IT Security Engineer IV – DFIR & Detection

Gravity IT Resources

Northern (KY)

Hybrid

USD 120,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Gravity IT Resources seeks a Senior Security Engineer with strong DFIR, detection engineering, security automation and cloud security. This hands-on role supports a large-scale security operations environment, collaborating with incident response and DLP teams to investigate activity, improve visibility, and build detections.

The position is a 12-month remote contract. Central Time preferred, Eastern Time considered.

Qualifications

  • 4+ years of cybersecurity experience including hands-on detection engineering or DFIR.
  • Proven experience with Splunk and SPL.
  • Hands-on CrowdStrike experience.
  • Experience investigating security incidents and analyzing telemetry.
  • Python scripting or security automation experience.
  • Experience with AWS security logs or cloud investigations.
  • Strong detection engineering concepts and monitoring.
  • Ability to independently investigate complex technical problems.

Responsibilities

  • Perform advanced incident investigations across endpoint, cloud, malware, identity and telemetry.
  • Serve as escalation resource for complex security incidents and forensics.
  • Develop and tune detections using Splunk and other security platforms.
  • Write and optimize SPL queries for detection and analytics.
  • Use CrowdStrike telemetry to investigate suspicious activity.
  • Analyze AWS security data across cloud environments.
  • Build Python scripts and API-based automation to improve workflows.
  • Onboard additional security data sources to improve visibility and response.
  • Partner with DLP teams on data movement and web activity detections.
  • Reduce noise and improve signal quality across high-volume platforms.
  • Support secure telemetry movement through cloud pipelines.
  • Evaluate AI-assisted security capabilities where appropriate.

Skills

DFIR
Detection engineering
Incident investigations
Python scripting
Cloud security

Tools

Splunk
SPL
CrowdStrike
AWS logging
APIs

Job description

We are seeking a Senior Security Engineer with strong experience across Digital Forensics and Incident Response (DFIR), detection engineering, security automation and cloud security.

This is a hands-on engineering role supporting a large-scale security operations environment. The position will work closely with incident response and data loss prevention teams to investigate complex security activity, improve security visibility, engineer detections and build capabilities that make the broader security operations team more effective.

This is a 12-month remote contract opportunity. Candidates located in Central Time are strongly preferred, with Eastern Time candidates also considered.

Responsibilities
  • Perform advanced incident investigations involving endpoint, cloud, malware, identity, application and security telemetry
  • Serve as a technical escalation resource for complex security incidents and forensic investigations
  • Develop, tune and improve security detections using Splunk and other security platforms
  • Write and optimize SPL queries for detection, investigation and security analytics
  • Use CrowdStrike and related endpoint telemetry to investigate suspicious activity
  • Analyze AWS security and logging data across cloud environments
  • Build Python scripts and API-based automation to improve investigation, enrichment and detection workflows
  • Identify and onboard additional security data sources to improve visibility and response capabilities
  • Partner with DLP teams to develop and improve detections involving web activity, data movement and potential data loss
  • Reduce noise and improve signal quality across high-volume security platforms
  • Support secure movement and processing of security telemetry through cloud and API-based pipelines
  • Evaluate and safely use AI-assisted security capabilities where appropriate
Required Qualifications
  • 4+ years of experience in cybersecurity, including hands‑on detection engineering and/or DFIR
  • Strong experience with Splunk and SPL
  • Hands‑on CrowdStrike experience
  • Experience performing security incident investigations and analyzing security telemetry
  • Python scripting or security automation experience
  • Experience working with AWS security logs, services or cloud investigations
  • Strong understanding of detection engineering concepts and security monitoring
  • Ability to independently investigate complex technical problems and develop practical solutions
Preferred Qualifications
  • Experience with Zscaler, particularly web traffic, logging or security monitoring
  • Data Loss Prevention (DLP) experience
  • Cloud forensics experience
  • Malware analysis or endpoint forensics experience
  • Experience building security pipelines using APIs, AWS Lambda or similar technologies
  • Experience with ServiceNow Security Incident Response
  • Experience in a large SaaS, software, fintech or cloud-heavy enterprise environment
  • Familiarity with AI-assisted security analysis or AI-related security investigations

The ideal candidate is not simply someone who has deployed security tools. We are looking for someone who has used those tools to investigate difficult security problems, build better detections and improve the capabilities of a security operations team.

Equal Employment Opportunity Statement

Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote DFIR & Detection Engineer — 12-Month Contract
Remote DFIR & Detection Engineer — 12-Month Contract

Gravity IT Resources • Northern (KY)

Hybrid
USD 120,000 - 150,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

On-site
USD 100,000 - 130,000
Security Engineer, Incident Response
Security Engineer, Incident Response

Eliassen Group • Burbank (CA)

Hybrid
Confidential
Medical insurance
Dental insurance
Vision insurance
+2
Detection Engineer Lead
Detection Engineer Lead

K&A Technologies LLC • Washington

Hybrid
USD 165,000 - 190,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

United States Digital Space LLC • New York (NY), Washington

On-site
USD 238,000 - 297,000
Health, dental & vision coverage
Retirement benefits
Learning & development stipend
+2
Security Engineer
Security Engineer

CipherData • Bellevue (WA)

On-site
USD 120,000 - 180,000
Senior Cybersecurity Analyst #3344
Senior Cybersecurity Analyst #3344

Genius Road, LLC • Austin (TX)

On-site
USD 150,000 - 190,000
Certified Women’s Business Enterprise
Equal Opportunity Employer