Threat and Incident Response Engineer

Volanno

Seattle (WA)

On-site

USD 150,000 - 185,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Volanno is seeking two Threat and Incident Response Engineers to support Sound Transit. You will handle security incidents across corporate IT and OT environments, triaging alerts from SIEM/EDR/NDR, and coordinating containment, eradication, and recovery. You will also perform proactive threat hunting with OT-visible telemetry.

The role emphasizes detection tuning, SOAR automation, and writing incident reports and playbooks. Occasional onsite work around Seattle is expected as needed.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Information Systems, or related field.
  • Minimum ten (10) years of cybersecurity operations for senior or five (5) years for mid-level positions.
  • Experience responding to incidents in OT/IC/SCADA environments, not enterprise IT alone.
  • Ability to pass a Sound Transit background check.
  • Ability to work Pacific Time business hours and onsite in the Seattle area on occasion.

Responsibilities

  • Own end-to-end security incidents from triage to containment, eradication, and recovery; produce post-incident reviews.
  • Develop and tune detection content in SIEM/EDR and coordinate with OT/plant teams as needed.
  • Lead threat hunting activities and map coverage to MITRE ATT&CK.
  • Create incident playbooks, root-cause analyses, and metrics such as MTTD/MTTR.
  • Collaborate across information security, infrastructure, operations, and engineering teams.

Skills

Incident response management
Threat hunting
MITRE ATT&CK
Written communication
Cross-functional collaboration

Education

Bachelor's degree in Computer Science, Information Security, Information Systems

Tools

Microsoft Sentinel
Splunk
QRadar
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Dragos
Claroty
Nozomi Networks

Job description

Description

Volanno is seeking two Threat and Incident Response Engineers to support the information security team at Sound Transit, the regional transit authority serving the Puget Sound area. The work spans the corporate IT network and the operational technology that runs transit systems. Time is split about evenly between responding to security incidents and proactive threat hunting, with detection tuning running underneath both.

On the incident side, this role owns alerts from the moment they arrive. That means triage out of SIEM, EDR, NDR, and the OT monitoring platform, then analysis, escalation, and guidance on containment, eradication, and recovery. This team member will write the root cause analyses and incident reports that go to Sound Transit leadership, keep incident metrics current, and build out response playbooks. In the OT environment the work also involves reading industrial network traffic and coordinating directly with plant and engineering staff, since a response step that is routine on a corporate network can take something offline that needs to stay running.

On the hunting side, this team member will form hypotheses and test them against endpoint, network, log, and OT protocol telemetry. What the hunts turn up becomes new detection content. Coverage is mapped against MITRE ATT&CK to guide where hunts focus next, and threat intelligence feeds back into the following round.

Alert quality runs through both halves of the job. Detection tuning is a standing part of the role, so expect meaningful time on rule tuning, suppression logic, correlation and enrichment, and SOAR automation.

This position will function within a highly motivated, dynamic team. We are looking for someone who works calmly during an active incident and who takes the initiative on hunting rather than waiting for work to be assigned.

Requirements
Required Background
  • Bachelor's degree from an accredited U.S. college or university in Computer Science, Information Security, Information Systems, or a related subject.
  • Minimum of ten (10) years of experience in cybersecurity operations for the senior position, or five (5) or more years for the mid-level position, covering both security incident response and proactive threat hunting.
  • Demonstrated experience responding to security incidents in an Operational Technology (OT), IC, or SCADA environment, not enterprise IT alone.
  • Ability to pass a Sound Transit background check.
  • Ability to work Pacific Time business hours and to be onsite in the Seattle area on occasion.
Required Abilities, Knowledge & Skills
  • Proven experience managing security incidents end to end, from triage through containment, eradication, recovery, and post-incident review.
  • Working proficiency with a major SIEM such as Microsoft Sentinel, Splunk, or QRadar, including writing and tuning detection content.
  • Working proficiency with EDR such as Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne, and with network detection and response tooling.
  • Experience with OT monitoring platforms such as Dragos, Claroty, or Nozomi Networks.
  • Practical fluency with MITRE ATT&CK, including ATT&CK for ICs, and the ability to map detection and hunt coverage against it.
  • Ability to design and run hypothesis-driven threat hunts across endpoint, network, log, and OT protocol telemetry.
  • Detection engineering skills, including writing and refining correlation rules, queries, and use cases in SIEM and EDR platforms.
  • A track record of reducing false positives, alert noise, and duplicate ticketing, with metrics to support it.
  • Familiarity with industrial protocols and industrial network traffic analysis, such as Modbus, DNP3, OPC, or BACnet.
  • Experience folding threat intelligence into hunting and detection workflows.
  • Ability to produce incident documentation, root cause analysis reports, SOPs, playbooks, and metrics such as MTTD, MTTR, and SLA adherence.
  • Judgment to recognize when a standard IT containment action is unsafe in an operational environment, and to work out a safe alternative with engineering staff.
  • Strong written and verbal communication skills, with the ability to brief technical responders and executive stakeholders.
  • Ability to work independently within a client environment and coordinate across information security, infrastructure, operations, and engineering teams.
Preferred
  • Experience supporting a transit, rail, utility, or other critical infrastructure organization
  • Public sector or government client experience
  • Certifications such as GCIH, GCIA, GCFA, GNFA, GICSP, GRID, or CISSP
  • SOAR automation and playbook development using Sentinel Automation Rules, Splunk SOAR, Cortex XSOAR, or a comparable platform
  • Experience standing up or maturing a formal threat hunting program
  • Familiarity with the NIST Cybersecurity Framework, NIST SP 800-82, IEC 62443, and TSA Security Directives
  • Scripting for detection and automation, such as KQL, SPL, Python, or PowerShell
  • Digital forensics or malware analysis capability
  • Experience mentoring SOC analysts or leading post-incident reviews
Company Profile

Volanno is a certified woman-owned small business based in Washington, DC. As an IT solution provider, our services include custom software development, program management, and advanced data analytics. From scoping and defining to implementation and support, we are ready to support our clients' needs at any stage of development in designing and building solutions that prepare them for the future.

Volanno is an equal opportunity employer. Volanno will consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat & Incident Response Engineer (OT & Hunting)
Threat & Incident Response Engineer (OT & Hunting)

Volanno • Seattle (WA)

On-site
USD 150,000 - 185,000
Detection and Response Engineer
Detection and Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1
Senior Product Security Assurance Analyst (term-limited)
Senior Product Security Assurance Analyst (term-limited)

SoundTransit • Seattle (WA)

Hybrid
USD 81,000 - 180,000
Health Benefits
Long-Term Disability and LifeInsurance
Employee Assistance Program
+9
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Member of Technical Staff, SecOps & Threat Detection Engineer
Member of Technical Staff, SecOps & Threat Detection Engineer

Envoy Inc. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Threat Intelligence and Detection Engineer
Threat Intelligence and Detection Engineer

Insane Cyber • San Antonio (TX)

On-site
USD 90,000 - 120,000
Competitive Base Salary
Equity offering subject to board approval
Comprehensive medical/dental/vision/life insurance plan
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2
Detection & Response Analyst
Detection & Response Analyst

Toyota Tsusho Systems • Plano (TX)

On-site
USD 90,000 - 130,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Security Engineer, Incident Response
Security Engineer, Incident Response

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 180,000