Lead incident response efforts for a global fintech focusing on Microsoft E5 security capabilities and DLP. Drive detection, containment, and proactive security measures for the enterprise.
Responsibilities
The Senior Incident Response Engineer will lead advanced security incident response efforts
focusing on Microsoft E5 security capabilities and Data Loss Prevention (DLP)
Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers
Lead post-incident reviews and drive process improvements
Perform advanced threat hunting using Microsoft Defender and related tools
Integrate threat intelligence and adapt detection strategies based on real world threats observed by the organization
Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents
Develop and maintain incident response playbooks and runbooks across the security operations toolset
Collaborate with analysts and other IR engineers to identify opportunities for improvement and tuning of detection rules
Collaborate with IT, legal, HR, communications, and other business units
Requirements
Minimum 5 years of progressive information security experience
At least 4 years focused on incident response, including investigations across different security domains (endpoint, application, DLP, and more)
Proficiency with Microsoft 365 Security Suite as well as other security tooling such as SentinelOne, Google SecOps, Abnormal Security, and others
Strong experience with incident response, digital forensics, and threat hunting across a hybrid environment
Knowledge of endpoint operating systems (Windows, macOS, and Linux)
Experience with cloud environments such as Azure, AWS, and GCP
Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing desired
Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, MS SC-200, MS SC-400 or similar
Benefits
Comprehensive medical insurance, dental insurance, and vision insurance
life and disability insurance
fertility benefits
wellness resources
paid sick time
Generous paid time off and holidays
Employee Assistance Program (EAP)
complimentary Calm app subscription
Immediate vesting in a 401(k) plan
Health Savings Account (HSA) and Flexible Spending Account (FSA) options
commuter benefits
employee discount programs
Paid maternity leave and paid paternity leave (including for adoptive parents)
Information Security Analyst supporting information security function at Ten, a trusted service provider. Ensuring compliance with global standards and managing security risks within the organization.
Security Operations Center Analyst managing incidents and security alerts for 7 - Eleven stores. Focusing on in - depth analysis and proactive monitoring within a state - of - the - art Security Operations Center.
Security Operations Manager at Qnity managing physical security programs across global sites. Overseeing operations and collaborating with cross - functional teams to mitigate risk and maintain secure facilities.
SOC Analyst monitoring security events and responding to incidents at Junglee Games. Collaborating on security protocols to ensure protection of digital assets.
Senior Director of Global Security Operations at CyrusOne strategizing and managing security across global data centers. Driving execution, governance, and operational excellence in a high - availability environment.
Cybersecurity generalist at PwC providing security solutions and maintaining the protection of client systems. Involves monitoring security alerts, incident response, and collaboration with stakeholders.
Security Operations Manager overseeing safety measures for corporate office locations and events at Whatnot. Responsible for developing security frameworks and managing vendor relationships across global operations.
Manager overseeing technical security operations for the Protection Services department. Responsible for managing security systems, staff training, and interdepartmental collaboration.
Principal in Security Monitoring Response at Mastercard managing global crises and resilience operations. Leading incident response efforts and ensuring the safety of people and assets.
SOC Analyst II providing real time security monitoring and threat hunting services for clients in various industries. Assisting in identifying security incidents and managing vulnerabilities.