As a Senior Security Engineer, you will serve as an individual contributor focused on security incident response, investigations, and digital forensics. You will triage, investigate, and resolve security incidents across enterprise and cloud environments, and help strengthen incident response capabilities through process improvements, metrics, and threat-informed recommendations.
Key Responsibilities
Triage, investigate, and resolve security incidents from multiple sources, following established playbooks, including (but not limited to):
Phishing email reports
SIEM/SOAR alerts (Splunk)
Cloud security alerts (AWS/Azure)
Endpoint Detection & Response alerts (CrowdStrike)
Host-based proxy alerts (Zscaler)
Abuse reports, account compromises, and other security escalations
Perform in-depth incident investigations, including forensic evidence collection and analysis, to determine scope, root cause, and impact.
Conduct malware behavior analysis to assess impact and recommend remediation across Linux, Windows, and macOS environments.
Help improve incident response processes by providing feedback, documenting lessons learned, and tracking operational metrics for leadership.
Perform threat analysis of emerging threats and communicate findings, recommendations, and risk implications to management.
Stay current with attacker tactics, techniques, and procedures (TTPs) to identify and respond to sophisticated threats.
Clearly articulate incident details and response actions to business stakeholders and non-technical audiences.