Engineer - Security Operations and Incident Response
Pearl Consulting Group
Job Title: Engineer - Security Operations and Incident Response
Location: USA or Canada (Remote or Hybrid)
Description
This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.
Primary Responsibilities
- Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
- Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
- Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
- Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
- Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
- Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
- Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
- Review and tune threat intelligence systems, including brand protection and dark web monitoring.
- Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
- Support IR leadership as backup on IR-related activities.
Qualifications
- Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
- In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
- Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
- Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
- Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
- Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
- Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.
$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information... ...will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers... ..., retail, entertainment, healthcare, operations, and physical stores.Work/Life Balance...OperationsInternshipFlexible hours$136k - $184k
...Hunting team is looking for a Security Engineer, Threat Hunting who is... ...selected be a US Person.Key job responsibilities- You will query big data... ...- You will work alongside incident response teams and provide... ...and enable threat hunting operations at Petabyte scale.- You...OperationsInternshipFlexible hoursShift work- ...Continuous Improvement and Accountability define who we are and how we work. Join us! POSITION SUMMARY The Security Engineer – Security Operations & Incident Response is responsible for monitoring, triaging, and investigating security events across AirLife’s global...Operations
- ...to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation... ...of this role As a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in...OperationsFull timeRemote work
- ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in United States. This role is central to strengthening and continuously evolving a global Security...OperationsFull timeRemote work
$175.1k - $236.9k
AWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadership judgment to drive a team through a fundamental... ...for a regional team of security engineers, engage directly with customer security...OperationsFlexible hoursShift work$104k - $166k
...currently seeking to hire an experienced Incident Response Analyst (ICS/OT/SCADA) for its'... ...and complexity.Support highly technical operations and forensic analysis while advising client... ...environments.Experience conducting security site assessments, including analysis of...OperationsContract workCurrently hiringShift work1 day per week$102k - $123k
...SummaryThis is a hands-on security position working within the... ...Detection, Threat Hunting, and Incident Response. You will be a key part of... ...global environment Design, engineer, and implement runbooks and... ...of the fundamental operations of servers, operating systems...OperationsPermanent employmentFull timeWork at officeLocal area$101.53k - $132.69k
...are seeking a Cybersecurity Analyst / Incident Response Coordinator to oversee incident response... ...analysis for a federal agency's IT security program. This role combines hands-on cyber... ...vulnerability management and scanning operations (e.g., Tenable) Above average...OperationsPermanent employmentFull timeContract workTemporary workWork at officeLocal area- ...young, energetic global IT-Engineering services company with... ...hearing from you! Cyber Incident Response Analyst - Tenable Chicago... ..., and respond to security incidents across enterprise... ...initiatives. Support security operations through monitoring, alert triage...OperationsLocal area
- ...Job Description Overview The Cyber Incident Response Analyst role is pivotal in reinforcing... ...and related information requests. Operating within the client’s 24x7 Operations Center... ...a related discipline such as Homeland Security or Business, or a combination of...OperationsTemporary workWork at officeLocal areaFlexible hoursShift work
- ...Services in Arlington, VA, seeks a Cybersecurity Incident Response Triage Analyst to join the CIRT team within... ...triaging, and analyzing alerts from SIEM and security sensors, coordinating with incident response and operations teams to qualify events and determine false...Operations
$143.7k - $194.4k
...company DNA. Our Software Development Engineers (SDEs) use industry-leading technology... ...impact of their work first-hand.Key job responsibilities• Collaborate with experienced cross-... ...management, build processes, testing, and operations experience- Bachelor's degree in...OperationsInternshipFlexible hours$70k - $98k
