Cybersecurity Engineer - Incident Response & Threat Detection
Fragomen Worldwide
Cyber Security Engineer
Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team.
Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and security is critical to its success. We are seeking a professional who is passionate about protecting the organization, capable of leading response efforts during security incidents, and eager to mature enterprise-wide incident detection, investigation, and response capabilities.
You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in detecting, investigating, containing, and remediating cyber incidents, while helping to strengthen Fragomen's overall security posture.
How Will You Make a Difference at Fragomen?
As a Security Engineer focused on Incident Response, you will:
- Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
- Monitor, investigate, and correlate security alerts using SIEM, EDR, and forensic tools.
- Perform digital forensic investigations across endpoints, servers, cloud, and network environments.
- Triage and escalate security events in accordance with established incident response procedures.
- Develop, maintain, and continuously improve incident response playbooks, SOPs, and workflows.
- Improve alert quality and response effectiveness through root cause analysis and post-incident reviews.
- Partner with IT, Legal, Compliance, Privacy, and Risk teams during security incidents.
- Support regulatory, legal, and client-driven incident response and reporting requirements.
- Participate in and facilitate incident response tabletop exercises and simulations.
- Contribute to the design and enhancement of detection, logging, and monitoring capabilities.
- Provide technical guidance and mentorship to junior analysts and security team members.
Required Qualifications
- 1+ years of experience in cybersecurity, incident response, or security operations.
- Hands-on experience responding to security incidents in enterprise environments.
- Strong ability to analyze security events and perform technical investigations.
- Working knowledge of:
- TCP/IP, DNS, VPNs, firewalls, and proxy technologies
- Windows and Linux operating systems
- Identity and access systems and authentication mechanisms
- Experience using SIEM and security platforms such as:
- Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar
- Ability to identify and respond to:
- Phishing and business email compromise
- Malware and ransomware
- Credential compromise
- Lateral movement and persistence mechanisms
- Brute-force and privilege escalation attacks
- Strong written and verbal communication skills, especially during high-pressure incidents.
- Demonstrated ability to follow structured processes while continuously improving them.
Preferred Qualifications
- Experience with EDR, SOAR, and forensic tooling (e.g., CrowdStrike, Defender, Carbon Black, EnCase, Velociraptor, etc.).
- Experience supporting investigations involving legal, compliance, or regulatory stakeholders.
- Knowledge of MITRE ATT&CK and modern adversary tactics.
- Experience with cloud and SaaS incident response (Azure, M365, AWS, etc.).
- Relevant certifications, including:
- GIAC (GCIH, GCFA, GCIA)
- Offensive Security (OSCP, OSCE, OSEE)
- Vendor certifications (Splunk, Sentinel, CrowdStrike, etc.)
All offers and/or employment contracts are contingent upon the successful completion of the Firm's pre-employment screening process. This process may include verifying the candidate's identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI-assisted tools for administrative screening purposes only - never for decision-making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.
- ...Mobility Tech Solutions LLC is seeking a Cyber Security Engineer to join its Information Security & Cyber Security... ...ideal candidate will have strong experience in incident response, digital forensics, and threat detection, ensuring robust security measures across...Suggested
- ...Job Description The Cybersecurity Incident Response (IR) Lead and Detection is responsible for the dual mission of advanced threat detection capabilities and leading the charge... ...KEY RESPONSIBILITIES: Detection Engineering (the "Hunt) Advanced Logic Development...Suggested
$103k - $128k
...law firm in Cleveland is seeking a SOC/Incident Report Engineer to strengthen their cybersecurity measures. In this role, you will detect and respond to cybersecurity incidents,... ...position requires 3-7 years of SOC or incident response experience, and familiarity with tools...Suggested$97k - $112k
Infleqtion is seeking a cybersecurity professional for a full-time role based in Louisville, CO. This position involves protecting systems and data from cyber threats while monitoring security incidents. The ideal candidate should have a Bachelor's in a relevant field,...SuggestedFull time- ...Threat Detection And Response Engineer Thought Machine's mission is bold – to properly and permanently rid the world's banks of legacy technology... ...Develop, integrate, and operate security event detection and incident management services. Automate repeatable incident...SuggestedRemote work
$135k - $216k
...Forensic And Incident Response Engineer **Position is Contingent Upon Award** Peraton... ...working alongside leaders in cybersecurity engineering, operations, forensics, threat analysis, data science, and... ...you will be responsible for detecting, investigating, and...Contract workRemote workShift work$55.7k - $82.1k
...The Cybersecurity Incident Response Engineer, Jr. monitors enterprise security tools and logs to detect, analyze, and triage potential cybersecurity threats targeting mission-critical systems and data. The role performs initial investigations, distinguishes false positives...Contract workWork at officeShift work- ...Senior Cybersecurity Engineer Opportunity to work in a hybrid model: Potential... ..., including Engineering, Threat Intelligence, Vulnerability Management, Incident Response, Firewall, Governance, Risk,... ...engineered security controls and detection mechanisms aligned with...Work experience placementWork at officeLocal areaRemote workFlexible hours
$146k - $184k
...Senior Threat Detection and Response Engineer At CarGurus, our mission is to give people the power to reach... ...our first line of defense against cybersecurity threats in a complex and evolving... ..., and efficient querying during incidents. Apply an engineering mindset to...Flexible hours$115k - $165k
...space environment and counter threats from the ultimate high... ...YOUR MISSION As a Threat Detection & Response Engineer III, you will be an... ...capabilities, sharpen our incident response procedures, and contribute... ...3+ years of experience in cybersecurity, with at least 2 years...Permanent employmentWork at office- ...Cybersecurity Incident Response Engineer, Mid The Cybersecurity Incident Response Engineer, Mid supports the detection, containment, and recovery of cybersecurity incidents across enterprise... ...and application teams to contain threats while preserving evidence and minimizing...Contract workWork experience placementWork at officeRemote work
- ...Threat Detection Engineer TENEX is an AI-native, automation-first, built-for... ...Managed Detection and Response (MDR) provider. We are a force... ...enhance their cybersecurity posture through advanced threat... ...malicious activity, security incidents, and policy violations....Remote work
$116k - $145k
...Threat Detection and Response Engineer II CarGurus is looking for a Security Engineer II to add to our... ...our first line of defense against cybersecurity threats in a complex and evolving... ...models, and efficient querying during incidents. Develop high-fidelity, rule-...$80.2k - $111.3k
...Position Overview The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts... ...deep technical focus on threat containment and eradication. It also... ...organization's ability to prevent, detect, and rapidly respond to sophisticated...Contract workWork experience placementWork at office- ...law firm based in Columbus is seeking a SOC/Incident Response Engineer to bolster its cybersecurity efforts. This hybrid position involves monitoring security threats, conducting incident responses, and improving detection capabilities. The ideal candidate should have...
