Lead incident response efforts for a global fintech focusing on Microsoft E5 security capabilities and DLP. Drive detection, containment, and proactive security measures for the enterprise.
Responsibilities
The Senior Incident Response Engineer will lead advanced security incident response efforts
focusing on Microsoft E5 security capabilities and Data Loss Prevention (DLP)
Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers
Lead post-incident reviews and drive process improvements
Perform advanced threat hunting using Microsoft Defender and related tools
Integrate threat intelligence and adapt detection strategies based on real world threats observed by the organization
Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents
Develop and maintain incident response playbooks and runbooks across the security operations toolset
Collaborate with analysts and other IR engineers to identify opportunities for improvement and tuning of detection rules
Collaborate with IT, legal, HR, communications, and other business units
Requirements
Minimum 5 years of progressive information security experience
At least 4 years focused on incident response, including investigations across different security domains (endpoint, application, DLP, and more)
Proficiency with Microsoft 365 Security Suite as well as other security tooling such as SentinelOne, Google SecOps, Abnormal Security, and others
Strong experience with incident response, digital forensics, and threat hunting across a hybrid environment
Knowledge of endpoint operating systems (Windows, macOS, and Linux)
Experience with cloud environments such as Azure, AWS, and GCP
Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing desired
Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, MS SC-200, MS SC-400 or similar
Benefits
Comprehensive medical insurance, dental insurance, and vision insurance
life and disability insurance
fertility benefits
wellness resources
paid sick time
Generous paid time off and holidays
Employee Assistance Program (EAP)
complimentary Calm app subscription
Immediate vesting in a 401(k) plan
Health Savings Account (HSA) and Flexible Spending Account (FSA) options
commuter benefits
employee discount programs
Paid maternity leave and paid paternity leave (including for adoptive parents)
Security Operations Centre Analyst for Long View's IGS branch, focused on incident detection and response. Collaborating with teams to monitor, identify, and remediate security incidents.
Intermediate Security Operations Centre Analyst involved in IT security operations for a dynamic IT provider. Collaborating with internal teams for incident detection and response across various platforms.
SOC Engineer at Replit monitoring and assessing emerging threats in cloud infrastructure and AI coding environments. Conducting investigations and collaborating with teams for mitigation strategies.
Security Operations Lead overseeing global SOC operations and AI product integration at Replit. Leading monitoring and incident response across multi - cloud environments and AI workloads.
Cybersecurity Incident Response Engineer in Comcast's Security Incident Response Team mitigating threats and restoring environments following incidents. Working with advanced technologies to safeguard customers and infrastructure.
Director of Security Operations responsible for strategic leadership and operational excellence in security at Abridge. Leading teams focused on preventing, detecting, and responding to security threats.
Sr. Security Incident Response Engineer leveraging Splunk expertise to investigate security incidents at Autodesk. Monitoring and analyzing threats while collaborating with incident response teams.
SOC Analyst I monitoring and responding to cybersecurity threats for Byline Bank. Assisting in protecting customer and business information with compliance and real - time threat management.
Senior Manager of Regional Security Operations overseeing security programs at McKesson nationwide. Supporting risk mitigation strategies and compliance across distribution business units in the USA.
IT Security Operations Specialist ensuring security of networks and data in an international organization. Designing security controls, monitoring incidents, and utilizing advanced threat hunting techniques.