Job Description
The Incident Response Engineer will manage security incident response processes, investigate threats, and implement corrective actions to contain and remediate incidents. They will analyze security alerts, perform initial triage, determine the scope and impact of incidents, and escalate or coordinate responses with other teams as necessary. Responsibilities include conducting thorough investigations, performing digital forensics and malware analysis, preserving digital evidence, and managing cybersecurity incident and spillage response processes. They will develop, maintain, and improve incident response playbooks, participate in threat hunting activities, and conduct post-incident reviews to generate reports and track metrics. This role involves configuring and maintaining incident response tools and systems, including SIEM solutions, and contributing to security awareness efforts through training and exercises. The Engineer will stay current with emerging threats and best practices, assist in security awareness programs, and collaborate with IT and security teams to enhance incident response capabilities and prevent future incidents.
Must have:
- Minimum 8 years of experience in security incident response, digital forensics, or cyber investigation
- Masters or Ph.D in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology or Software Engineering, OR possess a DoD 8140 Certification
Security Clearance:
- Active Secret, Top Secret, TS/SCI, or TS/SCI with Polygraph clearance required, depending on position