Hybrid Incident Response Engineer, Security Team

Posted last week

Apply now

About the role

  • Incident Response Engineer responsible for incident detection and recovery at Kong. Collaborating with teams to enhance security processes and systems.

Responsibilities

  • Execute, develop and document incident handling guides and processes for Kong
  • Prioritizes events using existing tools to correlate data to reduce false positives and detect threats
  • Analyze and tune security alerts and interpret events, as well as create new signals based on signatures and behavioral activities
  • Respond to security incidents and perform forensics on IT systems as necessary.
  • Guide/lead mitigation strategies for identified vulnerabilities and threats
  • Design, automate and maintain a portfolio of security alerts, automated actions, and escalation workflows supporting a high-performing 24/7 incident response capability.
  • Conduct threat hunting activities, anticipate future threats, and maintain forward-thinking strategies for tools/technology/processes that combat sophisticated threat actors.
  • Assist with implementation of counter-measures or mitigating controls
  • Develop and maintain Incident Response capabilities in public cloud environments
  • Prepare incident reports of analysis methodology and results.
  • Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough reviews and analyses of relevant event detail and summary information
  • Partner with key stakeholders and communicate effectively to improve preparation, identification, analysis, containment, and post-mortem activities feedback loop.
  • Develop monthly reporting dashboards and metrics on incidents and response capabilities
  • Prepare executive summaries and conduct briefings on significant investigations.

Requirements

  • Experience in crisis management, namely in preventing incidents from becoming a crisis
  • Insight of using incidents as opportunities by leveraging Incidents to drive innovation, situation awareness, and fixes
  • Passion for automation, delegation, and scalability via playbooks and highly effective processes
  • Drive for automating processes and workflows to detect, contain and eliminate active malicious agents
  • Expertise in building and operating security information/event management systems (SIEM), centralized logging, and enrichment solutions (Endpoint protection/detection, Panther, Crowdstrike, AWS Security Hub, codebase infrastructure, build infrastructure)
  • Practical experience working with cloud technologies; ability to build and deploy a solution using Terraform.
  • Experience with building and deploying solutions (Ansible, Terraform)
  • Competency in Linux, windows;
  • Ability to automate workflows via Python or javascript scripting languages.

Benefits

  • Health insurance
  • Flexible work arrangements

Job title

Incident Response Engineer, Security Team

Job type

Experience level

Mid levelSenior

Salary

Not specified

Degree requirement

No Education Requirement

Location requirements

HybridItaly

Report this job

See something inaccurate? Let us know and we'll update the listing.

Report job