Principal Incident Response Security Engineer

Empower Retirement, LLC

Overland Park (KS)

On-site

USD 138,000 - 200,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan with company matching
Tuition reimbursement
Paid time off
Volunteer time off

Job summary

Empower Retirement, LLC is seeking a senior cybersecurity incident response lead to own enterprise incident handling from detection to root cause analysis. You will guide on-call rotations and serve as top escalation for high-severity incidents, while mentoring analysts and communicating with executives.

The role emphasizes developing playbooks, integrating AI/ML into monitoring, and aligning MITRE ATT&CK with detection efforts. A strong security leadership presence is required.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.

Responsibilities

  • Lead major cybersecurity incidents from detection through containment, eradication, and recovery.

Job description

What you will do:
  • Lead major cybersecurity incidents from detection through containment, eradication, recovery, and post-incident review; including participating in on-call rotation.
  • Serve as the top escalation point for complex, high-severity incidents, ensuring rapid and effective resolution.
  • Develop, maintain, and optimize incident response playbooks, runbooks, and escalation procedures.
  • Oversee enterprise-wide monitoring of networks, cloud, and endpoints for threats, vulnerabilities, and anomalous activity.
  • Advance detection capabilities using EDR, SIEM, and behavioral analytics aligned with MITRE ATT&CK.
  • Act as subject matter expert on EDR and SIEM.
  • Design and implement automation frameworks (Python, PowerShell, AWS Lambda) to streamline response workflows and reduce manual effort.
  • Integrate AI/ML models into security monitoring and response processes for enhanced detection accuracy and prioritization.
  • Conduct forensic investigations and threat hunting to identify root causes and emerging threat patterns.
  • Collaborate cross-functionally with infrastructure, application, and network teams to enforce secure configurations and compliance.
  • Mentor and guide incident response analysts, fostering technical growth and operational excellence.
  • Communicate effectively with executives and technical teams during and after incidents, producing clear reports and recommendations.
  • Drive continuous improvement in detection, response, and prevention strategies to strengthen enterprise security posture.
What you will bring:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
  • Must have CISSP Certification (Current and active)
  • 6+ years of experience in the realms of enterprise cybersecurity at scale
  • 5+ years of experience with EDR, SIEM, email and network security
  • 3+ years of experience with cloud environment security, scripting/coding
  • Extensive knowledge of the incident response process and lifecycle, ability to contribute to policy and procedure.
  • Ability to respond to security alerts/incidents and drive the process start to finish
  • Ability to use generative AI in day-to-day operations as a force multiplier
  • Strong technical written and verbal communication skills, ability to document and present details on incidents
  • Strong analytic skills, able to analyze security incidents for root cause, resolution, lessons learned, and improvements
  • Excellent communication and leadership skills, with the ability to influence across technical and executive teams
What will set you apart:
  • Additional certifications (SANS, GIAC, CCSP, AWS, CEH, OSCP, etc)
  • Experience in a DevSecOps environment (Infrastructure as code, Terraform, Git)
  • Experience developing automation frameworks leveraging scripting languages (Python, PowerShell, Bash) and serverless technologies (e.g., AWS Lambda) to accelerate response workflows and reduce manual effort.
  • Experience automating repetitive tasks such as enrichment, correlation, containment.
  • Ability to integrate AI and machine learning models into security monitoring and response workflows to improve detection accuracy, reduce false positives, and prioritize threats.
  • Ability to create AI-driven anomaly detection, behavioral analysis, and natural language processing for log analysis, phishing detection, and threat intelligence enrichment.
  • Strong Linux, Windows, Network, Database skills
  • Experience with technical leadership
  • Experience as a security specialist in a regulated IT environment including some combination of SOX, HIPAA, GLBA, PCI
What we offer you

Medical, dental, vision and life insurance Retirement savings – 401(k) plan with generous company matching contributions (up to 6%), financial advisory services, potential company discretionary contribution, and a broad investment lineup Tuition reimbursement up to $5,250/year Business-casual environment that includes the option to wear jeans Generous paid time off upon hire – including a paid time off program plus ten paid company holidays and three floating holidays each calendar year Paid volunteer time — 16 hours per calendar year Leave of absence programs – including paid parental leave, paid short- and long-term disability, and Family and Medical Leave (FMLA) Business Resource Groups (BRGs) – BRGs facilitate inclusion and collaboration across our business internally and throughout the communities where we live, work and play. BRGs are open to all.

Base Salary Range $138,000.00 - $200,100.00

Equal opportunity employer Drug-free workplace

We are an equal opportunity employer with a commitment to diversity. All individuals, regardless of personal characteristics, are encouraged to apply. All qualified applicants will receive consideration for employment without regard to age (40 and over), race, color, national origin, ancestry, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, religion, physical or mental disability, military or veteran status, genetic information, or any other status protected by applicable state or local law.

For remote and hybrid positions you will be required to provide reliable high-speed internet with a wired connection as well as a place in your home to work with limited disruption. You must have reliable connectivity from an internet service provider that is fiber, cable or DSL internet. Other necessary computer equipment, will be provided. You may be required to work in the office if you do not have an adequate home work environment and the required internet connection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Staff Security Engineer I, Security Operations
Staff Security Engineer I, Security Operations

Etsy, Inc. • New York (NY)

On-site
USD 204,000 - 240,000
Equity package
Annual performance bonus
Competitive benefits supporting employees and families
Incident Response Lead
Incident Response Lead

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 170,000
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

ConsultNet Technology Services and Solutions • Chicago (IL)

On-site
USD 130,000 - 160,000
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Incident Response Principal Consultant
Incident Response Principal Consultant

Jobgether • United States

On-site
USD 115,000 - 160,000
Base salary
Bonuses
Health insurance
+1
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Incident Response Team Lead
Incident Response Team Lead

Agile Defense, LLC • Reston (VA)

Hybrid
USD 155,000 - 180,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2