Search by job, company or skills

Senior Incident Response & Security Automation Engineer

  • Posted 4 days ago
  • Be among the first 10 applicants

Job Description

We are seeking a deeply technical cybersecurity professional who can personally investigate complex security incidents while developing software and automation that improve detection and response capabilities.

This is a hands-on individual-contributor position—not primarily a SOC management, governance, or compliance role. The successful candidate will spend most of their time conducting technical investigations, developing detections, writing code, automating security workflows, and strengthening incident-response processes.

The ideal candidate can independently investigate security activity across endpoints, identities, networks, cloud platforms, and applications; determine the scope and root cause of an incident; execute containment and remediation actions; and develop reliable tools and automation using Python, PowerShell, APIs, and security platforms.

Key Responsibilities

  • Lead hands-on investigations of malware, compromised accounts, phishing, lateral movement, unauthorized access, data exfiltration, insider threats, and cloud security incidents.
  • Analyze endpoint, network, identity, cloud, application, email, firewall, authentication, SIEM, and EDR telemetry.
  • Determine incident scope, root cause, affected systems, attacker activity, business impact, and required remediation.
  • Build detailed incident timelines and document investigative findings, evidence, decisions, and response actions.
  • Perform proactive threat hunting across enterprise environments.
  • Develop and tune SIEM detections, correlation rules, investigation queries, alerts, dashboards, and enrichment workflows.
  • Write maintainable Python and/or PowerShell code to automate investigation, evidence collection, enrichment, containment, and reporting.
  • Build integrations between security platforms using REST APIs, webhooks, JSON, and other structured data.
  • Develop and maintain SOAR workflows and automated incident-response actions.
  • Review existing detections and response processes to identify visibility gaps and opportunities for automation.
  • Create clear, technically detailed incident-response playbooks that analysts can consistently execute.
  • Work with security, infrastructure, cloud, application, and software engineering teams to remediate vulnerabilities and security weaknesses.
  • Provide technical guidance during major incidents while remaining directly involved in the investigation.
  • Conduct post-incident reviews and translate lessons learned into improved detections, tools, playbooks, and controls.
  • Mentor other analysts and share technical knowledge without moving away from hands-on investigative work.

Required Qualifications

  • At least five years of hands-on experience in incident response, digital forensics, threat hunting, detection engineering, security engineering, or advanced SOC operations.
  • Demonstrated experience serving as a primary technical investigator for significant cybersecurity incidents.
  • Strong Python development experience and proficiency with PowerShell, Go, Java, C#, or another relevant programming language.
  • Experience developing security tools, scripts, integrations, or automation—not simply using existing security platforms.
  • Understanding of software engineering practices, including Git-based version control, testing, code reviews, reusable design, structured logging, documentation, and error handling.
  • Advanced experience working with SIEM, EDR, identity, cloud-security, email-security, and network-security technologies.
  • Strong knowledge of Windows and Linux operating systems, endpoint behavior, authentication activity, process execution, network communications, and common forensic artifacts.
  • Experience investigating compromised credentials, malicious processes, persistence mechanisms, lateral movement, command-line activity, suspicious network connections, and data-access events.
  • Ability to develop complex SIEM queries and detection logic using tools such as Microsoft Sentinel, Splunk, QRadar, or similar platforms.
  • Experience integrating systems through REST APIs and working with structured data such as JSON.
  • Strong understanding of the incident-response lifecycle, MITRE ATT&CK framework, common attacker techniques, and containment and remediation strategies.
  • Ability to communicate complex technical findings clearly to both technical teams and business stakeholders.
  • Strong written English and experience producing detailed incident reports, investigative documentation, and response playbooks.

Preferred Qualifications

  • Experience with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Carbon Black, Splunk, or similar platforms.
  • Experience developing SOAR playbooks and automated response workflows.
  • Familiarity with Azure, AWS, Microsoft 365, Entra ID, Active Directory, and cloud logging.
  • Experience with malware analysis, memory analysis, disk forensics, email investigations, or network forensics.
  • Experience building internal security applications, enrichment services, case-management integrations, or investigation tools.
  • Experience working with DevOps or CI/CD pipelines.
  • Relevant certifications such as CISSP, GCIH, GCFA, GCIA, GNFA, OSCP, SC-200, or equivalent practical experience.

  • What We Are Looking For

    We are looking for someone who can clearly explain:

    • A complex incident they personally investigated from initial alert through containment and recovery.
    • The evidence and forensic artifacts they personally analyzed.
    • How they determined the scope and root cause of the incident.
    • A security tool, integration, or automation they personally designed and coded.
    • How their work improved investigation quality, response speed, or detection coverage.

    More Info

    Job Type:
    Industry:
    Function:
    Employment Type:

    Job ID: 151600485