Senior Security Operations & Incident Response Engineer

SCIGON

Chicago (IL)

On-site

USD 113,000 - 150,000

Full time

20 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SCIGON is seeking a Senior Security Operations & Incident Response Engineer in Chicago to advance our security operations program. You will own incident response investigations, develop playbooks, and drive detections and automation across hybrid cloud environments (GCP, Azure).

The role requires 5+ years in incident response, strong SIEM/SOAR experience, and proficiency in Python/PowerShell/Bash. Collaboration with cross-functional teams is essential to reduce risk and improve time-to-respond.

Qualifications

  • Bachelor's degree and 5+ years in incident response and SOC tooling.
  • Deep knowledge of SIEM/SOAR platforms and hybrid cloud environments (GCP, Azure).
  • Experience leading incident response as Incident Commander.
  • Scripting in Python, PowerShell, Bash, and XQL preferred.
  • Understanding MITRE ATT&CK, NIST, and ISO frameworks.

Responsibilities

  • Lead deep-dive investigations including memory, network, and malware analysis.
  • Develop and refine incident response playbooks and guidelines.
  • Build threat models and translate pen-test findings into detections.
  • Design and tune detection rules and automated remediation workflows.
  • Tune SIEM rules with the SOC team to maximize fidelity and reduce alerts.
  • Review threat intel, brand protection, and dark web monitoring.
  • Collaborate across teams and act as Incident Commander when needed.
  • Proficiency in scripting and automation, with SOAR tooling.

Skills

Incident response
SOC tooling
Threat modeling
Scripting (Python)
XQL
SOAR automation
Communication

Education

Bachelor's degree

Tools

SIEM
SOAR
GCP
Azure

Job description

Senior Security Operations & Incident Response Engineer

Salary: $112,500-$150,000

The Engineer - Security Operations and Incident Response will be a critical function responsible for the transformation of the organization's Security Operations and Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, we operate an advanced Security Operations and Incident Response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the organization. In support of the continued growth of this critical program, we are seeking an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.

  • Provide expert-level support for deep-dive investigations, including digital forensics (memory, network, and malware analysis).
  • Author and refine incident response playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
  • Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
  • Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
  • Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
  • Maintain comprehensive documentation of detection strategies, active investigations, and incident response timelines.
  • Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
  • Review and tune threat intelligence systems, including brand protection and dark web monitoring capabilities.
  • Demonstrate proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
  • Support Incident Response leadership as a backup for incident response-related activities.
  • Bachelor's degree and 5+ years of relevant experience in incident response and SOC tooling.
  • In-depth knowledge of SIEM/SOAR platforms and incident response processes in hybrid cloud environments (GCP, Azure).
  • Experience leading incident response efforts as an Incident Commander, performing root cause analysis, and driving continuous optimization of SOC tools and processes.
  • Familiarity with scripting languages such as Python, PowerShell, Bash, and XQL is highly preferred.
  • Understanding of regulatory compliance requirements and cybersecurity frameworks such as MITRE ATT&CK, NIST, and ISO.
  • Ability to prioritize tasks effectively, manage multiple competing priorities, and work both independently and collaboratively within a team.
  • Strong communication skills with the ability to translate complex technical issues and concepts into clear, concise language for non-technical audiences while emphasizing business value.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineer - SOC & IR
Engineer - SOC & IR

Pearl Consulting Group • United States

On-site
USD 120,000 - 180,000
Lead SOC IR Engineer - Remote/Hybrid
Lead SOC IR Engineer - Remote/Hybrid

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 180,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Senior Security Analyst
Senior Security Analyst

Yardi Systems • Santa Barbara (CA)

Hybrid
USD 97,000 - 110,000
Flexible work arrangements
100% paid employee medical premiums
Company profit-sharing plan
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

ConsultNet Technology Services and Solutions • Chicago (IL)

On-site
USD 130,000 - 160,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000