Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cybersecurity Engineer - Incident Response & Threat Detection

Fragomen Worldwide

Cyber Security Engineer

Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team.

Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and security is critical to its success. We are seeking a professional who is passionate about protecting the organization, capable of leading response efforts during security incidents, and eager to mature enterprise-wide incident detection, investigation, and response capabilities.

You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in detecting, investigating, containing, and remediating cyber incidents, while helping to strengthen Fragomen's overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Incident Response, you will:

  • Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
  • Monitor, investigate, and correlate security alerts using SIEM, EDR, and forensic tools.
  • Perform digital forensic investigations across endpoints, servers, cloud, and network environments.
  • Triage and escalate security events in accordance with established incident response procedures.
  • Develop, maintain, and continuously improve incident response playbooks, SOPs, and workflows.
  • Improve alert quality and response effectiveness through root cause analysis and post-incident reviews.
  • Partner with IT, Legal, Compliance, Privacy, and Risk teams during security incidents.
  • Support regulatory, legal, and client-driven incident response and reporting requirements.
  • Participate in and facilitate incident response tabletop exercises and simulations.
  • Contribute to the design and enhancement of detection, logging, and monitoring capabilities.
  • Provide technical guidance and mentorship to junior analysts and security team members.

Required Qualifications

  • 1+ years of experience in cybersecurity, incident response, or security operations.
  • Hands-on experience responding to security incidents in enterprise environments.
  • Strong ability to analyze security events and perform technical investigations.
  • Working knowledge of:
    • TCP/IP, DNS, VPNs, firewalls, and proxy technologies
    • Windows and Linux operating systems
    • Identity and access systems and authentication mechanisms
  • Experience using SIEM and security platforms such as:
    • Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar
  • Ability to identify and respond to:
    • Phishing and business email compromise
    • Malware and ransomware
    • Credential compromise
    • Lateral movement and persistence mechanisms
    • Brute-force and privilege escalation attacks
  • Strong written and verbal communication skills, especially during high-pressure incidents.
  • Demonstrated ability to follow structured processes while continuously improving them.

Preferred Qualifications

  • Experience with EDR, SOAR, and forensic tooling (e.g., CrowdStrike, Defender, Carbon Black, EnCase, Velociraptor, etc.).
  • Experience supporting investigations involving legal, compliance, or regulatory stakeholders.
  • Knowledge of MITRE ATT&CK and modern adversary tactics.
  • Experience with cloud and SaaS incident response (Azure, M365, AWS, etc.).
  • Relevant certifications, including:
    • GIAC (GCIH, GCFA, GCIA)
    • Offensive Security (OSCP, OSCE, OSEE)
  • Vendor certifications (Splunk, Sentinel, CrowdStrike, etc.)

All offers and/or employment contracts are contingent upon the successful completion of the Firm's pre-employment screening process. This process may include verifying the candidate's identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI-assisted tools for administrative screening purposes only - never for decision-making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cybersecurity Engineer - Incident Response & Threat Detection in United States vacancy
  •  ...Mobility Tech Solutions LLC is seeking a Cyber Security Engineer to join its Information Security & Cyber Security...  ...ideal candidate will have strong experience in incident response, digital forensics, and threat detection, ensuring robust security measures across... 
    Suggested

    600 Mobility Tech Solutions LLC

    New York, NY
    2 days ago
  •  ...Job Description The Cybersecurity Incident Response (IR) Lead and Detection is responsible for the dual mission of advanced threat detection capabilities and leading the charge...  ...KEY RESPONSIBILITIES: Detection Engineering (the "Hunt) Advanced Logic Development... 
    Suggested

    United States Steel

    Pittsburgh, PA
    2 days ago
  • $103k - $128k

     ...law firm in Cleveland is seeking a SOC/Incident Report Engineer to strengthen their cybersecurity measures. In this role, you will detect and respond to cybersecurity incidents,...  ...position requires 3-7 years of SOC or incident response experience, and familiarity with tools... 
    Suggested

