Mid- Senior Cyber Security Incident Responder

Guaranteed Rate, Inc.

Chicago (IL)

Remote

USD 130,000 - 150,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Guaranteed Rate, Inc. is seeking a Senior Cyber Security Incident Responder to lead and mature our incident response program. You will manage detection, containment, and recovery while coordinating with IT, Legal, and executives.

The role requires 5+ years in cybersecurity with at least 2 years in SOC/IR, and hands-on experience with SIEM/EDR tools. Remote options exist, with Chicago as a core hub for collaboration.

Qualifications

  • 5+ years of hands-on cybersecurity experience with 2+ years in Tier 2/3 security operations or incident response.
  • Knowledge of threat vectors, malware behavior, APTs and attacker TTPs.
  • Experience with incident response plans, tabletop exercises, and post-incident reviews.
  • Familiarity with NIST SANS, MITRE ATT&CK, and regulatory requirements.
  • Strong scripting/automation experience is a plus.

Responsibilities

  • Mature the incident response program across preparation, detection, containment, eradication and recovery.
  • Investigate security events to determine impact, root cause and remediation steps.
  • Maintain runbooks and playbooks aligned with evolving threats.
  • Coordinate with IT, Legal, Compliance and leadership during major incidents.
  • Optimize SIEM/EDR and threat intel tooling to reduce detection and response time.
  • Escalate high-severity incidents and report findings clearly to leadership.
  • Develop metrics to measure MTTD/MTTR and overall program effectiveness.
  • Collaborate on training and tabletop exercises to improve readiness.

Skills

Incident response
Threat hunting
Detection engineering
Threat intelligence
Fraud investigations
Python scripting

Education

Bachelor's degree in cybersecurity/IT

Tools

Splunk
Sentinel
CrowdStrike
Carbon Black
Forensics tools

Job description

Job Profile: Senior Cyber Security Incident Responder

Job Description Summary: We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent. The expected base salary range for this position is $130,000 to $150,000

Why Rate is the BEST Place to Work

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.

What Makes Our Team Awesome

We are a gritty group of passionate technologists on a mission to dominate the mortgage world! The Information Technology Team within Rate passionately and consistently puts our customers first. We are building the latest technology to help create the best mortgage experience on the planet and get your mortgage, your way, anytime, anywhere. Whether that is improving our digital mortgage platform, automating loan coordination and underwriting processes, or building out the latest marketing and customer engagement platform, we’re doing it all. We build high-performing, self-organized, cross-functional agile teams that operate with minimal hierarchy. Information Technology team members hold themselves and others accountable and live and breathe the tenets of autonomy, mastery, and purpose.

What’s the Role?

Every week, somewhere in our environment, something tries to break. A credential gets phished. A mule account starts moving money it shouldn't. An adversary finds a gap between two systems that were never designed to talk to each other. Most people at Rate never see it happen, because a tight, sharp, and relentless team already did. That team is the Risk Operations Center (ROC), and Rate is looking for a mid-to-senior level response engineer who wants to be the one that gets the page, reads the signal that no one else caught, and calls the shots when the room goes quiet and everyone looks at you. This opportunity is not simply a one-lane job. You will rotate and flex across five unique, yet overlapping terrains, often in the same week. You'll work from a real IR plan mapped to NIST CSF 2.0, a growing playbook library, and a team that has already done the hard work of building the scaffolding — you're here to run on it, sharpen it, and push it further.

The five domains are:
  • Incident Response — Take incident command on active events. Establish ground truth fast, drive containment and eradication, and own the post-incident review that makes the next one shorter.
  • Threat Hunting — Don't wait for the alert. Go looking for what the tooling missed — hypothesis-driven hunts across endpoint, identity, and network telemetry.
  • Detection Engineering — Turn every incident and hunt into a new detection. Write, tune, and retire rules; you're building the team's muscle memory into code.
  • Threat Intelligence — Track the actors and techniques relevant to financial services. Translate raw intel into detections, playbooks, and briefings people actually use.
  • Fraud Investigations — Cross into fraud ops when account takeover, mule activity, or payment fraud overlaps with a security incident — which, in this environment, is often.
Responsibilities
  • Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned.
  • Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps.
  • Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes.
  • Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents.
  • Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time.
  • Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively.
  • Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness.
  • Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization.
  • Collaborate with engineering teams to continuously strengthen detection and response capabilities.
Qualifications
  • 5+ years of hands‑on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role.
  • Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures).
  • Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms.
  • Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies.
  • Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews.
  • Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS.
  • Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus.
  • Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership.
  • Bachelor’s degree in cybersecurity, information technology, or equivalent experience.
Preferred Certifications
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)
Other Useful Details

Employee Type: Full-Time

Pay Range: annual pay + bonus and/or commissions

Location: Remote

Rate Companies is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other any other protected characteristic.

#LI-Remote

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State: https://www.rate.com/careers/open-positions/disclosures

Additional Job Description Summary

Rate is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other reason protected by law.

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State: Benefit Offerings for Washington State

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

HRIS Analyst
HRIS Analyst

Guaranteed Rate, Inc. • Chicago (IL)

Remote
USD 90,000 - 110,000
Support Manager (IT Operations Partner Management)
Support Manager (IT Operations Partner Management)

Guaranteed Rate, Inc. • United States

Remote
USD 130,000 - 140,000
Business Analyst (HRIS)
Business Analyst (HRIS)

Guaranteed Rate, Inc. • Chicago (IL)

Remote
USD 110,000 - 125,000
401(k) matching
Medical benefits
Paid time off
+1
Director of HRIS
Director of HRIS

Guaranteed Rate, Inc. • Chicago (IL)

Remote
USD 155,000 - 175,000
401(k) participation
Vacation benefits
Medical, dental, vision
+4
Senior Software Engineer
Senior Software Engineer

Rate • Chicago (IL), Northern (KY)

Hybrid
USD 130,000 - 170,000
401(k) Matching
Medical, dental, vision
Remote-first
+2
Sales Assistant
Sales Assistant

Guaranteed Rate, Inc. • San Francisco (CA)

On-site
USD 50,000 - 80,000
401(k)
Vacation benefits
Medical/Dental/Vision coverage
+3
Director of Mortgage Lead Acquisition & Affiliate Partnerships
Director of Mortgage Lead Acquisition & Affiliate Partnerships

Guaranteed Rate, Inc. • Chicago (IL)

On-site
USD 130,000 - 190,000
401(k) matching programs
Vacation benefits
Medical, dental, vision benefits
+2
Director, AI-Enabled Software Delivery
Director, AI-Enabled Software Delivery

Rate • Chicago (IL), Northern (KY)

On-site
USD 200,000 - 250,000
401(k) plan
Paid vacation
Medical, dental, vision coverage
+4
Director, AI-Enabled Software Delivery
Director, AI-Enabled Software Delivery

Guaranteed Rate, Inc. • Chicago (IL)

On-site
USD 200,000 - 250,000
Company 401(k)
Vacation benefits
Medical, dental, vision benefits
+4
Art Director
Art Director

Guaranteed Rate, Inc. • United States

Remote
USD 90,000 - 100,000
401(k) eligibility
Vacation benefits
Medical, dental, vision benefits
+5