Engineer - Security Operations and Incident Response
Pearl Consulting Group
Job Title: Engineer - Security Operations and Incident Response
Location: USA or Canada (Remote or Hybrid)
Description
This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.
Primary Responsibilities
- Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
- Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
- Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
- Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
- Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
- Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
- Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
- Review and tune threat intelligence systems, including brand protection and dark web monitoring.
- Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
- Support IR leadership as backup on IR-related activities.
Qualifications
- Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
- In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
- Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
- Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
- Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
- Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
- Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.
- ...to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation... ...of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in...OperationsFull timeRemote work
- ...Continuous Improvement and Accountability define who we are and how we work. Join us! POSITION SUMMARY The Security Engineer – Security Operations & Incident Response is responsible for monitoring, triaging, and investigating security events across AirLife’s global...Operations
- ...productivity without compromising security by ensuring every identity is authentic... ...future. As a Staff Security Engineer on Security Incident Response, you'll serve as a senior technical... ...or agentic automation for security operations (triage, investigation, containment...OperationsFull timeImmediate startRemote work
- ...Threat Analyst to support a U.S. Government customer with onsite incident response. You will investigate breaches, compose mitigation steps,... ...and 2+ years in cyber incident management or cybersecurity operations. This role is based in Sterling, VA with possible shift work...OperationsShift work
- Cyber Incident Response Analyst Location: Austin OR San Antonio, TX - Hybrid Candidates must reside... .... • Support multi-agency response operations, including SLTT partners and critical... ...and ticketing systems. 4 - Preferred - Security Certifications Preferred (CISSP, CIH,...Operations
- ...Job Description Overview The Cyber Incident Response Analyst role is pivotal in reinforcing... ...and related information requests. Operating within the client’s 24x7 Operations Center... ...a related discipline such as Homeland Security or Business, or a combination of...OperationsTemporary workWork at officeLocal areaFlexible hoursShift work
$75.2k - $158.1k
Job Title: Cyber Incident Response AnalystJob Category: Information TechnologyTime Type: Full... ...Response Analyst that will join the Cyber Security Incident Response Team (IRT)... ..., and maintain cybersecurity Standard Operating Procedures (SOPs) and incident response...OperationsContract workWork experience placementLocal areaFlexible hoursShift work$70k - $98k
...months of employment Understanding of cybersecurity principles, incident detection, and response methodologies Familiarity with various operating systems, network protocols, and enterprise security technologies Knowledge of threat intelligence application and...OperationsFull timeShift workDay shift- ...powershell Cybersecurity SIEM Cybersecurity Incident Response Analyst Job Description: The... ...responsible for real-time threat detection, security event monitoring, triaging, and... ...cloud, and endpoint infrastructures. Operating as a core member of the Security Operations...OperationsFull time
- Title: Cyber Security Specialist - Incident Response & Forensics Location: New York, NY 10004 Duration: 12 Months... ...group within the Cyber Security Operations Center and will be expected to... ...Threat Readiness o Cyber Content Engineering & Automation Skills: Excellent communication...OperationsContract work
$102k - $123k
...Summary This is a hands-on security position working within the... ..., Threat Hunting, and Incident Response. You will be a key part of... ...global environment Design, engineer, and implement runbooks and... ...understanding of the fundamental operations of servers, operating...OperationsPermanent employmentWork at officeLocal area$190k - $260k
Senior Incident Response & Digital Forensics Analyst Location New York Business Area... ...Description & Requirements Cyber Security Operations Center — Threat Hunting,... ...cyber threats. Working closely with Engineering, Legal, Compliance, and other teams...OperationsTemporary workFor contractorsWork experience placementImmediate startRemote workShift work- We are currently seeking a Senior Cyber Incident Response Engineer as part of our Enterprise Information Security department. Enterprise Information Security (EIS) is... ...integrated with the Enterprise Technology and Operations division (1100+ technical people) at Zions Bancorporation...OperationsWork at officeWork from homeFlexible hours3 days per week
- ...Hollstadt Consulting is seeking a Junior Cybersecurity Analyst to support our Information Security Operations team in Minneapolis. You will monitor alerts, triage incidents, and respond to security requests while collaborating with IT staff to resolve issues. Ideal...Operations
