They are seeking a Senior Cyber Incident Response Engineer to design, automate, and improve the systems used to manage cybersecurity incidents, ensuring effective response capabilities and ...
They are seeking a Senior Cyber Incident Response Engineer to design, automate, and improve the systems used to manage cybersecurity incidents, ensuring effective response capabilities and ...
Incident Response Engineer
New York, NY · On-site
We have built an excellent product & engineering machine and we now want to do the same on the go-to-market side. You could be a great fit if You love becoming a product and domain expert. You sell ...
Incident Response Engineer
New York, NY · On-site
We have built an excellent product & engineering machine and we now want to do the same on the go-to-market side. You could be a great fit if You love becoming a product and domain expert. You sell ...
The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and ...
The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and ...
Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise networks and mission-critical ...
Position Overview The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise networks and mission-critical ...
Sr. Incident Response Engineer (Remote)
$125K - $160K/yr
As a Senior Incident Response Engineer, you will work with a team of highly capable engineers with various degrees of experience in a newly formed IR practice. The team lives the mantra of "We don't ...
Sr. Incident Response Engineer (Remote)
$125K - $160K/yr
As a Senior Incident Response Engineer, you will work with a team of highly capable engineers with various degrees of experience in a newly formed IR practice. The team lives the mantra of "We don't ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Senior Incident Response Engineer
New York, NY · On-site
$125K - $171K/yr
Rockstar is on the lookout for a versatile Senior Incident Response Engineer who is skilled at leading response to complex security situations. We are seeking someone that can utilize their ...
Senior Incident Response Engineer
New York, NY · On-site
$125K - $171K/yr
Rockstar is on the lookout for a versatile Senior Incident Response Engineer who is skilled at leading response to complex security situations. We are seeking someone that can utilize their ...
Senior Incident Response Engineer
Manhattan, NY · On-site
$126K - $173K/yr
Rockstar is on the lookout for a versatile Senior Incident Response Engineer who is skilled at leading response to complex security situations. We are seeking someone that can utilize their ...
Senior Incident Response Engineer
Manhattan, NY · On-site
$126K - $173K/yr
Rockstar is on the lookout for a versatile Senior Incident Response Engineer who is skilled at leading response to complex security situations. We are seeking someone that can utilize their ...
Sr. Incident Response Engineer (Remote)
$117K - $160K/yr
As a Senior Incident Response Engineer, you will work with a team of highly capable engineers with various degrees of experience in a newly formed IR practice. The team lives the mantra of "We don't ...
Sr. Incident Response Engineer (Remote)
$117K - $160K/yr
As a Senior Incident Response Engineer, you will work with a team of highly capable engineers with various degrees of experience in a newly formed IR practice. The team lives the mantra of "We don't ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Job Title: Cyber Security Incident Response Engineer Location: Washington, DC Duration: FULL TIME Requirements: * 5+ years of experience in Cybersecurity incident handling and experience in Security ...
Incident Response Engineer - AI Trainer
Gainesville, FL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Gainesville, FL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Carmel, IN · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Carmel, IN · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Eugene, OR · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Eugene, OR · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Huntsville, AL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Huntsville, AL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Yuma, AZ · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Yuma, AZ · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Riverside, CA · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Riverside, CA · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Corona, CA · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Corona, CA · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Topeka, KS · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Topeka, KS · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Deltona, FL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Deltona, FL · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer - AI Trainer
Fishers, IN · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Quick apply
Incident Response Engineer - AI Trainer
Fishers, IN · Remote
$40 - $75/hr
Qualifications: * 2+ years of hands-on experience in a cybersecurity role -- such as penetration testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat ...
Incident Response Engineer information
See salary details
$17.79 - $22.25
8% of jobs
$22.25 - $26.70
1% of jobs
$29.56 is the 25th percentile. Wages below this are outliers.
$26.70 - $31.16
24% of jobs
$31.16 - $35.62
8% of jobs
$35.62 - $40.08
4% of jobs
The median wage is $41.19 / hr.
$40.08 - $44.54
15% of jobs
$47.22 is the 75th percentile. Wages above this are outliers.
$44.54 - $48.99
23% of jobs
$48.99 - $53.45
2% of jobs
$53.45 - $57.91
2% of jobs
$57.91 - $62.37
1% of jobs
$62.37 - $66.83
11% of jobs
$17
$41
$66
How much do incident response engineer jobs pay per hour?
What are the key skills and qualifications needed to thrive as an Incident Response Engineer, and why are they important?
What are Incident Response Engineers?
How does an Incident Response Engineer typically collaborate with other teams during a security incident?
What is the difference between Incident Response Engineer vs Security Analyst?
| Aspect | Incident Response Engineer | Security Analyst |
|---|---|---|
| Certifications | GCIH, CISSP, CEH | CISSP, Security+ |
| Work Environment | Responds to security incidents, investigates breaches | Monitors security systems, analyzes threats |
| Employer & Industry | Tech companies, cybersecurity firms, large enterprises | Financial institutions, government agencies, corporations |
Incident Response Engineers focus on investigating and mitigating security incidents, often working in a reactive capacity. Security Analysts monitor security systems proactively, analyzing threats and vulnerabilities. While both roles require similar certifications and work in cybersecurity environments, Incident Response Engineers are more involved in incident handling and response, whereas Security Analysts focus on threat detection and prevention.
