Senior Information Security Engineer - Incident Response

LinkedIn

United States

Hybrid

USD 129,000 - 212,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Annual bonus
Stock plans
Benefits

Job summary

LinkedIn is seeking a Senior Incident Response Engineer to join our Information Security organization. You will independently triage alerts, investigate incidents, and lead large-scale incidents across teams to containment and remediation, mentored by senior staff.

The role supports hybrid or remote work anywhere in the United States and may involve on-call duties. The team emphasizes continuous improvement, playbook development, and proactive data sharing with stakeholders.

Qualifications

  • BA/BS degree in Information Security, CyberSecurity, Computer Science, or related discipline, or equivalent practical experience.
  • 4+ years in Information Security with 3+ years in Incident Response.
  • Experience triaging security alerts and managing incident lifecycle.
  • Experience with SIEM, logs, and EDR across Windows, Unix, and macOS.

Responsibilities

  • Triage security alerts and incident reports independently.
  • Investigate incidents using forensic and threat hunting techniques.
  • Drive small to medium incidents with cross-team collaboration to closure.
  • Conduct host, network, and log analysis to support investigations.
  • Enhance in-house IR platforms and build new capabilities.
  • Participate in on-call activities.
  • Collaborate with PR, HR, Legal, Compliance, Investigations, Eng., and other teams.
  • Lead large-scale incidents and mentor junior staff.
  • Improve processes, procedures, and detection quality.
  • Provide proactive data to stakeholders for internal comms.

Skills

Information Security
Incident Response
Threat Hunting
SOAR/Security Orchestration

Education

BA/BS in Information Security or related field
Master’s degree (preferred)

Tools

SIEM
EDR
Log Analysis
Windows Logs
Unix Logs
Web Server Logs

Job description

Senior Information Security Engineer - Incident Response
  • Full-time
  • Workplace Type: Hybrid or Remote

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. This role may be remote or hybrid. At LinkedIn, hybrid roles are performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team. Remote roles are performed from the designated home work location upon time of hire, and any changes to this home work location requires a review of remote status and approval.

This role can be remote anywhere in the United States or be hybrid in LinkedIn's Mountain View office location.

About the Team

LinkedIn's members entrust us with their information every day and we take their security seriously. Our core value of putting our members first powers all the decisions we make, including how we manage and protect the data of our members and customers. We never stop working to ensure LinkedIn is secure. We follow industry standards and have developed our own best practices to stay ahead of the increasing number of threats facing all Internet services and infrastructure. LinkedIn is looking for a Senior Incident Response Engineer to be an integral part of our Information Security organization. The Incident Response team is responsible for protecting our infrastructure, applications, and, most importantly, our members. This role will be responsible for playing a key role in our security monitoring and incident response team.

The role is a Senior position, coming in with years of real world experience in responding and leading incident investigations, developing playbooks, and continually striving to improve processes and response times. Additionally as a Senior, a successful candidate will help lead the continued improvements, mentor more junior team members, while acting as a lead during large scale incidents.

Responsibilities

Independently triage security alerts and incident reports.

Investigate incidents using available resources, forensic and threat hunting skills.

Drive small to medium scale incidents with multiple team members and partner teams to closure.

Conduct host, network, and log analysis in support of incident response investigations

Enhance our in-house incident response platforms and build new capabilities.

Participate in oncall activities.

Work with partner teams including: PR, HR, Legal, Compliance, Investigations, Microsoft CDOC, Engineering, EPE.

Work in a team environment to drive large scale incidents to closure and full remediation.

Contribute to improving processes, procedures and technologies used by the team.

Provide feedback to detection engineering team about accuracy and quality of detections

Provide proactive and accurate data to all stakeholders for internal communication

Help uplift entire team by providing demonstration of new processes or training on systems

Support mentoring and technical development of incident response engineers

Basic Qualifications

BA/BS degree in Information Security, CyberSecurity, Computer Science, or other related technical disciplines, or equivalent practical experience

4+ years experience in Information Security, with 3+ years experience in Incident Response as part of that experience.

Incident response experience should include:

Experience with triaging security alerts.

Experience with incident lifecycle and incident handling.

Experience with log analysis

Experience with SIEM solutions

Experience with Windows and Unix operating systems logs.

Experience with Web Server logs.

Experience with EDR solutions

Experience with system level analysis - windows, linux, and mac.

Experience with 1 or more of these areas:

SOAR/Security Orchestration

Preferred Qualifications

Master’s degree in Information Security, CyberSecurity, Computer Science, or other related technical disciplines.

Developer experience, the ability to understand source code and develop scripts.

Practical threat hunting experience with open source tool chain

Scripting knowledge to automate repetitive, time consuming and error prone activities using a general purpose scripting language (ex: Python)

Prior experience with malware analysis

Suggested Skills
  • Information Security
  • Threat Hunting
You will Benefit from our Culture

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels. LinkedIn is committed to fair and equitable compensation practices.

The pay range for this role is $129,000 to $212,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Equal Opportunity Statement

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.
Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer - Incident Response
Senior Information Security Engineer - Incident Response

Linkedin3 • United States

Hybrid
USD 129,000 - 212,000
Senior Security Engineer - Detection Engineering
Senior Security Engineer - Detection Engineering

LinkedIn • United States

On-site
USD 129,000 - 212,000
Engineering Manager, Information Security
Engineering Manager, Information Security

LinkedIn • California (MO)

Hybrid
USD 156,000 - 255,000
Bonus potential
Stock options
Benefits
Staff Information Security Engineer - Detection Engineering
Staff Information Security Engineer - Detection Engineering

LinkedIn • United States

On-site
USD 156,000 - 255,000
Staff Security Engineer - Identity & Access Management
Staff Security Engineer - Identity & Access Management

LinkedIn • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Executive Assistant to the VP, Global CSO Organization (HYBRID)
Executive Assistant to the VP, Global CSO Organization (HYBRID)

CyberJobs.Com • Mountain View (CA)

Hybrid
USD 156,000 - 255,000
Sr. Technical Investigator, Trust Investigations Account Security
Sr. Technical Investigator, Trust Investigations Account Security

LinkedIn • California (MO)

Hybrid
USD 136,000 - 221,000
Health and wellness programs
Time off / generous leave
Senior Staff Software Engineer, Systems Infrastructure
Senior Staff Software Engineer, Systems Infrastructure

LinkedIn • California (MO)

Hybrid
USD 198,000 - 326,000
Principal Staff Software Engineer, Systems Infrastructure
Principal Staff Software Engineer, Systems Infrastructure

LinkedIn • California (MO)

Hybrid
USD 226,000 - 369,000
Senior Trust Technical Investigator
Senior Trust Technical Investigator

LinkedIn • Mountain View (CA)

Hybrid
USD 136,000 - 221,000