Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Incident Response Engineer

Acrisure

About Acrisure A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more. In the last twelve years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.Job Summary: The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This role serves as a key member of the Security Operations team and works closely with Infrastructure, Cloud, Identity, Workplace Technology, Legal, Privacy, Human Resources, and business stakeholders to rapidly respond to security threats and reduce organizational risk. The engineer leverages enterprise security technologies including EDR, SIEM, cloud security platforms, email security solutions, threat intelligence, and security automation tooling to identify and respond to attacks impacting endpoints, identities, cloud environments, applications, and data. This position combines hands-on incident response, threat hunting, detection tuning, forensic investigation, and continuous improvement activities. Success in this role means rapidly detecting and containing threats before they become business-impacting events, continuously improving the organization's ability to respond to attacks, and driving measurable reductions in response times, incident severity, and operational risk. Responsibilities:Incident Response Operations Investigate and respond to cybersecurity incidents involving endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure. Perform incident triage, severity classification, impact analysis, containment, eradication, and recovery activities. Execute cyber incident response procedures and escalation processes in accordance with the Cyber Incident Response Plan (CIRP). Coordinate response efforts across Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams. Support major incident management activities and provide technical leadership during active security events. Maintain detailed incident records, timelines, evidence, findings, and lessons learned. Threat Detection and Investigation Analyze alerts generated by EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence platforms. Validate suspicious activity to distinguish true security incidents from false positives. Perform root cause analysis to identify attack vectors, affected assets, compromised accounts, and attacker activities. Conduct proactive threat hunting to identify indicators of compromise, adversary behaviors, and emerging threats. Leverage MITRE ATT&CK techniques to improve detection and investigative effectiveness. Digital Forensics and Evidence Collection Collect, preserve, and analyze system, endpoint, cloud, email, and identity-related evidence. Perform log analysis, forensic triage, malware investigation, and timeline reconstruction. Support legal, regulatory, audit, and compliance investigations as required. Maintain evidence handling and chain-of-custody procedures where applicable. Security Engineering and Continuous Improvement Develop and maintain incident response playbooks, investigation procedures, and operational runbooks. Recommend detection improvements, new use cases, automations, and response capabilities. Tune security alerts and detection logic to improve fidelity and reduce false positives. Assist in the implementation and improvement of SOAR workflows and automated response capabilities. Participate in tabletop exercises, incident simulations, and purple team activities. Metrics and Reporting Track and report operational metrics including: Mean Time to Detect (MTTD) Mean Time to Respond (MTTR) Incident volume Severity trends Containment effectiveness Detection fidelity Produce incident reports, executive summaries, and post-incident reviews. Identify recurring trends and recommend corrective actions. Collaboration and Enablement Partner with Security Engineering teams to improve telemetry, monitoring, and investigative capabilities. Work with Vulnerability Management and Exposure Management teams on remediation activities resulting from incidents. Provide guidance and mentorship to analysts and junior responders. Participate in after-hours incident response and on-call rotations as required. Education and Experience:Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience). Minimum 3 years of progressive information security experience. Strong understanding of incident response methodologies, attack lifecycle, and containment strategies. Experience with one or more EDR platforms such as Microsoft Defender for Endpoint, SentinelOne, CrowdStrike, or equivalent. Experience with SIEM technologies such as Microsoft Sentinel, Google SecOps, Splunk, QRadar, or similar platforms. Knowledge of Microsoft 365, Entra ID, Active Directory, and cloud security concepts. Understanding of MITRE ATT&CK, threat intelligence, and threat hunting methodologies. Familiarity with Windows, Linux, and macOS operating systems. Ability to analyze logs, indicators of compromise (IOCs), and attacker techniques. Experience with PowerShell, Python, KQL, or other scripting/query languages. #LI-CH1Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.Why Join Us:At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.Employee BenefitsWe also offer our employees a comprehensive suite of benefits and perks, including:Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.… and so much more!This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting View email address on us.fitly.work candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.Welcome, your new opportunity awaits you.SummaryLocation: 1170 Peachtree St Ste 1200 - ATLANTA, GA; 100 Ottawa Ave Sw - GRAND RAPIDS, MIType: Full time

