Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Engineer - Security Operations and Incident Response

Temporary

Pearl Consulting Group

Job Title:  Engineer - Security Operations and Incident Response 

Location:  USA or Canada (Remote or Hybrid) 

Description

This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.

Primary Responsibilities

  • Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
  • Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
  • Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
  • Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
  • Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
  • Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
  • Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
  • Review and tune threat intelligence systems, including brand protection and dark web monitoring.
  • Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
  • Support IR leadership as backup on IR-related activities.

Qualifications

  • Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
  • In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
  • Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
  • Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
  • Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
  • Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
  • Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.

Vacancy posted 27 days ago
Similar jobs that could be interesting for youBased on the Engineer - Security Operations and Incident Response in United States vacancy
  •  ...to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation...  ...of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in... 
    Operations
    Full time
    Remote work

    GitLab

    Remote
    8 days ago
  •  ...Continuous Improvement and Accountability define who we are and how we work. Join us! POSITION SUMMARY The Security Engineer – Security Operations & Incident Response is responsible for monitoring, triaging, and investigating security events across AirLife’s global... 
    Operations

    AirLife

    Grand Rapids, MI
    a month ago
  •  ...productivity without compromising security by ensuring every identity is authentic...  ...future. As a Staff Security Engineer on Security Incident Response, you'll serve as a senior technical...  ...or agentic automation for security operations (triage, investigation, containment... 
    Operations
    Full time
    Immediate start
    Remote work

    1password

    Remote
    22 days ago
  •  ...Threat Analyst to support a U.S. Government customer with onsite incident response. You will investigate breaches, compose mitigation steps,...  ...and 2+ years in cyber incident management or cybersecurity operations. This role is based in Sterling, VA with possible shift work... 
    Operations
    Shift work

    Nightwing Intelligence Solutions, LLC

    Sterling, VA
    2 days ago
  • Cyber Incident Response Analyst Location: Austin OR San Antonio, TX - Hybrid Candidates must reside...  .... • Support multi-agency response operations, including SLTT partners and critical...  ...and ticketing systems. 4 - Preferred - Security Certifications Preferred (CISSP, CIH,... 
    Operations

    RIT Solutions

    Austin, TX
    3 days ago
  •  ...Job Description Overview The Cyber Incident Response Analyst role is pivotal in reinforcing...  ...and related information requests. Operating within the client’s 24x7 Operations Center...  ...a related discipline such as Homeland Security or Business, or a combination of... 
    Operations
    Temporary work
    Work at office
    Local area
    Flexible hours
    Shift work

    Cayuse Holdings

    Washington DC
    a month ago
  • $75.2k - $158.1k

    Job Title: Cyber Incident Response AnalystJob Category: Information TechnologyTime Type: Full...  ...Response Analyst that will join the Cyber Security Incident Response Team (IRT)...  ..., and maintain cybersecurity Standard Operating Procedures (SOPs) and incident response... 
    Operations
    Contract work
    Work experience placement
    Local area
    Flexible hours
    Shift work

    CACI International Inc.

    Hampton, VA
    6 days ago
  • $70k - $98k

     ...months of employment Understanding of cybersecurity principles, incident detection, and response methodologies Familiarity with various operating systems, network protocols, and enterprise security technologies Knowledge of threat intelligence application and... 
    Operations
    Full time
    Shift work
    Day shift

    MANTECH

    McLean, VA
    a month ago
  •  ...powershell Cybersecurity SIEM Cybersecurity Incident Response Analyst Job Description: The...  ...responsible for real-time threat detection, security event monitoring, triaging, and...  ...cloud, and endpoint infrastructures. Operating as a core member of the Security Operations... 
    Operations
    Full time

    myBridge Corporation

    Brooklyn, NY
    4 days ago
  • Title: Cyber Security Specialist - Incident Response & Forensics Location: New York, NY 10004 Duration: 12 Months...  ...group within the Cyber Security Operations Center and will be expected to...  ...Threat Readiness o Cyber Content Engineering & Automation Skills: Excellent communication... 
    Operations
    Contract work

    InterSources

    New York, NY
    6 days ago
  • $102k - $123k

     ...Summary This is a hands-on security position working within the...  ..., Threat Hunting, and Incident Response. You will be a key part of...  ...global environment Design, engineer, and implement runbooks and...  ...understanding of the fundamental operations of servers, operating... 
    Operations
    Permanent employment
    Work at office
    Local area

    Caa Executive Search

    Los Angeles, CA
    2 days ago
  • $190k - $260k

    Senior Incident Response & Digital Forensics Analyst Location New York Business Area...  ...Description & Requirements Cyber Security Operations Center — Threat Hunting,...  ...cyber threats. Working closely with Engineering, Legal, Compliance, and other teams... 
    Operations
    Temporary work
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Shift work

    Bloomberg

    New York, NY
    2 days ago
  • We are currently seeking a Senior Cyber Incident Response Engineer as part of our Enterprise Information Security department. Enterprise Information Security (EIS) is...  ...integrated with the Enterprise Technology and Operations division (1100+ technical people) at Zions Bancorporation... 
    Operations
    Work at office
    Work from home
    Flexible hours
    3 days per week

    Zions Bancorporation

    Midvale, UT
    1 day ago
  •  ...Hollstadt Consulting is seeking a Junior Cybersecurity Analyst to support our Information Security Operations team in Minneapolis. You will monitor alerts, triage incidents, and respond to security requests while collaborating with IT staff to resolve issues. Ideal... 
    Operations

