1

Security Engineer Incident Response Jobs (NOW HIRING)

Develop processes, tooling and automation to scale incident management response and mitigate risks to the business * Collaborate with other security functions, engineering, product, support, business ...

Develop processes, tooling and automation to scale incident management response and mitigate risks to the business * Collaborate with other security functions, engineering, product, support, business ...

What you'll do You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint ...

What you'll do You will leverage your security engineering experience to improve incident response capabilities at Stripe. With an emphasis on user and entity behavior analytics, as well as endpoint ...

Showing results 21-40

Security Engineer Incident Response information

See salary details

$61.5K

$152.8K

$205.5K

How much do security engineer incident response jobs pay per year?

As of Sep 9, 2026, the average yearly pay for security engineer incident response in the United States is $152,773.00, according to ZipRecruiter salary data. Most workers in this role earn between $143,000.00 and $158,500.00 per year, depending on experience, location, and employer.

What does a security engineer incident response do?

A Security Engineer in Incident Response is responsible for detecting, investigating, and responding to security incidents within an organization. They analyze threats, contain breaches, and work to minimize damage caused by cyberattacks. Their role also involves improving security measures, documenting incidents, and collaborating with other IT and security teams to strengthen the company's defenses. Additionally, they may conduct post-incident reviews and help develop policies to prevent future incidents.

What are some common challenges faced by security engineers incident response, and how can they be addressed?

Security Engineers in Incident Response often face challenges such as rapidly evolving threats, managing large volumes of alerts, and coordinating response efforts across multiple teams. Staying updated with the latest attack techniques and regularly practicing incident response drills can help address these challenges. Effective communication, clear documentation, and collaboration with IT, legal, and management teams are crucial for successful incident handling and minimizing the impact of security incidents.

What are the key skills and qualifications needed to thrive as a security engineer incident response, and why are they important?

To thrive as a Security Engineer Incident Response, you need a solid understanding of cybersecurity principles, incident handling, and digital forensics, typically supported by a degree in computer science or a related field. Familiarity with SIEM tools, intrusion detection systems, and certifications like CISSP, CEH, or GIAC is highly valuable. Strong problem-solving abilities, attention to detail, and effective communication skills help you respond swiftly and collaborate with cross-functional teams during security incidents. These competencies are crucial for minimizing damage, ensuring rapid recovery, and strengthening an organization’s security posture.

What is the difference between Security Engineer Incident Response vs Security Analyst?

AspectSecurity Engineer Incident ResponseSecurity Analyst
CertificationsCompTIA Security+, GIAC certifications, CISSP (preferred)CompTIA Security+, GIAC certifications, CISSP (preferred)
Work EnvironmentIncident response teams, security operations centers (SOCs)Security operations centers, monitoring teams, threat analysis
Primary FocusResponding to security incidents, analyzing breaches, mitigating threatsMonitoring security alerts, analyzing vulnerabilities, reporting
Common UsageHandling security incidents, forensic analysis, threat mitigationSecurity monitoring, risk assessment, vulnerability management

While both roles involve cybersecurity and require similar certifications, Security Engineer Incident Response primarily focuses on responding to and managing security incidents, whereas Security Analysts concentrate on monitoring, analyzing threats, and identifying vulnerabilities. Both roles are essential in maintaining organizational security but differ in their core responsibilities and daily tasks.

What cities are hiring for Security Engineer Incident Response jobs?

Cities with the most Security Engineer Incident Response job openings:

What states have the most Security Engineer Incident Response jobs?

States with the most job openings for Security Engineer Incident Response jobs include:

What are popular job titles related to Security Engineer Incident Response jobs?

For Security Engineer Incident Response jobs, the most frequently searched job titles are:

Infographic showing various Security Engineer Incident Response job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $152,773 per year, or $73.4 per hour.