...months of employment Understanding of cybersecurity principles, incident detection, and response methodologies Familiarity with various operating systems, network protocols, and enterprise security technologies Knowledge of threat intelligence application and...OperationsFull timeShift workDay shift- ...powershell Cybersecurity SIEM Cybersecurity Incident Response Analyst Job Description: The... ...responsible for real-time threat detection, security event monitoring, triaging, and... ...cloud, and endpoint infrastructures. Operating as a core member of the Security Operations...OperationsFull time
- ...Job Title: Mid-Level Cybersecurity Incident Response Analyst Location: Bethesda, Maryland... ...Work Model: Hybrid Hours: 40.0 Security Clearance: Public Trust Responsibilities... ...documentation and contribute to operational metrics and reporting. Participate...OperationsLocal area
- ...across the globe to create, secure, and run applications that... ...individual can thrive.Security Engineer III _ Incident ResponseF5 Office of the... ...as a dedicated incident response member within F5’s Office of... ...incident response execution and operational maturity across corporate,...OperationsFull timeWork at officeLocal area
- ...across the globe to create, secure, and run applications that... ...individual can thrive.Security Engineer III - Incident ResponseOrganization: F5... ...of our Global Incident Response team. In this role, you will... ...across engineering, SRE, cloud operations, legal, and executive...OperationsFull timeWork at officeLocal area
$112.3k - $151.5k
...enabled business, our approach to security operations must evolve and grow alongside... ...We are looking for a Security Engineer with a diverse set of skills... ...as build out new detections and response workflowsProvide triage support for incident response and investigation efforts...OperationsLocal areaFlexible hours- ...to work at the highest levels possible.Job Summary: The Security Incident Response Engineer is responsible for detecting, investigating, containing... .... This role serves as a key member of the Security Operations team and works closely with Infrastructure, Cloud, Identity...OperationsFull timeImmediate startFlexible hours
- ...inquiries won't receive a response).Regular or Temporary:... ...Hunt & Respond Senior Engineer is a senior-level... ...advanced threat hunting and incident response activities.... ...collaborates with security, technology, and business... .... This role operates in a fast-paced environment...OperationsPermanent employmentFull timePart timeH1bWork at officeWork visaShift workNight shiftDay shift
- Job DescriptionThe RoleThe Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities...Full timeLocal areaWork from homeRelocation package
- Claytoncountyga is looking for a Cybersecurity Operations Analyst to design and manage security solutions, summarize trends, and implement processes that... ...collaboration with various stakeholders to resolve security incidents and ensure safe access to all systems. Minimum...Operations
$159.3k - $202.4k
Amazon's Security team is looking for a Security Incident Response Analyst to detect, investigate, and respond to threats... ...in the trenches with detection engineers, SOC analysts, forensics, and... ...retail, entertainment, healthcare, operations, and physical stores.Inclusive...OperationsFlexible hours- ...Director of Cybersecurity to execute and evolve the security program across risk, threat modeling, incident response, and governance. You will own architecture, IAM, SIEM, and tooling while partnering with IT Operations, Solutions Delivery, and Digital Innovation to bake...Operations
- Job Description: Oversees continuous security operations, threat detection, and incident response procedures across enterprise infrastructure. Executes threat hunting proactively, manages Security Information and Event Management (SIEM) telemetry, investigates breach attempts...Operations
- Amazon is looking for a focused Security Engineer who can take on a leadership role in responding to security issues across the... ...software security, malware analysis, forensics, security operations, incident response, and emergent security intelligence. An ideal candidate...Operations
- ...to work on planetary scale incident response solutions in the cloud? Are you skilled at performing Security Incident Response activities... ...and automate security operations giving them unprecedented capability... ...(Science, Technology, Engineering, Mathematics), or 2+ years...OperationsInternshipFlexible hours
- Amazon Web Services, Inc. seeks a Security Incident Response professional to lead operations and help customers build scalable threat detection and incident response capabilities in the cloud. You will work with AWS service teams to innovate and deploy secure, automated...Operations
- ...centered IT company that believes strong security starts long before an incident occurs, and that calm, capable... ...as you are leading incident response efforts in real time. You bring clarity... ...budget guidance Assist sales/engineering with scoping security engagements...Full timeTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Engineer - Security Operations and Incident Response. Be the first to apply!
- junior cyber security analyst United States
- cyber security analyst United States
- cyber security operations analyst United States
- remote cyber security analyst United States
- cyber security business analyst United States
- cyber security analyst internship United States
- information security consultant United States
- entry level cyber security analyst United States
- marketing operations United States
- hr operations United States


