Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor

Town of Gates (NY)

Remote

USD 120,000 - 170,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

12 weeks Gender Neutral Paid Parental/
LinkedIn Learning access
Diversity & Inclusion initiatives
Free mental health support
Flexible working arrangements
Medical and life insurance

Job summary

Xplor’s Cyber Threat Intelligence & Response (CTIR) team seeks an experienced incident responder to lead security events end-to-end. You will triage, investigate, contain, and eradicate threats across our platforms, coordinating with engineering and leadership to strengthen defenses.

The role requires hands-on incident response, calm decision-making under pressure, and an ability to own alerts from first to final report. Remote work available.

Qualifications

  • 3 to 6 years in security operations or incident response.
  • Experience handling full incident life cycle and coordinating with teams.
  • Strong triage, log correlation, and communication skills.

Responsibilities

  • Own incidents as part of the CTIR team: detect, triage, investigate, contain and eradicate, driving each one until the threat is under control.
  • Work live incidents alongside the team and be ready to step up and take the lead yourself when the situation calls for it.
  • Lead investigations across our systems, digging into logs, endpoints, email and network data to work out what happened, how far it reached, and how to resolve.
  • Perform host and network forensics, malware triage, and email analysis to understand attacker activity and build a reliable timeline.
  • Coordinate with engineering, IT and the wider security team during a response, and communicate clearly to both technical teams and leadership.
  • Hunt proactively for threats across system logs, user behaviour and threat intelligence, turning what you find into new detections and indicators of compromise.
  • Build and automate incident response workflows and playbooks so routine response is fast and repeatable.
  • Strengthen our detection coverage using the MITRE ATT&CK framework, closing monitoring gaps, and tuning to reduce noise.
  • Feed what you learn from each incident back into how the team detects and responds, so an attack pattern we've seen once is caught faster next time.
  • Analyse threat intelligence, research emerging threats, and recommend practical mitigation.
  • Be ready to work incidents as they arise, including on‑call and out‑of‑hours cover when needed.

Skills

Incident response
Security operations
Log analysis
Threat hunting
MITRE ATT&CK
Python scripting
PowerShell scripting
SIEM
EDR
ISO 27001 awareness

Tools

Microsoft Sentinel
KQL
Jupyter Notebooks
SOAR

Job description

At Xplor, we believe that helping people make the most of each day is the most rewarding way to spend ours.

We give small and medium-sized businesses cloud-based, intuitive technology solutions that enable them to manage all the hassles of running and growing a business, so business owners can get back to doing what they love. With Xplor Pay, we help businesses get paid quickly and securely – without hidden fees. We built the tech ourselves, and our platform delivers secure, transparent, fast, and accurate payments.

We are unified by our purpose of helping people to succeed. So, when you become part of our team, you also become part of the personal connection that strengthens the relationship people have with Xplor products.

About the role

Our Cyber Threat Intelligence & Response (CTIR) engineers are the people we count on when something goes wrong, and the people who make sure it goes wrong far less often. This is a hands‑on incident response role. You'll lead the response to security events across our platforms and applications: triage, investigate, contain, eradicate and recover, then make sure we come out of it stronger.

We're looking for someone who genuinely loves incident response. Someone who gets calmer and sharper when an incident kicks off, who is confident making decisions when the picture isn't complete, and who doesn't wait to be told what to look at. If you're a self‑starter who takes ownership from the first alert to the final report, you'll fit right in.

Location: Remote

Reports to: VP of Cybersecurity | Cyber Threat Intelligence, Engineering & Response

What you'll do
  • Own incidents as part of the CTIR team: detect, triage, investigate, contain and eradicate, driving each one until the threat is under control.
  • Work live incidents alongside the team and be ready to step up and take the lead yourself when the situation calls for it.
  • Lead investigations across our systems, digging into logs, endpoints, email and network data to work out what happened, how far it reached, and how to resolve.
  • Perform host and network forensics, malware triage, and email analysis (including PDF and document analysis) to understand attacker activity and build a reliable timeline.
  • Coordinate with engineering, IT and the wider security team during a response, and communicate clearly to both technical teams and leadership.
  • Hunt proactively for threats across system logs, user behaviour and threat intelligence, turning what you find into new detections and indicators of compromise.
  • Build and automate incident response workflows and playbooks so routine response is fast and repeatable.
  • Strengthen our detection coverage using the MITRE ATT&CK framework, closing monitoring gaps, and tuning to reduce noise.
  • Feed what you learn from each incident back into how the team detects and responds, so an attack pattern we've seen once is caught faster next time.
  • Analyse threat intelligence, research emerging threats, and recommend practical mitigation.
  • Be ready to work incidents as they arise, including on‑call and out‑of‑hours cover when needed.
What we're looking for

People who want to make a real difference in security, and who care about incident response in particular.