Vacancy posted 23 days ago
Similar jobs that could be interesting for youBased on the Security Incident Response Engineer in Atlanta, GA vacancy
  • $80.2k - $111.3k

     ...and eliminate high level data and cyber security risks. Designs, tests and implements...  ...complex computer and information security incidents to determine extent of compromise to...  ...damage and threat assessment programs. Responsible for the formal Security Test and Evaluation... 
    Suggested
    Contract work
    Work at office

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    5 days ago
  •  ...help businesses get paid quickly and securely - without hidden fees. We built the tech...  ...roleOur Cyber Threat Intelligence & Response (CTIR) engineers are the people we count on when...  ...wrong far less often. This is a hands-on incident response role. You'll lead the response... 
    Suggested
    Local area
    Immediate start
    Visa sponsorship

    FieldEdge

    Atlanta, GA
    1 day ago
  • $105k

     ...operate at the intersection of security and technology, combining...  ...previous experience as a Sales Engineer, Solutions Engineer, or Pre-...  ...simultaneously Main Responsibilities Partner with Account Executives...  ...prevents security breaches or incidents that compromise... 
    Suggested

    RedHelm

    Atlanta, GA
    6 days ago
  •  ...nation's most mission-critical facilities, secure environments, complex infrastructure,...  ...power and technology solutions through engineering expertise and smart systems integration...  ...zones and various other individual responsibilities as assignedForklift and telehandler experience... 
    Suggested
    Relocation

    M.C. Dean, Inc.

    Atlanta, GA
    2 days ago
  •  ...Sales Engineer EyeQ Monitoring is a rapidly growing security technology and remote video monitoring company committed to protecting people, property, and...  ...values-driven organization. The Sales Engineer is responsible for all aspects of supporting the design and... 
    Suggested
    For contractors
    For subcontractor
    Work at office
    Remote work

    EyeQ Monitoring

    Atlanta, GA
    5 days ago
  • A hands-on Senior Infrastructure Engineer who will own and elevate an on-premises and hybrid...  ..., scalability, lifecycle, and security across servers, virtualization platforms...  ...patching, monitoring, capacity planning, incident response, backup validation, and disaster recovery... 
    Temporary work
    Flexible hours

    Humans Doing

    Smyrna, GA
    5 days ago
  •  ...per year | Full Time OT Cybersecurity Engineer I-V Protect the Digital Infrastructure...  ...Operations Corporation (GSOC) is seeking an Security Operations Engineer to help protect the...  ..., monitoring, threat detection, incident response, recovery, and secure access capabilities... 
    Full time
    Work experience placement

    Georgia Systems Operations

    Tucker, GA
    5 days ago
  • $169.6k - $233.2k

     ...SummaryYour CareerAs a Cortex Transformation Engineer, you are a critical part of the Global...  ...undergo a flawless migration and security operations transformation to modern platforms...  ...platform workflows, alert triage, incident response, Agentic-AI and automated playbooks using... 
    Full time
    Remote work
    Visa sponsorship
    Work visa

    Palo Alto Networks

    Atlanta, GA
    4 days ago
  •  ...Description Description: Leads OT/ICS security strategy and architecture, sets...  ..., and directs advanced assessment and incident response for industrial environments. Key...  ...convergence risk ? Mentor Mid/Junior OT engineers Requirements:   Minimum Qualifications... 
    Contract work
    Local area

    Xtreme Solutions Corporate

    Atlanta, GA
    8 days ago
  • Cybersecurity Engineer III-V Lead Security Engineering for Mission-Critical Technology Environments Georgia System Operations Corporation (...  ...engineering, security monitoring, vulnerability management, incident response, and continuous improvement initiatives that strengthen... 
    Work experience placement
    Casual work
    Work at office
    Afternoon shift