Security Incident Response Engineer

Atlanta, GA • On-site

Acrisure
Insurance Services • 5 - 10K employees

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 18 days ago


Acrisure rating

7.5

Company rating: 7.5 out of 10

Based on 124 frontline employees who took The Breakroom Quiz

226th of 315 rated insurance


Job description

About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services - and more.
In the last eleven years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win.
Job Summary:
The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This role serves as a key member of the Security Operations team and works closely with Infrastructure, Cloud, Identity, Workplace Technology, Legal, Privacy, Human Resources, and business stakeholders to rapidly respond to security threats and reduce organizational risk.
The engineer leverages enterprise security technologies including EDR, SIEM, cloud security platforms, email security solutions, threat intelligence, and security automation tooling to identify and respond to attacks impacting endpoints, identities, cloud environments, applications, and data. This position combines hands-on incident response, threat hunting, detection tuning, forensic investigation, and continuous improvement activities.
Success in this role means rapidly detecting and containing threats before they become business-impacting events, continuously improving the organization's ability to respond to attacks, and driving measurable reductions in response times, incident severity, and operational risk.
Responsibilities:
Incident Response Operations
  • Investigate and respond to cybersecurity incidents involving endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
  • Perform incident triage, severity classification, impact analysis, containment, eradication, and recovery activities.
  • Execute cyber incident response procedures and escalation processes in accordance with the Cyber Incident Response Plan (CIRP).
  • Coordinate response efforts across Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
  • Support major incident management activities and provide technical leadership during active security events.
  • Maintain detailed incident records, timelines, evidence, findings, and lessons learned.

Threat Detection and Investigation
  • Analyze alerts generated by EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence platforms.
  • Validate suspicious activity to distinguish true security incidents from false positives.
  • Perform root cause analysis to identify attack vectors, affected assets, compromised accounts, and attacker activities.
  • Conduct proactive threat hunting to identify indicators of compromise, adversary behaviors, and emerging threats.
  • Leverage MITRE ATT&CK techniques to improve detection and investigative effectiveness.

Digital Forensics and Evidence Collection
  • Collect, preserve, and analyze system, endpoint, cloud, email, and identity-related evidence.
  • Perform log analysis, forensic triage, malware investigation, and timeline reconstruction.
  • Support legal, regulatory, audit, and compliance investigations as required.
  • Maintain evidence handling and chain-of-custody procedures where applicable.

Security Engineering and Continuous Improvement
  • Develop and maintain incident response playbooks, investigation procedures, and operational runbooks.
  • Recommend detection improvements, new use cases, automations, and response capabilities.
  • Tune security alerts and detection logic to improve fidelity and reduce false positives.
  • Assist in the implementation and improvement of SOAR workflows and automated response capabilities.
  • Participate in tabletop exercises, incident simulations, and purple team activities.

Metrics and Reporting
  • Track and report operational metrics including:
  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Incident volume
  • Severity trends
  • Containment effectiveness
  • Detection fidelity
  • Produce incident reports, executive summaries, and post-incident reviews.
  • Identify recurring trends and recommend corrective actions.

Collaboration and Enablement
  • Partner with Security Engineering teams to improve telemetry, monitoring, and investigative capabilities.
  • Work with Vulnerability Management and Exposure Management teams on remediation activities resulting from incidents.
  • Provide guidance and mentorship to analysts and junior responders.
  • Participate in after-hours incident response and on-call rotations as required.

Education and Experience:
  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience).
  • Minimum 3 years of progressive information security experience.
  • Strong understanding of incident response methodologies, attack lifecycle, and containment strategies.
  • Experience with one or more EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or equivalent.
  • Experience with SIEM technologies such as Microsoft Sentinel, Google SecOps, Splunk, QRadar, or similar platforms.
  • Knowledge of Microsoft 365, Entra ID, Active Directory, and cloud security concepts.
  • Understanding of MITRE ATT&CK, threat intelligence, and threat hunting methodologies.
  • Familiarity with Windows, Linux, and macOS operating systems.
  • Ability to analyze logs, indicators of compromise (IOCs), and attacker techniques.
  • Experience with PowerShell, Python, KQL, or other scripting/query languages.

#LI-CH1
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
Why Join Us:
At Acrisure, we're building more than a business, we're building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.
Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks, including:
  • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
  • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
  • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
  • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
  • ... and so much more!

This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting leaves@acrisure.com.
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.
Welcome, your new opportunity awaits you.

What Acrisure employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom