Incident Responder
The Incident Responder investigates cloud attacks, performs proactive threat hunting, and supports customers during incident response engagements. The role requires at least five years of cybersecurity experience, strong cloud security knowledge, and familiarity with Kubernetes, major cloud providers, and Windows and Linux internals.
About the job
Responsibilities
- Investigate real-world cyberattacks on customers’ cloud environments and workloads, determine root causes and the full scope of compromise, and leverage the Wiz platform.
- Perform proactive threat hunting to identify undetected cyberattacks and cloud threats in customer environments.
- Collaborate with customer teams during engagements to respond effectively to threats.
- Develop and deliver professional engagement reports, including high-level summaries and detailed technical findings.
- Develop and document incident response methodologies, best practices, and standard operating procedures for cloud environments and workloads.
- Collaborate with threat research and engineering teams to improve incident response detections, tools, and features based on real-world investigations.
Requirements
- 5+ years of experience in cybersecurity, cyber-incident response, and threat hunting.
- Solid cloud security foundation, including familiarity with cloud services, Kubernetes, cloud architecture, and major providers such as AWS, Google Cloud, and Azure.
- In-depth knowledge of Windows and Linux operating system internals.
- Strong analytical skills and attention to detail.
- Experience with scripting and querying languages.
- Excellent verbal and written communication skills.
- Ability to solve problems independently and innovate in an incident response role.
Skills
Cloud Security, Kubernetes, AWS, GCP, Microsoft Azure, Cloud Architecture, Windows Internals, Linux Internals, Threat Hunting, Incident Response, Scripting Languages, Querying Languages, Wiz Platform
Similar jobs
Security Engineering jobsBuild and scale application security for an enterprise AI platform through threat modeling, secure architecture, automated controls, code review, penetration testing, and AI/ML threat research. Requires 4+ years of application security experience and proficiency in at least two programming languages.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Conduct end-to-end security research on emerging threats, CVEs, misconfigurations, and cloud attack surfaces, then turn findings into scalable detection capabilities. Requires at least five years of security research or related experience, strong scripting skills, and expertise in network and application security.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.