$115k - $125k
A cybersecurity firm is seeking an Engineer II - Cyber Incident Response in Carrollton, TX. The role focuses on detecting, investigating, and responding to cybersecurity incidents to protect digital assets against threats. Candidates should have 2-5 years of experience...- A cybersecurity firm in San Antonio is seeking a Threat Intelligence and Detection Engineer. This position involves providing consultancy services to mitigate cybersecurity... ..., with skills in digital forensics and incident response. The firm offers competitive benefits,...Flexible hours
$89.01k - $142.19k
...insight and research into new threats, exploits, and mitigation... ...an innovator in threat detection? About the Role You will... ...senior most technical member of incident response team for our global... ...techniques, malware reverse engineering, threat analysis, and security...Local areaRemote workWork from home$260k - $405k
A leading AI research organization is seeking a mid-level to senior Security Engineer specialized in Insider Threat Detection & Response. This role involves innovating infrastructure for security, developing detection rules, and managing insider threats. Ideal candidates...Remote work- ...write together. We are starting the mapping of cybersecurity talent to integrate into a SOC team as specialists in advanced detection to strengthen Threat Hunting and Detection Engineering capabilities. Responsibilities Development of detection rules (Sigma,...Remote work
- ...experienced Information Security SOC Engineer to enhance security operations. This hands... ..., operating, and automating detection and response capabilities utilizing Microsoft Sentinel... ...building automation workflows to improve incident response. #J-18808-Ljbffr Harris Health...
- A leading defense contractor in Virginia is seeking a Cybersecurity Engineer to enhance IT systems security for government contracts. The role involves monitoring security status, investigating incidents, and applying advanced cybersecurity knowledge. Candidates must possess...For contractors
$112k - $139k
A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and responding to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in...Work at office$40 per hour
...looking for experienced cybersecurity professionals to join... ...reason about real-world threats and defenses. Cybersecurity... ..., and New Zealand Responsibilities Evaluate AI-generated cybersecurity... ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis...Hourly payFull timePart timeRemote work- ...Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles... ...Security Operations and Incident Response teams to... ...Education: Bachelor's degree in Cybersecurity or equivalent... ...vulnerability scanning, threat hunting, network monitoring...Long term contract
- An innovative startup is seeking a cybersecurity expert to join their team in Seattle.... ...industrial cybersecurity. You will be responsible for developing detection strategies and analyzing network traffic to protect against cyber threats. With competitive compensation and...
- ...0 biopharma. ROLE OVERVIEW As a Detection and Response Engineer at Benchling you’ll be joining a team... ...deploying and maintaining high signal threat detections based on your... ...TTPs. Architecting a highly scalable incident response process by developing, applying...Temporary workLocal areaRemote work
- ...Senior Threat Detection Engineer Job Category: Information Technology Location... ...detection engineers, and incident responders who are... ...analytics, and develop automated response capabilities to... ...• Bachelor’s Degree in Cybersecurity, Computer Science, Data Science...Work experience placementRemote workFlexible hours
- ...Job Responsibilities Incident Investigation: Lead investigations into high-severity threats, identifying root causes to prevent... ...conduct threat hunting to detect malicious activity.... ...3–5+ years in cybersecurity, SOC analysis, or system engineering. Technical Skills: Proficiency...Immediate start
- ...Develop and Implement Custom Detections: Design, develop, and maintain... ..., Endpoint Detection and Response (EDR) platforms, and... ...identify both known and emerging threats effectively. Translate complex... ...corrective measures to prevent future incidents. Proactively conduct...Local areaRemote workNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity Engineer - Incident Response & Threat Detection. Be the first to apply!
- entry level cyber security United States
- cyber security United States
- junior cyber security United States
- remote cyber security United States
- cybersecurity software engineer United States
- cyber security incident responder United States
- cybersecurity technical writer United States
- no experience cyber security United States
- cyber security intern United States
- senior cybersecurity engineer United States

