New York (NY)

On-site
USD 140,000 - 190,000
Senior Security Analyst – Security Operations Center
Senior Security Analyst – Security Operations Center

Jobtailor • Town of Florida (NY)

On-site
USD 120,000 - 180,000
Sr. Incident Response Analyst
Sr. Incident Response Analyst

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Senior Incident Response and Threat Management Analyst
Senior Incident Response and Threat Management Analyst

Compunnel, Inc. • Charlotte (NC)

On-site
USD 90,000 - 130,000
Cyber Incident Responder
Cyber Incident Responder

Meriplex • Town of Texas (WI)

On-site
USD 120,000 - 180,000