Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit Inc.

Frisco (TX)

On-site

USD 140,000 - 180,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Bonus potential
Equity rewards
Benefits package

Job summary

Intuit Inc. is seeking a Senior Security Engineer to join the DFIR team within the SOC. You will respond to cyber-attacks, lead forensic investigations, and extend playbooks to cover AI/LLM risks and agentic platforms. You will collaborate with Compliance, Legal, and Risk to align IR with regulatory needs.

You will mentor responders, tune detections, and help build threat hunting capabilities across AI, cloud, and endpoint telemetry, ensuring swift action and regulatory compliance.

Qualifications

  • A Bachelor's degree or higher in Technology, CS, Cybersecurity, or related field, or equivalent hands-on experience is preferred.
  • Industry certifications such as CISSP, GCIH, GCFA, GFCE, or AWS Security Specialty are advantageous.
  • 3-5 years in a dedicated cybersecurity role with emphasis on digital forensics and IR.
  • 1-3 years writing scripts (Bash, PowerShell, Python) to automate security work; familiar with AI coding tools.
  • Experience with AI/LLM security risks and mitigations and frameworks like MITRE ATT&CK, NIST AI RMF.

Responsibilities

  • Oversee and promptly respond to escalated security events and incidents.
  • Provide on-call support for critical severity issues and report status to stakeholders.
  • Lead forensic analysis to determine root cause, scope, and impact.
  • Investigate incidents involving AI/LLM tools and extend IR playbooks for AI risks.
  • Develop and improve incident response plans, procedures, and playbooks.
  • Leverage AI SOC platforms to accelerate triage and investigations.
  • Present guidance on security best practices and incident response to partners.
  • Mentor incident responders in forensics and cloud security forensics.
  • Collaborate with Compliance, Legal and Risk to align IR with regulatory needs.
  • Assess vulnerabilities and stay updated on threats and countermeasures.

Skills

Incident response
Digital forensics
Threat hunting
Scripting (Python)
AI security awareness
Cloud security fundamentals
Communication skills

Education

Bachelor's degree in Technology/CS or equivalent
Certifications in security (CISSP, GCIH, GCFA, GFCE, AWS Security Specialty)

Tools

CrowdStrike Falcon
Wiz
Splunk
LogScale

Job description

We are seeking an experienced Senior Security Engineer to join our Digital Forensics and Incident Response (DFIR) team within the broader Security Operations Center (SOC), to help our organization respond to cyber-attacks. The ideal candidate will have a deep understanding of the security incident response and incident management process, attacker kill chains / methodologies, be able to respond quickly to attacks, restore services, and forensically investigate the root cause. They will also help defend against emerging AI and agentic system risks, tune detections, and build out threat hunting capabilities. As a member of our SOC, you will closely collaborate with other engineers to design and implement solutions, improve incident response readiness, and provide guidance and training to external teams.

Responsibilities
  • Oversee and promptly respond to escalated security events or investigations, and activate the Security Incident Response Plan as required.

  • Provide on-call support for critical severity issues, manage communications, and report incident status to the appropriate stakeholders.

  • Lead forensic analysis and conduct investigations to ascertain the root cause, scope, and impact of security incidents.

  • Investigate and respond to incidents involving AI/LLM-based tools and agentic platforms, such as data leakage, insecure output handling, and unauthorized model access, and extend IR playbooks to cover generative AI and AI SOC platform risks.

  • Develop, maintain, and improve incident response plans, procedures, and playbooks to ensure swift action and regulatory compliance.

  • Leverage AI SOC platforms and frontier AI tools to accelerate triage, detection tuning, investigation and documentation, and help evaluate new AI capabilities as they are onboarded.

  • Present guidance and training on security best practices and incident response to organizational partners, while ensuring alignment with business objectives and compliance requirements.

  • Mentor and train incident responders on incident handling techniques, forensic analysis and cloud security forensics and best practices.

  • Collaborate with Compliance, Legal and Risk teams to integrate incident response operations with business and regulatory needs.

  • Assess vulnerabilities, propose remediation strategies, and keep up-to-date on current and emerging security trends, threats, and countermeasures.

Qualifications
  • A Bachelor's degree or higher in Technology, Computer Science, Cybersecurity, or a related field, or equivalent hands‑on experience, is preferred.

  • Possession of industry-recognized professional certifications such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials is advantageous.

  • 3-5 years of experience in a dedicated cybersecurity role, with a strong emphasis on digital forensics and incident response.

  • 1-3 years writing scripts or code (Bash, PowerShell, Python) to automate security work, comfortable using AI coding assistants and AI SOC platforms to build faster, and aware of the risks that come with AI-generated code.

  • Working knowledge of AI/LLM security risks and mitigations, such as data exfiltration, insecure output handling, model and data supply chain risk, and shadow AI usage, and familiarity with frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS and NIST AI RMF.

  • Experience performing analysis and detection engineering using Endpoint Detection and Response or Cloud Security Posture Management tools such as CrowdStrike Falcon and Wiz.

  • Proven threat hunting experience, developing and executing hypothesis-driven hunts across endpoint, cloud and network telemetry to uncover threats that evade existing detections.

  • Comprehensive understanding of cybersecurity, networking and cloud fundamentals and frameworks such as OWASP, MITRE ATT&CK, NIST and CIS.

  • Experience using and defending Public Cloud services such as AWS, Azure and GCP (IAM, CI/CD Pipelines, Network Security, DLP).

  • Deep understanding of Security Information and Event Management (SIEM) solutions such as Splunk and LogScale.

  • Strong analytical and problem-solving abilities, with a focus on identifying root causes and assessing risk exposure.

  • Exceptional communication skills, both verbal and written, capable of explaining technical details to non-technical audiences and fostering strong stakeholder relationships.

  • Self-motivated with the ability to work autonomously, managing tasks effectively and seeking assistance when necessary.

  • Proficient in working under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.

  • Profound knowledge of digital forensics technologies and methodologies, as well as expertise in the Security Incident Response Lifecycle according to frameworks like NIST or SANS.

  • Adaptable and proactive attitude, willing to take on various responsibilities and eager to continuously learn and upgrade skills.

If you have a passion for security and a proven track record in incident response and security operations, we invite you to apply for this role. Join our SOC and help us protect our organization and our customers from cyber-attacks.

Intuit provides a competitive compensation package with a strong pay for performance rewards approach. This position may be eligible for a cash bonus, equity rewards and benefits, in accordance with our applicable plans and programs (see more about our compensation and benefits at Intuit®: Careers | Benefits). Pay offered is based on factors such as job-related knowledge, skills, experience and work location. To drive ongoing fair pay for employees, Intuit conducts regular comparisons across categories of ethnicity and gender.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Senior Security Engineer - Digital Forensics and Incident Response (DFIR)

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Senior Incident Response Security Engineer - Escalations
Senior Incident Response Security Engineer - Escalations

Intuit Inc. • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior Incident Response Security Engineer - Escalations
Senior Incident Response Security Engineer - Escalations

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior DFIR Engineer: AI-Driven Incident Response & Forensics
Senior DFIR Engineer: AI-Driven Incident Response & Forensics

Intuit • Frisco (TX)

On-site
USD 140,000 - 190,000
Senior AI-Driven Incident Response Engineer
Senior AI-Driven Incident Response Engineer

Intuit Inc. • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior DFIR Engineer - Incident Response & Forensics
Senior DFIR Engineer - Incident Response & Forensics

Intuit Inc. • Frisco (TX)

On-site
USD 140,000 - 180,000
Bonus potential
Equity rewards
Benefits package
Senior Cyber Security Software Engineer
Senior Cyber Security Software Engineer

Optimum Communications Inc. • Bethpage (NY)

On-site
USD 100,000 - 165,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Incident Response Engineer: AI-Driven SOC Leader
Senior Incident Response Engineer: AI-Driven SOC Leader

Intuit • Charlotte (NC)

On-site
USD 140,000 - 190,000
Cash bonus
Equity rewards
Benefits
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000