    Georgia System Operations

    Tucker, GA
    4 days ago
  • $130.2k - $195.4k

     ...TeamSecurity Automation & Integration Engineering (SecAIE) transforms...  ...support tools that enable security teams to make precise, data-...  ...security data - so detection, response, and threat-intel teams can...  ...security data (vulnerabilities, incidents, identity, threat intel,... 
    Full time
    Work at office
    Remote work
    Home office
    Flexible hours

    Workday

    Atlanta, GA
    1 day ago
  •  ...nation’s most mission-critical facilities, secure environments, complex infrastructure,...  ...power and technology solutions through engineering expertise and smart systems integration...  ...Quality Engineer 2 is responsible for following the M.C. Dean Quality Control... 
    For subcontractor

    M.C. Dean

    Atlanta, GA
    a month ago
  • $24.92 - $33.23 per hour

     ...Responsibilities for this Position Location: 1941 Robertson Road, Ottawa, Canada Employment Type:...  ...Dynamics Mission SystemsCanada, were not just engineering technology were shaping the future of defence and security. Our teams design and deliver advanced, mission... 
    Hourly pay
    Full time
    Temporary work
    Work experience placement
    Internship
    Flexible hours

    General Dynamics

    Atlanta, GA
    1 day ago
  • Company Overview ibossis a cloud security company that enables the modern workforce to...  ...learn more, visit Job Description Sales Engineers partner closely with their sales team...  ...opportunity for growth within the company. Responsibilities Work with and support sales team... 
    Shift work

    iboss

    Atlanta, GA
    6 days ago
  •  ...Automation EngineerWe are seeking an Automation Engineer to design, build, and operate automation...  ...repeatable. You will collaborate with security, platform, network, and application...  ...frequency. • MTTR for automation incidents and scope of auto-remediation coverage.... 

    Tekfortune Inc

    Atlanta, GA
    3 days ago
  •  ...test, deploy and operate. The team is responsible for taking products like Ghost, Anvil,...  ...customers. We are looking for software engineers, hardware engineers, roboticists, and front...  ...critical national and international security challenges. Engineers rely on Mission Operators... 
    Contract work
    Work at office
    Local area
    Immediate start

    Anduril

    Atlanta, GA
    6 days ago
  •  ...Our teams operate at the intersection of security and technology, combining deep...  ...Role We are seeking a Senior Network Engineer to join our team in a projects-focused...  ...in the Eastern Time Zone.   Role & Responsibilities Design, deploy, and maintain enterprise... 
    H1b
    Local area
    Remote work
    Shift work

    RedHelm

    Atlanta, GA
    17 days ago
  • $87.1k - $157.45k

     ...NISC IV program seeks an Electrical Engineer/ Radio Frequency (RF) Engineer to support...  ...The Spectrum Engineering Group is responsible for securing, managing, and protecting all civil...  ...local law enforcement and report the incident to the . Commitment to Non-Discrimination... 
    Work at office
    Local area
    Immediate start
    Remote work

    Leidos

    Decatur, GA
    4 days ago
  • $58.1k - $95.9k

     ...Overview The Change Management Engineer designs, implements, and...  ...ITSM tooling. Key Responsibilities Design and maintain ITIL-...  ...volume, and change-related incidents, recommending process and tooling...  ...with project, operations, and security teams to integrate change... 
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Atlanta, GA
    2 days ago
  • $99k - $225k

    Systems Security Tool EngineerThe Opportunity: Serve as a key member of the HHS Security...  ...experience as a cybersecurity and systems engineer, supporting enterprise security...  ...Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Atlanta, GA
    6 days ago
  • $168.75k - $270k