    Jobleads-US

    Minneapolis, MN
    2 days ago
  • $159.3k - $202.4k

    Amazon's Security team is looking for a Security Incident Response Analyst to detect, investigate, and respond to threats...  ...in the trenches with detection engineers, SOC analysts, forensics, and...  ...retail, entertainment, healthcare, operations, and physical stores.Inclusive... 
    Operations
    Flexible hours

    Amazon

    Herndon, VA
    1 day ago
  • Claytoncountyga is looking for a Cybersecurity Operations Analyst to design and manage security solutions, summarize trends, and implement processes that...  ...collaboration with various stakeholders to resolve security incidents and ensure safe access to all systems. Minimum... 
    Operations

    Claytoncountyga

    New York, NY
    3 days ago
  •  ...AnaVation is seeking a Cyber Security SME to oversee defense and monitoring across enterprise...  ...have TS/SCI with CI Poly, 7+ years in CND/incident response, Tableau experience, and a track record of leadership in cross-functional cyber operations. #J-18808-Ljbffr Jobleads-US
    Operations

    Jobleads-US

    Bethesda, MD
    2 days ago
  •  ...Ripple Inc. is seeking a Senior Security Engineer to join the Security Operations team in San Francisco. You will design, implement, and tune detections, lead high‑severity incident responses, and build automation to scale threat detection and response across our environment... 
    Operations

    Jobleads-US

    San Francisco, CA
    3 days ago
  •  ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland...  ...Work Model: Hybrid Hours: 40.0 Security Clearance: Public Trust Responsibilities...  ...documentation and contribute to operational metrics and reporting. Participate... 
    Operations
    Local area

    System One

    Bethesda, MD
    5 days ago
  •  ...Job Description The Senior Security Engineer will support day-to-day Security Operations, with a focus on investigating...  ...responding to complex security incidents. This person will lead containment...  ...investigations, and incident response Hands-on experience investigating... 
    Operations
    Contract work
    Local area
    Relocation

    Apidel Technologies

    Blue Ash, OH
    8 days ago
  •  ...Burbank, CA   Our client has an opportunity for a Security Engineer, Incident Response on an initial 3-month contract with expected extensions...  ...candidate has experience in incident response, security operations, digital forensics, or threat hunting and can assess third... 
    Operations
    Hourly pay
    Full time
    Contract work
    Local area

    Eliassen Group

    Burbank, CA
    18 days ago
  • $120k - $140k

    DescriptionThe Cyber Detection and Response Analyst supports day-to-day...  ..., working closely with Security Engineering and broader security...  ...and identity systems.Support incident response activities including...  ...on incident response, SOC operations, or cyber defense. Hands-on... 
    Operations
    Full time
    Work at office
    Remote work
    Flexible hours
    Shift work

    Control Risks

    San Francisco, CA
    4 days ago
  • $98.9k - $164.9k

     ...Cyber Threat Detection & Response AnalystLocation:...  ...and supporting detection engineering and response enablement...  ...support alert triage and incident response, and maintain...  ...and follows established security policies, standards, and standard operating procedures. The engineer... 
    Operations
    Full time
    Internship

    McKesson

    Richmond, VA
    2 days ago
  •  ...in a high-growth, entrepreneurial environment, we'd love to have you on board! Position Overview As our IT/OT Security Engineer & Incident Response Lead, you'll be a hands-on security engineer who also leads incidents during business hours across our corporate,... 
    Full time
    Remote work

    1440 Foods Manufacturing

    Remote
    a month ago
  •  ..., career and customer-oriented Cyber Incident Response Analyst to join our team in McLean,...  ...Diploma and 3+ years' experience in cyber security ~2+ years’ experience with incident...  ...methodologies. ~ Knowledge of operating systems, network protocols, and security... 
    Shift work
    Night shift
    Day shift
    Afternoon shift

    ManTech

    McLean, VA
    2 days ago
  • $77.12k - $147.39k

     ...to achieve financial security through highly competitive...  ...Monitoring & Response Analyst - Mid Level is...  ...help safeguard USAA's operations, members, employees,...  ...responding to cyber incidents, performing moderately...  ...Security Architecture and Engineering, Communications and... 
    Operations
    Full time
    H1b
    Work at office
    Remote work
    Home office
    Relocation package
    Flexible hours
    Shift work

    USAA - United Services Automobile Association

    San Antonio, TX
    4 days ago
  •  ...Samsara Inc. is hiring for a Security Incident Response role within the Security Operations Team. You will monitor security events, lead incidents as Incident Commander, and drive digital investigations influencing Employee Relations, Legal, Compliance, or Information... 
    Operations
    Remote job
    Flexible hours

    Jobleads-US

    Portland, OR
    2 days ago
  •  ...Incident Response and Digital Forensics Expert is a remote review track for evaluating AI outputs across incident response and digital forensics specialist operations workflows. Reviewers grade workflow correctness, policy adherence, and stakeholder fit; flag operational... 
    Operations
    Remote job
    Hourly pay
    For contractors
    Work experience placement
    10 hours per week

    AuraOne Human Data

    Remote
    12 days ago
  •  ...Security SpecialistMirazon is a scaling, people-centered IT company...  ...starts long before an incident occurs, and that calm, capable...  ...as you are leading incident response efforts in real time. You bring...  ...budget guidanceAssist sales/engineering with scoping security... 
    Full time

    Mirazon

    Louisville, KY
    2 days ago
  • Forensic Focus is seeking a Digital Forensics specialist to support a 24x7 SOC and incident response team. You will conduct forensic imaging, collect evidence, analyze artifacts, and maintain rigorous chain-of-custody across Windows, Linux, macOS, and cloud environments... 

    Forensic Focus

    Bethesda, MD
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Engineer - Security Operations and Incident Response. Be the first to apply!