$159.3k - $202.4k
Amazon's Security team is looking for a Security Incident Response Analyst to detect, investigate, and respond to threats... ...in the trenches with detection engineers, SOC analysts, forensics, and... ...retail, entertainment, healthcare, operations, and physical stores.Inclusive...OperationsFlexible hours- Claytoncountyga is looking for a Cybersecurity Operations Analyst to design and manage security solutions, summarize trends, and implement processes that... ...collaboration with various stakeholders to resolve security incidents and ensure safe access to all systems. Minimum...Operations
- ...AnaVation is seeking a Cyber Security SME to oversee defense and monitoring across enterprise... ...have TS/SCI with CI Poly, 7+ years in CND/incident response, Tableau experience, and a track record of leadership in cross-functional cyber operations. #J-18808-Ljbffr Jobleads-USOperations
- ...Ripple Inc. is seeking a Senior Security Engineer to join the Security Operations team in San Francisco. You will design, implement, and tune detections, lead high‑severity incident responses, and build automation to scale threat detection and response across our environment...Operations
- ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland... ...Work Model: Hybrid Hours: 40.0 Security Clearance: Public Trust Responsibilities... ...documentation and contribute to operational metrics and reporting. Participate...OperationsLocal area
- ...Job Description The Senior Security Engineer will support day-to-day Security Operations, with a focus on investigating... ...responding to complex security incidents. This person will lead containment... ...investigations, and incident response Hands-on experience investigating...OperationsContract workLocal areaRelocation
- ...Burbank, CA Our client has an opportunity for a Security Engineer, Incident Response on an initial 3-month contract with expected extensions... ...candidate has experience in incident response, security operations, digital forensics, or threat hunting and can assess third...OperationsHourly payFull timeContract workLocal area
$120k - $140k
DescriptionThe Cyber Detection and Response Analyst supports day-to-day... ..., working closely with Security Engineering and broader security... ...and identity systems.Support incident response activities including... ...on incident response, SOC operations, or cyber defense. Hands-on...OperationsFull timeWork at officeRemote workFlexible hoursShift work$98.9k - $164.9k
...Cyber Threat Detection & Response AnalystLocation:... ...and supporting detection engineering and response enablement... ...support alert triage and incident response, and maintain... ...and follows established security policies, standards, and standard operating procedures. The engineer...OperationsFull timeInternship- ...in a high-growth, entrepreneurial environment, we'd love to have you on board! Position Overview As our IT/OT Security Engineer & Incident Response Lead, you'll be a hands-on security engineer who also leads incidents during business hours across our corporate,...Full timeRemote work
- ..., career and customer-oriented Cyber Incident Response Analyst to join our team in McLean,... ...Diploma and 3+ years' experience in cyber security ~2+ years’ experience with incident... ...methodologies. ~ Knowledge of operating systems, network protocols, and security...Shift workNight shiftDay shiftAfternoon shift
$77.12k - $147.39k
...to achieve financial security through highly competitive... ...Monitoring & Response Analyst - Mid Level is... ...help safeguard USAA's operations, members, employees,... ...responding to cyber incidents, performing moderately... ...Security Architecture and Engineering, Communications and...OperationsFull timeH1bWork at officeRemote workHome officeRelocation packageFlexible hoursShift work- ...Samsara Inc. is hiring for a Security Incident Response role within the Security Operations Team. You will monitor security events, lead incidents as Incident Commander, and drive digital investigations influencing Employee Relations, Legal, Compliance, or Information...OperationsRemote jobFlexible hours
- ...Incident Response and Digital Forensics Expert is a remote review track for evaluating AI outputs across incident response and digital forensics specialist operations workflows. Reviewers grade workflow correctness, policy adherence, and stakeholder fit; flag operational...OperationsRemote jobHourly payFor contractorsWork experience placement10 hours per week
- ...Security SpecialistMirazon is a scaling, people-centered IT company... ...starts long before an incident occurs, and that calm, capable... ...as you are leading incident response efforts in real time. You bring... ...budget guidanceAssist sales/engineering with scoping security...Full time
- Forensic Focus is seeking a Digital Forensics specialist to support a 24x7 SOC and incident response team. You will conduct forensic imaging, collect evidence, analyze artifacts, and maintain rigorous chain-of-custody across Windows, Linux, macOS, and cloud environments...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Engineer - Security Operations and Incident Response. Be the first to apply!
- cyber security operations analyst United States
- cyber security analyst internship United States
- information security consultant United States
- cyber security business analyst United States
- entry level cyber security analyst United States
- cyber security analyst no experience United States
- junior cyber security analyst United States
- cyber security analyst United States
- remote cyber security analyst United States
- cannabis operations United States