     ....Job Description - Principal Security Operations EngineerOur mission...  ...PrincipalSecurity Operations Engineer, you will play a key role in...  ...security and infrastructure incidents, driving root cause analysis,...  ...distributed systems and lead technical response to high-impact security,... 
    Work experience placement
    Work at office

    Axon

    Atlanta, GA
    2 days ago
  •  ...NEC (NFPA 70), NFPA 70E, and EM-385. Responsibilities: ~• Support company Environmental...  ...general safety audits and near miss, incident, and accident investigations as needed...  ...electrical experience. Bachelor's Degree in Engineering or Construction Management strongly... 
    For contractors
    Work at office
    Weekend work

    Owen Electric Company, Inc

    Atlanta, GA
    2 days ago
  •  ...systems (S4HANA, SAP BW) using Azure Data Factory. Ensure data security by designing and implementing object-level Role-Based Access...  ...reliable analytics. Collaborate with business stakeholders, data engineers, and analysts to understand requirements and deliver effective... 

    E-Solutions

    Atlanta, GA
    5 days ago
  •  ..., and executive programs in engineering, computing, science, business...  ...neuroscience, and national security. Georgia Tech ranks among the...  ...We act ethically. 9. We are responsible stewards. Over the next...  ...processes, configurations, and incident response procedures to ensure... 
    Full time
    Contract work
    Temporary work
    Part time
    For contractors
    Work at office
    Local area

    Georgia Tech

    Atlanta, GA
    3 days ago
  • Job Description TITLE: Customer Success Engineer DEPARTMENT: Information Technology...  ...technical, user-friendly way. PRIMARY JOB RESPONSIBILITIES Offers technical support to both internal...  ...audiences. Resolves assigned support incidents and tasks within the established SLA parameters... 
    Permanent employment
    Full time
    Casual work
    Work at office
    Local area
    Remote work
    Weekend work
    Weekday work

    Engle Martin

    Atlanta, GA
    5 days ago
  • $100k - $130k

     ...Exposure to large enterprises or regulated environments. Roles & Responsibilities Plan, prepare, and execute z/OS operating system upgrades...  ..., SMF datasets). Provide expert-level support for mainframe incidents, including problem determination, diagnosis, and resolution... 

    Tata Consultancy Services

    Atlanta, GA
    2 days ago
  •  ...highly motivated Help Desk Engineer to join our Infrastructure &...  ...enterprise environment.Manage incidents through completion while...  ...by providing professional, responsive, and solution-oriented support...  ...vulnerabilities.Support endpoint security and ensure systems remain... 
    Work at office
    Remote work

    Atlanticus Services Corporation

    Atlanta, GA
    6 days ago
  •  ...Description POSITION: Senior Microsoft 365 Engineer (Identity, Endpoint & Compliance) We’...  ...Compliance and configuration profiles, security baselines, Autopilot, update rings, app...  ...• Defender: endpoint detection and response on every managed device, Defender for Office... 
    Work at office
    Shift work

    Four Winds Health

    Atlanta, GA
    7 days ago
  • $159.6k - $239.4k

     ...Identity team sits within Workday's Cyber Security function as a key part of Enterprise...  ...About the RoleAs a Sr. IAM Cybersecurity Engineer on the Enterprise Identity team, you will...  ...IGA, and PAM.In this role, you will be responsible for:Working with key business leaders and... 
    Full time
    Work at office
    Remote work
    Home office
    Flexible hours
    Shift work

    Workday

    Atlanta, GA
    2 days ago
  • $132.1k - $165.1k

     ...generations. Role Summary We are seeking an Incident Commander to lead our response capabilities through a code-first...  ...to minimize business downtime. Engineering Resilience: Pivot from reactive "...  ..."fire-proofing." operationalize "Security as Code" by developing automation... 
    Full time
    Contract work
    Temporary work
    Part time
    Local area
    Shift work

    Rivian

    Atlanta, GA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Incident Response Engineer. Be the first to apply!