Full-time
Posted 3 days ago
Job description
NBCUniversal is one of the world's leading media and entertainment companies. They are seeking a Senior Cyber Incident Response Engineer to design, automate, and improve the systems used to manage cybersecurity incidents, ensuring effective response capabilities and operational readiness.
Responsibilities:
• Design, build, and improve automated evidence collection capabilities that increase the speed, consistency, and completeness of incident investigations.
• Create and maintain SOAR playbooks that orchestrate investigation, enrichment, containment, notification, and recovery workflows.
• Integrate SIEM, EDR, IAM, cloud, email, case management, and threat intelligence platforms to enable unified response actions and stronger analyst context.
• Develop and deploy response tooling that may utilize AI to improve response capabilities across cloud, endpoint, identity, SaaS, email, and data platforms.
• Develop scripts, tools, and integrations that support triage, containment, enrichment, forensic collection, and operational response workflows.
• Ensure responders have the logs, telemetry, access, and tooling needed to investigate and respond without unnecessary delay.
• Build dashboards, operational views, and incident metrics that measure response performance, workflow health, and process effectiveness.
• Identify repeated manual analyst tasks and turn them into safe, scalable, and repeatable automation.
• Review incident response plans, identify readiness gaps, and help develop practical strategies to improve preparedness.
• Design and optimize incident response playbooks aligned to relevant threats, operating models, and business needs to allow for quick identification and response to potential incidents.
• Collaborate with Response Operations and Automation team stakeholders for prioritization, automation creation, and integrations with security tooling
• Facilitate or support tabletop exercises, drills, and readiness activities to validate plans and improve operational performance.
• Lead or support complex investigations involving host, network, identity, email, and cloud artifacts to determine nature, scope, and root cause.
• Partner with cross-functional teams to guide containment, remediation, recovery, and post-incident improvement activities.
• Brief technical teams and leadership on findings, risks, recommendations, and response decisions during and after incidents.
• Contribute to incident response standards, methodologies, documentation, and internal knowledge sharing.
• Participate in an incident response on-call rotation, including weekend coverage, as required.
Qualifications:
Required:
• 5+ years of relevant cybersecurity experience in either incident response, DFIR, detection engineering, threat hunting, and or SOC escalation
• 2+ years of security automation / cyber defense engineering
• Strong proficiency with Python, PowerShell, Bash, or similar scripting languages used for automation and response engineering.
• Ability to lead projects with little guidance, and strong communication
• Knowledge of SIEM, SOAR, EDR, Data Lake, and enterprise security tooling and methodologies.
• Experience handling security incidents and investigating a multitude of cyber threats with various TTPs across multiple enterprise platforms
• Experience building and maintaining API integrations across security and enterprise platforms.
• Working knowledge of SIEM query languages such as SPL, KQL, SQL, or equivalent analytics languages.
• Experience with EDR response actions, investigation workflows, and endpoint containment techniques.
• Experience designing, building, or operating SOAR platforms and automated playbooks.
• Strong understanding of endpoint, identity, network, cloud, email, and SaaS telemetry, including logging, evidence collection, and containment actions across modern environments.
• Experience collecting and using forensic artifacts to support investigations across endpoints, identities, cloud services, email, or SaaS platforms.
• Ability to design for scale, repeatability, automation, reliability, and reduced response time in a production security environment.
• Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Digital Forensics, or a related field, or equivalent practical experience.
Preferred:
• 7+ years of relevant cybersecurity or security operations experience.
• Demonstrated ownership of incident response engineering, automation, forensic collection, containment workflows, or large-scale security operations improvements.
• Experience conducting threat intelligence, threat detection, malware analysis, or forensic analysis in security incidents as a team
• Experience building and leveraging AI-assisted tooling in investigation or triage workflows for a large, distributed enterprise environment
• Experience integrating case management, email security, identity platforms, cloud services, and threat intelligence into response workflows.
• Experience building analyst-facing dashboards, metrics, and reporting that show operational health and response effectiveness.
• Strong understanding of cloud technologies, AI agents, and LLMs
• Familiarity with secure automation guardrails, approval models, and change control for containment actions.
• Experience with detection engineering and the operationalization of alerts, enrichments, and response workflows.
• Experience improving responder access to logs, telemetry, and investigative tooling across multiple security domains.
• Relevant certifications are preferred rather than required. Preferred certifications may include GCIH, GCFA, GCFE, GNFA, EnCE, CFCE, GCIA, GSEC, CySA+, Blue Team Level 2, AWS Security Specialty, Azure Security Engineer, Google Cloud Security Engineer, CISSP, CISM, GPEN, OSCP, or PNPT.
Company:
NBCUniversal is a media company that provides entertainment and news development, production, distribution, and marketing services. It is a sub-organization of Comcast. Founded in 1912, the company is headquartered in New York, USA, with a team of 10001+ employees. The company is currently Late Stage.