Security & Cyber Incident Response Engineer

Socket.dev

Louisville (KY)

On-site

USD 131,000 - 164,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Yum! Brands is seeking an Information Security & Cyber Incident Response Engineer to influence global cybersecurity strategy and advance the incident response program.

You will protect enterprise systems and lead investigations across endpoints, servers, networks, and cloud environments, coordinating with multiple teams to manage risk and respond to incidents. The role requires extended hours, after-hours on-call participation, and the ability to investigate incidents within 30 minutes of

Qualifications

  • Bachelor’s degree in computer science, information security or related field.
  • Certifications such as CompTIA Security+, CompTIA CySA+, GIAC Certified Incident Handler (GCIH).
  • 5+ years of cybersecurity experience including hands-on incident response or security operations.
  • Knowledge of incident response processes (detection, triage, remediation, reporting).
  • Knowledge of Linux, Mac, and Windows administration.
  • Knowledge of cloud environments, specifically Azure and AWS.
  • Ability to communicate complex findings to technical and non-technical audiences.

Responsibilities

  • Lead technical investigations across endpoints, servers, networks, and cloud environments to identify assets and IOC.
  • Coordinate containment, eradication, and remediation actions.
  • Maintain incident timelines and documentation throughout the lifecycle.
  • Partner with security and infrastructure teams to coordinate response actions.
  • Serve as Incident Response Lead for complex, high-severity incidents.

Skills

Incident response
Security operations
Communication

Education

Bachelor's degree in computer science or information security

Tools

ServiceNow
Azure
AWS

Job description

Yum! Brands has a new opportunity for an Information Security & Cyber Incident Response Engineer. This role gives a successful candidate the opportunity to influence Yum’s business at a global level by working to drive the Global Cybersecurity strategy by further progressing the incident response program. The position partners with various Information Technology teams, business functions, and other key stakeholders to gain commitment and alignment to identify and manage risk. In this role, you will have the opportunity to learn our business from the ground up while working on cutting edge technologies. The ideal candidate will be protecting enterprise systems and information by responding to security threats and incidents, working autonomously or as part of a geographically diverse team to detect, examine and resolve cybersecurity incidents globally.

For this role, the ideal candidate will need to have the ability to work extended hours including nights, weekends, and holidays with little notice to facilitate incident response. This role also requires participation in after-hours on-call rotation, including the ability to investigate reported incidents within 30 minutes of notice.

Responsibilities

Responsibilities

  • Lead technical investigation activities across endpoints, servers, networks, cloud environments, identities, applications, and other enterprise platforms to identify affected assets, accounts, data, indicators of compromise, attack vectors, and root cause.
  • Coordinate and execute technical containment, eradication, and remediation activities, including endpoint isolation, account disablement, access revocation, IOC blocking, credential resets, malware removal, vulnerability remediation, system reconfiguration, and other corrective actions as appropriate.
  • Maintain a comprehensive incident timeline and document investigative findings, technical decisions, response actions, approvals, communications, and evidence references throughout the incident lifecycle.
  • Partner with Security Operations, Cyber Threat Intelligence, Digital Forensics, Security Engineering, Vulnerability Management, Threat Hunting, Architecture, infrastructure teams, and other technical stakeholders to coordinate investigation and response activities.
  • Serve as Incident Response Lead for complex and high-severity cybersecurity incidents, independently coordinating technical workstreams, establishing investigative priorities, driving technical decisions, managing dependencies, and escalating material risks and decisions to cybersecurity leadership.
  • Apply threat intelligence and adversary behavior analysis during active investigations to reconstruct attack paths, identify attacker objectives, assess potential additional compromise, and inform containment and remediation strategies.
  • Lead and participate in incident response exercises, tabletop simulations, and post-incident reviews; identify capability gaps and own or drive continuous improvements to incident response playbooks, procedures, investigation methodologies, automation, tooling, monitoring, and technical controls.
  • Independently develop and coordinate technical response strategies for complex incidents, including situations where established playbooks, procedures, or precedent may not fully address the circumstances, exercising judgment based on incident type, severity, business impact, operational risk, evidence-preservation requirements, and business continuity considerations.
  • Validate the effectiveness of containment and remediation actions, confirm that residual indicators of compromise or attacker persistence have been removed, and ensure corrective actions address identified root causes and reduce the likelihood of recurrence.
  • Coordinate secure recovery of affected systems and services with infrastructure, application, cloud, and business teams, including validation of rebuilt systems, restored data, security configurations, and enhanced controls before returning systems to normal operation.
  • Coordinate technical response activities with third-party vendors, service providers, cloud providers, and external incident response partners in accordance with established incident response procedures and contractual requirements.
  • Maintain accurate, timely, and auditable Security Incident Records (SIRs) within ServiceNow, including incident scope, severity, investigation findings, actions taken, decisions, status updates, evidence references, and closure documentation.
  • Communicate technical findings, risks, incident impact, response options, dependencies, and implications of technical decisions to cybersecurity leadership, business stakeholders, executive leadership, and other technical and non-technical audiences as appropriate.
  • Identify systemic security control, monitoring, architecture, and operational gaps discovered through investigations and influence partner teams to implement corrective actions that reduce enterprise cybersecurity risk and the likelihood of recurrence.
  • Serve as a technical resource and mentor for less-experienced security engineers and analysts, providing guidance on investigation methodology, technical analysis, incident response decisions, and complex escalations.
Qualifications