  • 3 to 6 years experience in security operations or incident response, with genuine passion for running incidents, not just watching a queue.
  • Confidence managing incidents through the full incident‑handling lifecycle, and the judgement to make sound calls under pressure.
  • Strong triage and root cause analysis, with a solid understanding of different log sources and how to correlate events across them.
  • Comfortable reading logs (HTTP, SMTP, network), Windows and Active Directory, and common operating systems and servers.
  • Hands‑on experience with a SIEM to investigate, hunt and build detections. Microsoft Sentinel and KQL preferred.
  • Practical experience across EDR, advanced threat protection, identity management and API security.
  • Threat‑hunting experience across network flow, user behaviour and threat intelligence, plus the ability to design new ways to detect and contain attacks using scripting, analytics and automation.
  • Familiar with a broad range of attacker tools and techniques (TTPs), with the ability to map adversary activity across the Cyber Kill Chain to identify, assess, and communicate potential attack progression.
  • A self‑starter who works independently, delivering projects without being chased, and keeps learning as the industry develops.
  • A critical thinker with strong problem‑solving instincts and exceptional communication skills, capable of translating complex technical risks into clear, actionable insights for both the immediate team and cross‑functional partners, including engineers, administrators, and leadership, through both verbal and written communication.
  • Good understanding of ITIL processes and standards such as ISO 27001 and PCI DSS, including change, incident and problem management.
Nice to have
  • Malware analysis experience.
  • Preferred certifications such as GCIH, GCFA, AZ‑500 or SC‑100.
  • Experience with Jupyter Notebooks for threat‑hunting.
  • Python and PowerShell scripting.
  • Experience building and tuning SOAR automation for response.
Values and Life at Xplor
  • Make life simple
  • Build for people
  • Move with purpose
  • Create lasting communities.

Our four core values guide us from how we hire and recognise our team members to how they interact with customers day to day.

If these values sound like you, and describe people you want to work with, you will thrive at Xplor.

As an Xplorer, you will be part of a global network of talented colleagues who will support your success. We look for commonalities and shared passions and give people the tools they need to deliver great work and grow at speed.

Some of our perks and benefits are: *include additional benefits provided in your region*

  • 12 weeks Gender Neutral Paid Parental Leave for both primary and secondary carer
  • #GiveBackDays/Commitment to social impact – 3 extra days off to volunteer and give back to your local community
  • Unlimited access to LinkedIn Learning, plus regular career and growth conversations with your leader, as part of Xplor GPS
  • Ongoing dedication to Diversity & Inclusion initiatives such as D&I Council, Global Mentorship Program
  • Access to free mental health support
  • Flexible working arrangements
  • Medical and life insurance
More about us

More than 130,000 businesses in 72+ countries rely on Xplorto run their day and get paid, processing over $47 billion in payments annually.Ourconnected ecosystemhelps operators spend less time managing complexity and more time delivering the experiences that matter most.

Xplorisbacked by world‑class investorsAdvent International, Battery Ventures,and Silver Lake.

Good to know

To be considered for employment, you must be legally authorized to work in the country you're applying for. Xplor does not sponsor visas, either at the time of hire or at any later time.

We kindly ask you to apply through our careers portal or external job boards only. Please don't send your application via email.

To learn more about usand our products, please visit xplor.com/careers/.

We also invite you to check out our Candidate FAQs for more information about our recruitment process xplor.com/recruitment‑faqs/.

EEO and Artificial Intelligence

We believe in transparent hiring. We use an applicant tracking system that includes artificial intelligence‑enabled features to assist with the screening and assessment of job applications, such as candidate scoring or ranking. These tools support our recruitment process, but all hiring decisions are made by our recruitment team following human review. We do not rely on artificial intelligence to make final hiring decisions. Find our Candidate AI Usage guidelines here.

Xplor is proud to be an Equal Employment Opportunity employer. We're dedicated to attracting, retaining and developing our people regardless of gender identity, ethnicity, sexual orientation, disability, veteran statusand age. Applications are encouraged from all sectors of the community. All Information will be kept confidential according to EEO guidelines.

Xplor is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Xplor will take steps to ensure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact us via talent@xplortechnologies.com.

We make it a priority to respond to every applicant.

We make it a priority to respond to every applicant.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer
Senior Software Engineer

Xplor • United States

Remote
USD 140,000 - 190,000
Paid Parental Leave
GiveBackDays
Diversity & Inclusion initiatives
+2
Senior Software Engineer
Senior Software Engineer

Xplor • Georgia

Remote
USD 140,000 - 190,000
Parental Leave
Volunteer days
Diversity & Inclusion
+2
Account Executive
Account Executive

Xplor Pay • Blacksburg (VA)

On-site
USD 100,000
Uncapped commissions
Residual income on active accounts
Sales training and mentorship
+1
Senior Product Designer - Mariana Tek (Remote)
Senior Product Designer - Mariana Tek (Remote)

Xplor • United States

Remote
USD 120,000 - 165,000
Paid Parental Leave
Volunteer days (#GiveBackDays)
Diversity & Inclusion programs
+2
Account Executive
Account Executive

Xplor Pay • Temecula (CA)

On-site
USD 70,000 - 150,000
Uncapped commissions
Flexible schedule
Sales training and mentorship
+2
Account Executive
Account Executive

Xplor Technologies • Howell (MI)

On-site
USD 70,000 - 125,000
Uncapped commissions
Residual income
Flexible schedule
+1
Marketing Manager, SaaS
Marketing Manager, SaaS

Xplor • Utah

On-site
USD 95,000 - 115,000
Parental Leave
Volunteer days off
Diversity & Inclusion initiatives
+2
Remote Account Executive, Payment Solutions (Uncapped Commission)
Remote Account Executive, Payment Solutions (Uncapped Commission)

Xplor Technologies • Howell (MI)

On-site
USD 70,000 - 125,000
Account Executive
Account Executive

Xplor Education • Cerritos (CA)

On-site
USD 50,000 - 90,000
Lifetime Residuals
W2 Status
Activation bonuses paid weekly
+4
Account Executive
Account Executive

Xplor Technologies • State College

On-site
USD 60,000 - 110,000
Lifetime Residuals
Activation bonuses
Access to mental health support
+2