    Benesch, Friedlander, Coplan & Aronoff

    Cleveland, OH
    2 days ago
  • $97k - $112k

    Infleqtion is seeking a cybersecurity professional for a full-time role based in Louisville, CO. This position involves protecting systems and data from cyber threats while monitoring security incidents. The ideal candidate should have a Bachelor's in a relevant field,... 
    Suggested
    Full time

    Infleqtion

    Louisville, KY
    1 day ago
  •  ...Threat Detection And Response Engineer Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology...  ...Develop, integrate, and operate security event detection and incident management services. Automate repeatable incident... 
    Suggested
    Remote work

    Thought Machine

    United States
    3 days ago
  • $135k - $216k

     ...Forensic And Incident Response Engineer **Position is Contingent Upon Award** Peraton...  ...working alongside leaders in cybersecurity engineering, operations, forensics, threat analysis, data science, and...  ...you will be responsible for detecting, investigating, and... 
    Contract work
    Remote work
    Shift work

    Peraton

    United States
    5 days ago
  • $55.7k - $82.1k

     ...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives... 
    Contract work
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Annapolis, MD
    2 days ago
  •  ...Senior Cybersecurity Engineer Opportunity to work in a hybrid model: Potential...  ..., including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk,...  ...engineered security controls and detection mechanisms aligned with... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Flexible hours

    GMAC Financial Services

    Fort Worth, TX
    19 days ago
  • $146k - $184k

     ...Senior Threat Detection and Response Engineer At CarGurus, our mission is to give people the power to reach...  ...our first line of defense against cybersecurity threats in a complex and evolving...  ..., and efficient querying during incidents. Apply an engineering mindset to... 
    Flexible hours

    Venturefizz Product Management Community

    Boston, MA
    4 days ago
  • $115k - $165k

     ...space environment and counter threats from the ultimate high...  ...YOUR MISSION As a Threat Detection & Response Engineer III, you will be an...  ...capabilities, sharpen our incident response procedures, and contribute...  ...3+ years of experience in cybersecurity, with at least 2 years... 
    Permanent employment
    Work at office

    True Anomaly

    Denver, CO
    5 days ago
  •  ...Cybersecurity Incident Response Engineer, Mid The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise...  ...and application teams to contain threats while preserving evidence and minimizing... 
    Contract work
    Work experience placement
    Work at office
    Remote work

    ASM Research

    United States
    3 days ago
  •  ...Threat Detection Engineer TENEX is an AI-native, automation-first, built-for...  ...Managed Detection and Response (MDR) provider. We are a force...  ...enhance their cybersecurity posture through advanced threat...  ...malicious activity, security incidents, and policy violations.... 
    Remote work

    TenEx

    United States
    4 days ago
  • $116k - $145k

     ...Threat Detection and Response Engineer II CarGurus is looking for a Security Engineer II to add to our...  ...our first line of defense against cybersecurity threats in a complex and evolving...  ...models, and efficient querying during incidents. Develop high-fidelity, rule-... 

    Venturefizz Product Management Community

    Boston, MA
    4 days ago
  • $80.2k - $111.3k

     ...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts...  ...deep technical focus on threat containment and eradication. It also...  ...organization's ability to prevent, detect, and rapidly respond to sophisticated... 
    Contract work
    Work experience placement
    Work at office

    ASM Research, An Accenture Federal Services Company

    Little Rock, AR
    3 days ago
  •  ...law firm based in Columbus is seeking a SOC/Incident Response Engineer to bolster its cybersecurity efforts. This hybrid position involves monitoring security threats, conducting incident responses, and improving detection capabilities. The ideal candidate should have... 

    Benesch, Friedlander, Coplan & Aronoff

    Columbus, OH
    2 days ago
  • $115k - $125k

    A cybersecurity firm is seeking an Engineer II - Cyber Incident Response in Carrollton, TX. The role focuses on detecting, investigating, and responding to cybersecurity incidents to protect digital assets against threats. Candidates should have 2-5 years of experience... 