Minimum Requirements

  • Bachelor’s degree in computer science, information security or related field
  • Industry certifications such as CompTIA Security+, CompTIA CySA+, GIAC Certified Incident Handler (GCIH)
  • 5+ years of cybersecurity experience, including significant hands‑on experience in security incident response, security operations, or equivalent relevant experience
  • Knowledge of incident response processes (detection, triage, incident research, remediation, and reporting)
  • Knowledge of administration and use of Linux, Mac, and Windows systems
  • Knowledge of complex cloud environments, specifically providers such as Azure and Amazon AWS
  • Ability to communicate complex technical findings, risks, and recommendations effectively to technical and non-technical audiences
  • Proficient in written and spoken English

Preferred Requirements

  • Experience with leading Incident Response in a global organization with Cloud and Software as a Service exposure
  • Experience with large scale and complex incidents of all types to include Advanced Threats, DDoS, insider, web and mobile applications, data ex‑filtration etc.
  • Knowledge of Cybersecurity practices, operations, risk management processes, methods, architectural requirements, engineering and threats and vulnerabilities, including incident response methodologies
  • Thorough knowledge of networking and security architecture
  • Experience with ServiceNow Ticket Management and managing the SIR module

Key Performance Indicators (KPIs)

Short-Term Outcomes (3-6 months)

  • Demonstrate consistent compliance with critical-incident engagement and on‑call response requirements, including investigation initiation within required response timeframes.
  • Maintain at least 95% timely and complete Security Incident Record documentation for assigned incidents, including scope, decisions, evidence references, response actions, and closure details.

Long-Term Outcomes (6-12+ months)

  • Drive corrective actions from significant incidents and post‑incident reviews to completion within agreed timelines, with measurable reduction in repeat issues attributable to previously identified root causes.
  • Deliver measurable improvements to incident response capability through enhanced playbooks, automation, tooling, monitoring, or investigation methodologies.
  • Demonstrate sustained technical leadership on complex and high‑severity incidents, including effective coordination, decision‑making, escalation, and recovery.

Functional Areas

  • Technical Delivery: Produce accurate, defensible investigations and validate containment, eradication, remediation, and secure recovery before incident closure.
  • Operational Efficiency: Improve response consistency and reduce avoidable investigation or remediation delays through reusable processes, automation, and technical standards.
  • Technical Leadership & Influence: Mentor less‑experienced team members, provide guidance on complex escalations, and influence partner teams to address systemic security gaps.
  • Stakeholder Impact: Communicate incident risk, impact, response options, dependencies, and technical decisions clearly to cybersecurity leadership, business stakeholders, and executive audiences.

Salary Range: $131,100 to $164,300 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security and Cyber Incident Response Engineer
Security and Cyber Incident Response Engineer

Yum! Brands • United States

On-site
USD 131,000 - 164,000
Security & Cyber Incident Response Engineer
Security & Cyber Incident Response Engineer

KFC Corporation • United States

On-site
USD 110,000 - 150,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MFI Technologies Incorporated • New York (NY)

On-site
USD 75,000 - 100,000
Senior Incident Response Engineer
Senior Incident Response Engineer

Elsevier • New Jersey

Hybrid
USD 89,000 - 143,000
Annual incentive bonus
Consulting/Principal Security Engineer
Consulting/Principal Security Engineer

RELX • Raleigh (NC)

On-site
USD 104,900 - 174,700
Staff Security Incident Commander
Staff Security Incident Commander

Servicenow • Santa Clara (CA)

On-site
USD 146,000 - 256,000
Health plans
401(k) plan with company match
Flexible spending accounts
+4
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Global Cyber Incident Response Lead
Global Cyber Incident Response Lead

Socket.dev • Louisville (KY)

On-site
USD 131,000 - 164,000