Senior Incident Response Security Engineer - Escalations

Intuit Inc.

Charlotte (NC)

On-site

USD 140,000 - 190,000

Full time

10 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Cash bonus
Equity rewards
Benefits

Job summary

Intuit is seeking an experienced Senior IR Security Engineer to join our Escalations team within the SOC. You will respond to modern cyber-attacks, guide incident management, and leverage AI SOC tools to accelerate triage and analysis.

You will develop IR playbooks, mentor junior responders, and collaborate with Compliance, Legal, and Risk teams to align security with business needs. A strong foundation in cloud security and forensics is required.

Qualifications

  • Bachelor's degree or higher in technology, computer science, cybersecurity, or related field.
  • Security certifications like AWS Security Specialty, GIAC, ISC2 advantageous.
  • 3-5 years in cybersecurity with emphasis on forensics and IR.
  • 1-3 years scripting/automation with AI tooling and AI SOC platforms.
  • Experience with AI/LLM security risks and MITRE/NIST frameworks.
  • Experience securing AWS/Azure/GCP and CSPM/EDR technologies.

Responsibilities

  • Oversee and promptly respond to escalated security events and activate IR plan.
  • Provide on-call support and report incident status to stakeholders.
  • Lead investigations to determine root cause, scope, and impact.
  • Leverage AI platforms to accelerate triage and documentation.
  • Develop and improve IR playbooks ensuring compliance with regs.
  • Present guidance on security best practices to partners.
  • Mentor junior responders and coach incident handling.
  • Collaborate with Compliance, Legal, and Risk teams.
  • Assess vulnerabilities and propose remediation strategies.

Skills

Incident response
AI/LLM security
Cloud security
Forensics
Security lifecycle
Communication

Education

Bachelor's degree in technology, CS, cybersecurity

Tools

CrowdStrike Falcon
Wiz
Splunk
LogScale

Job description

We are seeking an experienced Senior IR Security Engineer to join our Escalations team within the broader Security Operations Center (SOC), to help our organization respond to modern cyber-attacks. The ideal candidate will have a deep understanding of the security incident response and incident management process, attacker kill chains and methodologies, and the ability to respond quickly to attacks, restore services, and investigate root cause. Just as importantly, they'll be fluent in the AI-enabled SOC of today; leveraging frontier AI platforms and AI SOC tools to move faster, while understanding the new risks that AI and agentic systems introduce to the environments we defend. As a member of our SOC, you will closely collaborate with security engineers to design and implement solutions, improve incident response readiness, and provide guidance and training to partner teams.


Responsibilities

  • Oversee and promptly respond to escalated security events or investigations, and activate the security incident response plan as required.
  • Provide on-call support for critical severity issues, manage communications, and report incident status to the appropriate stakeholders.

  • Lead analysis and conduct investigations to ascertain the root cause, scope, and impact of security incidents.

  • Leverage frontier AI platforms and AI SOC tools to accelerate triage, investigation, and documentation, and help evaluate new AI capabilities as they're onboarded.

  • Investigate and respond to security incidents involving AI/LLM-based tools and agentic platforms (e.g., prompt injection, data leakage, unauthorized model access), extending IR playbooks to cover generative AI and AI SOC platform risks.

  • Develop, maintain, and improve incident response plans, procedures, and playbooks to ensure swift action and regulatory compliance.

  • Present guidance and training on security best practices and incident response to organizational partners, while ensuring alignment with business objectives and compliance requirements.

  • Mentor and train junior incident responders on incident handling techniques, forensic analysis, and cloud security forensics and best practices.

  • Collaborate with Compliance, Legal, and Risk teams to integrate incident response operations with business and regulatory needs.

  • Assess vulnerabilities, propose remediation strategies, and stay up-to-date on current and emerging security trends, threats, and countermeasures.


Qualifications

  • A Bachelor's degree or higher in technology, computer science, cybersecurity, or a related field is preferred.

  • Possession of industry-recognized professional certifications, such as AWS Security Specialty, GIAC, ISC2, or emerging AI security credentials, is advantageous.

  • 3-5 years of experience in a dedicated cybersecurity role, with a strong emphasis on digital forensics and incident response.

  • 1-3 years writing scripts or code to automate security work, comfortable using AI coding assistants and AI SOC platforms to build faster, and aware of the risks that come with AI-generated code.

  • Working knowledge of AI/LLM security risks and mitigations (data exfiltration, insecure output handling, model/data supply chain risk, shadow AI usage), familiarity with frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.

  • Experience performing analysis and detection engineering using endpoint detection and response (EDR) or cloud security posture management (CSPM) tools such as CrowdStrike Falcon and Wiz.

  • Comprehensive understanding of cybersecurity, networking/cloud fundamentals, and frameworks such as OWASP, MITRE ATT&CK, NIST, and CIS.

  • Experience securing and managing public cloud services (AWS, Azure, GCP), with a focus on areas such as IAM, CI/CD pipelines, network security, and DLP.

  • Deep understanding of Security Information and Event Management (SIEM) solutions such as Splunk or LogScale.

  • Hands-on experience triaging incidents with digital forensics tools, with expertise in the security incident response lifecycle according to frameworks like NIST or SANS.

  • Exceptional communication skills, both verbal and written, capable of explaining technical details to non-technical audiences and fostering strong stakeholder relationships.

  • Strong analytical and problem-solving abilities, with a focus on identifying root causes and assessing risk exposure.

  • Self-motivated with the ability to work autonomously, managing tasks effectively and seeking assistance when necessary.

  • Proficient in working under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.

  • Adaptable and proactive attitude, willing to take on various responsibilities and eager to continuously learn and upgrade skills.


Intuit provides a competitive compensation package with a strong pay for performance rewards approach. This position may be eligible for a cash bonus, equity rewards and benefits, in accordance with our applicable plans and programs (see more about our compensation and benefits at Intuit: Careers | Benefits). Pay offered is based on factors such as job-related knowledge, skills, experience, and work location. To drive ongoing fair pay for employees, Intuit conducts regular comparisons across categories of ethnicity and gender.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Security Engineer - Escalations
Senior Incident Response Security Engineer - Escalations

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit Inc. • Frisco (TX)

On-site
USD 140,000 - 180,000
Bonus potential
Equity rewards
Benefits package
Senior AI-Driven Incident Response Engineer
Senior AI-Driven Incident Response Engineer

Intuit Inc. • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior Incident Response Engineer: AI-Driven SOC Leader
Senior Incident Response Engineer: AI-Driven SOC Leader

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Security Engineer, Incident Response
Senior Security Engineer, Incident Response

Snowflake • Menlo Park (CA)

On-site
USD 176,000 - 253,000
Medical, dental, vision benefits
401(k) retirement plan
Paid time off & holidays
Senior Security Engineer, Incident Response
Senior Security Engineer, Incident Response

Snowflake • United States

On-site
USD 176,000 - 253,000
Senior Security Engineer, Incident Response
Senior Security Engineer, Incident Response

Snowflake • Menlo Park (CA)

On-site
USD 176,000 - 253,000
Medical, dental, vision insurance
401(k) retirement plan
Paid holidays