Remote Security Operations & Incident Response Engineer

Pearl Consulting Group

United States

Hybrid

USD 120,000 - 170,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Pearl Consulting Group is seeking an Engineer - Security Operations and Incident Response to lead the ongoing transformation of our Security Operations program across the global enterprise, focusing on detection, response, and resilience.

You will perform deep dive investigations, develop IR playbooks, model threats, tune SIEM rules, and drive automation, working with cross‑functional teams to deliver business value. Remote or hybrid work in USA or Canada is supported.

Qualifications

  • Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
  • In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
  • Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
  • Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
  • Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
  • Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
  • Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.

Responsibilities

  • Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
  • Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
  • Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
  • Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
  • Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
  • Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
  • Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
  • Review and tune threat intelligence systems, including brand protection and dark web monitoring.
  • Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
  • Support IR leadership as backup on IR-related activities.

Skills

Incident response
SOC tooling
Threat modeling
Scripting (Python/PowerShell/Bash/XQL)
SOAR automation
Digital forensics
Communication skills

Education

Bachelor's degree

Tools

Microsoft Sentinel
Palo Alto Cortex XSIAM
Cortex XSOAR

Job description

Pearl Consulting Group is seeking an Engineer - Security Operations and Incident Response to lead the ongoing transformation of our Security Operations program across the global enterprise, focusing on detection, response, and resilience.

You will perform deep dive investigations, develop IR playbooks, model threats, tune SIEM rules, and drive automation, working with cross‑functional teams to deliver business value. Remote or hybrid work in USA or Canada is supported.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations & Incident Response Engineer - Remote
Security Operations & Incident Response Engineer - Remote

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Pearl Consulting Group. • Northern (KY)

Hybrid
USD 110,000 - 170,000
Remote Senior Security Incident Response Engineer
Remote Senior Security Incident Response Engineer

United States Digital Space LLC • United States

Remote
USD 135,000 - 228,000
Senior Incident Response Engineer - Remote/Hybrid
Senior Incident Response Engineer - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 129,000 - 212,000
Annual bonus
Stock plans
Benefits
Remote Threat Detection & Response Engineer — IR & SOC
Remote Threat Detection & Response Engineer — IR & SOC

Whatnot • United States

Remote
USD 120,000 - 170,000
Health Insurance
401(k) with employer match
Work From Home Support
+2
Remote Senior Incident Response Lead
Remote Senior Incident Response Lead

Pondurance • United States

Remote
USD 110,000 - 136,000
Remote Security Incident Response Engineer
Remote Security Incident Response Engineer

Chainlink • United States

Remote
USD 160,000 - 260,000
Senior IR Engineer - Automation & Remote
Senior IR Engineer - Automation & Remote

United States Digital Space LLC • United States

Remote
USD 153,000 - 214,000
Health insurance
Dental insurance
401k
+2
Remote Security Operations Analyst - Threat Detection & Response
Remote Security Operations Analyst - Threat Detection & Response

Remote Genie • Northern (KY)

Hybrid
USD 70,000 - 90,000
Remote-first culture
Unlimited PTO
Medical, dental, vision covered
+2