Senior Cyber Incident Response Engineer

Acrisure

Atlanta (GA)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Acrisure is seeking a Security Incident Response Engineer to detect, investigate, contain, eradicate, and recover from cybersecurity incidents across our global environment. You will collaborate with Security Operations, Infrastructure, Cloud, IAM, and Legal to rapidly respond and reduce risk.

You will perform incident triage, containment, forensic analysis, threat hunting, and develop runbooks and automation to shorten response times while strengthening detection fidelity.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience).
  • Minimum 3 years of progressive information security experience.
  • Strong understanding of incident response methodologies, attack lifecycle, and containment strategies.
  • Experience with one or more EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or equivalent.
  • Experience with SIEM technologies such as Microsoft Sentinel, Google SecOps, Splunk, QRadar, or similar platforms.
  • Knowledge of Microsoft 365, Entra ID, Active Directory, and cloud security concepts.
  • Understanding of MITRE ATT&CK, threat intelligence, and threat hunting methodologies.
  • Familiarity with Windows, Linux, and macOS operating systems.
  • Ability to analyze logs, indicators of compromise (IOCs), and attacker techniques.
  • Experience with PowerShell, Python, KQL, or other scripting/query languages.

Responsibilities

  • Investigate and respond to cybersecurity incidents involving endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
  • Perform incident triage, severity classification, impact analysis, containment, eradication, and recovery activities.
  • Execute cyber incident response procedures and escalation processes in accordance with the Cyber Incident Response Plan (CIRP).
  • Coordinate response efforts across Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
  • Support major incident management activities and provide technical leadership during active security events.
  • Maintain detailed incident records, timelines, evidence, findings, and lessons learned.
  • Analyze alerts from EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence platforms.
  • Validate suspicious activity to distinguish true incidents from false positives.
  • Perform root cause analysis to identify attack vectors and attacker activities.
  • Conduct proactive threat hunting to identify indicators of compromise and emerging threats.
  • Leverage MITRE ATT&CK techniques to improve detection and investigative effectiveness.

Skills

Incident response
Threat hunting
Digital forensics
Root-cause analysis
Cross-functional collaboration

Education

Bachelor's degree in CS/IS/Cybersecurity or related

Tools

Microsoft Defender for Endpoint
SentinelOne
CrowdStrike
Microsoft Sentinel
Splunk
QRadar
KQL
PowerShell
Python

Job description

Acrisure is seeking a Security Incident Response Engineer to detect, investigate, contain, eradicate, and recover from cybersecurity incidents across our global environment. You will collaborate with Security Operations, Infrastructure, Cloud, IAM, and Legal to rapidly respond and reduce risk.

You will perform incident triage, containment, forensic analysis, threat hunting, and develop runbooks and automation to shorten response times while strengthening detection fidelity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Engineer — Cyber Threat Defender
Incident Response Engineer — Cyber Threat Defender

Royal Abstract of New York LLC • Atlanta (GA)

On-site
USD 90,000 - 130,000
Dynamic Security Incident Responder
Dynamic Security Incident Responder

Acrisure, LLC • Atlanta (GA)

On-site
USD 110,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+4
Security Incident Response Engineer
Security Incident Response Engineer

Royal Abstract of New York LLC • Atlanta (GA)

On-site
USD 90,000 - 130,000
Director of Security Operations & Incident Response
Director of Security Operations & Incident Response

Acrisure • Atlanta (GA)

On-site
USD 180,000 - 250,000
Health insurance
Dental insurance
Vision insurance
+1
Senior Cyber Defense & Incident Response Lead
Senior Cyber Defense & Incident Response Lead

AIG • Town of Charlotte (NY)

On-site
USD 180,000 - 240,000
Total Rewards Program
Security Incident Response Engineer
Security Incident Response Engineer

Acrisure • Atlanta (GA)

On-site
USD 120,000 - 180,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Senior Cyber Incident Response Engineer - Threat & Remediation
Senior Cyber Incident Response Engineer - Threat & Remediation

Elsevier • Philadelphia

On-site
USD 110,000 - 190,000
Senior AI-Driven Incident Response Engineer
Senior AI-Driven Incident Response Engineer

Intuit Inc. • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
SOC Threat Hunter & Incident Response Engineer
SOC Threat Hunter & Incident Response Engineer

Cyberdata Technologies, Inc. • Herndon (VA)

On-site
USD 80,000 - 120,000