Security Incident Response Engineer
Build and improve security analytics, detection, and incident response capabilities by analyzing telemetry, investigating threats, and developing scalable behavioral models and pipelines. Requires 3+ years of security analytics experience, strong Python and SQL skills, and expertise in incident response and forensics.
About the job
Responsibilities
- Analyze and investigate threats or activities occurring on client devices.
- Develop requirements for detection models and enhance existing systems.
- Collect, transform, and ingest raw data from disparate sources into threat detection pipelines.
- Streamline incident response capabilities, tooling, and processes.
- Work cross-functionally with security engineering and data science teams to analyze security event data at scale and protect networks, systems, and data.
- Provide actionable insights to identify, prevent, detect, and respond to anomalous or potentially malicious user and entity activity.
- Serve as a subject-matter expert and primary contact for Security Analytics and Detection programs and company-wide security initiatives.
- Lead projects, mentor teammates, and champion quality standards.
Requirements
- 3+ years of experience analyzing large datasets to solve problems and/or building behavior-based security models.
- B.S. or M.S. in Computer Science or a related field, or equivalent experience.
- Expert knowledge of Python and SQL; familiarity with other programming languages.
- Experience with log analysis, network security, digital forensics, and incident response investigations.
- Proficiency developing, automating, and improving analytical detection and response systems.
- Clear communication and an impact-focused approach.
- Creative, holistic thinking about risk reduction in complex environments.
Nice-to-haves
- Adversarial mindset and understanding of threat actor goals, behaviors, and TTPs.
- Experience with software engineering, data processing, and analysis tools such as Databricks, Jupyter, and Trino.
- Familiarity with big data processing and data science frameworks such as PySpark, Pandas, and scikit-learn.
- Experience with tactical threat intelligence or hunting sophisticated enterprise threat actors.
- Familiarity with network observability, security software, or data engineering solutions such as osquery and Splunk/LogScale.
- Experience with UEBA, SIEM, SOAR, or DLP.
Skills
Python, SQL, Log Analysis, Network Security, Digital Forensics, Incident Response, Databricks, Jupyter, Trino, Pyspark, pandas, scikit-learn, Osquery, Splunk, SIEM
Similar jobs
Security Engineering jobsProtects a cloud-native fintech environment by building detections, investigating threats, operating vulnerability management, and automating security workflows. Requires 5+ years in security operations or related fields, strong Python skills, cloud experience, and expertise in telemetry-driven threat detection.
Designs and operates identity and access management systems covering federation, governance, privileged access, automation, and Zero Trust controls. Requires hands-on scripting and IAM engineering experience, including production automation and AI/LLM usage.
Build and operate automated corporate security controls across endpoint devices, identity, network access, and enterprise AI tooling. The role requires 3–5 years of endpoint, identity, or corporate security experience, strong macOS and Okta expertise, and scripting skills.
Owns hands-on GRC operations for the public-sector business, including FedRAMP/GovRAMP continuous monitoring, POA&M management, vulnerability remediation, audit readiness, and customer-facing compliance content. Requires 4+ years of cybersecurity or compliance experience and direct FedRAMP, GovRAMP, or comparable experience.
Reviews and validates real-time physical security alerts, analyzes incident data, documents findings, and escalates potential threats. The role requires strong communication, analytical ability, computer proficiency, attention to detail, and flexibility for overnight or weekend shifts.