    Piper Companies

    Carrollton, TX
    5 days ago
  • A cybersecurity firm in San Antonio is seeking a Threat Intelligence and Detection Engineer. This position involves providing consultancy services to mitigate cybersecurity...  ..., with skills in digital forensics and incident response. The firm offers competitive benefits,... 
    Flexible hours

    Insane Cyber

    San Antonio, TX
    1 day ago
  • $89.01k - $142.19k

     ...insight and research into new threats, exploits, and mitigation...  ...an innovator in threat detection? About the Role You will...  ...senior most technical member of incident response team for our global...  ...techniques, malware reverse engineering, threat analysis, and security... 
    Local area
    Remote work
    Work from home

    RELX

    United States
    7 days ago
  • $260k - $405k

    A leading AI research organization is seeking a mid-level to senior Security Engineer specialized in Insider Threat Detection & Response. This role involves innovating infrastructure for security, developing detection rules, and managing insider threats. Ideal candidates... 
    Remote work

    OpenAI

    Los Angeles, CA
    7 days ago
  •  ...write together. We are starting the mapping of cybersecurity talent to integrate into a SOC team as specialists in advanced detection to strengthen Threat Hunting and Detection Engineering capabilities. Responsibilities Development of detection rules (Sigma,... 
    Remote work

    Babel Inc

    United States
    5 days ago
  •  ...experienced Information Security SOC Engineer to enhance security operations. This hands...  ..., operating, and automating detection and response capabilities utilizing Microsoft Sentinel...  ...building automation workflows to improve incident response. #J-18808-Ljbffr Harris Health... 

    Harris Health System, Inc.

    Bellaire, TX
    5 days ago
  • A leading defense contractor in Virginia is seeking a Cybersecurity Engineer to enhance IT systems security for government contracts. The role involves monitoring security status, investigating incidents, and applying advanced cybersecurity knowledge. Candidates must possess... 
    For contractors

    Leidos

    Fairfax, VA
    4 days ago
  • $112k - $139k

    A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and responding to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in... 
    Work at office

    Benesch, Friedlander, Coplan & Aronoff

    Chicago, IL
    2 days ago
  • $40 per hour

     ...looking for experienced cybersecurity professionals to join...  ...reason about real-world threats and defenses. Cybersecurity...  ..., and New Zealand Responsibilities Evaluate AI-generated cybersecurity...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Annapolis, MD
    2 days ago
  •  ...Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles...  ...Security Operations and Incident Response teams to...  ...Education: Bachelor's degree in Cybersecurity or equivalent...  ...vulnerability scanning, threat hunting, network monitoring... 
    Long term contract

    InterSources

    Seattle, WA
    2 days ago
  • An innovative startup is seeking a cybersecurity expert to join their team in Seattle....  ...industrial cybersecurity. You will be responsible for developing detection strategies and analyzing network traffic to protect against cyber threats. With competitive compensation and... 

    Galvanick

    Seattle, WA
    4 days ago
  •  ...0 biopharma. ROLE OVERVIEW As a Detection and Response Engineer at Benchling you’ll be joining a team...  ...deploying and maintaining high signal threat detections based on your...  ...TTPs. Architecting a highly scalable incident response process by developing, applying... 
    Temporary work
    Local area
    Remote work

    Benchling

    Richmond, VA
    2 days ago
  •  ...Senior Threat Detection Engineer Job Category: Information Technology Location...  ...detection engineers, and incident responders who are...  ...analytics, and develop automated response capabilities to...  ...• Bachelor’s Degree in Cybersecurity, Computer Science, Data Science... 
    Work experience placement
    Remote work
    Flexible hours

    Pegasystems

    United States
    3 days ago
  •  ...Job Responsibilities Incident Investigation: Lead investigations into high-severity threats, identifying root causes to prevent...  ...conduct threat hunting to detect malicious activity....  ...3–5+ years in cybersecurity, SOC analysis, or system engineering. Technical Skills: Proficiency... 
    Immediate start

    True Zero Technologies, LLC

    New York, NY
    5 days ago
  •  ...Develop and Implement Custom Detections: Design, develop, and maintain...  ..., Endpoint Detection and Response (EDR) platforms, and...  ...identify both known and emerging threats effectively. Translate complex...  ...corrective measures to prevent future incidents. Proactively conduct... 
    Local area
    Remote work
    Night shift

    Unisys

    United States
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cybersecurity Engineer - Incident Response & Threat Detection. Be the first to apply!