Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Incident Response Principal Engineer

$130k
Full-time

Gennte Technologies

Hiring Partners We currently have an open position for Cyber Incident Response Principal Engineer role in USA. I would like to request your support in souring suitable and qualified profiles for this role as per the below details.

Position Description: Cyber Incident Response Principal Engineer (Area Cybersecurity)

No. of positions - 1

Location : Remote, US (EST time preferred)

Salary Range $130k

Role Description

Bring deep Incident Response (IR) experience plus strong engineering capability to design, build and evolve IR automation and orchestration that improves speed and consistency of containment, analysis, and mitigation. A key focus is applying AI/ML and modern data engineering approaches to accelerate collection, triage, enrichment, investigation, and response decisioning, safely and in a controlled, auditable way.

  • Lead the continued evolution of incident response and forensic capabilities and processes, including automation and orchestration, with strong emphasis on engineering delivery.
  • Engineer and enhance security platforms by designing integrations and workflows that reduce manual IR effort and shorten time-to-contain.
  • Build and maintain automation pipelines that connect detections (use cases), enrichment, investigation steps, evidence capture, and response actions.
  • Translate incident response playbooks into automated workflows (e.g., decision trees, conditional branching, approvals, safe-guards, rollback).
  • Develop bespoke tooling/solutions to solve unique problems
  • AI for IR acceleration:

o Build AI-assisted capabilities to speed up triage and investigations (e.g., alert clustering, entity resolution, log summarisation, enrichment recommendations).

o Develop and maintain LLM-enabled analyst-assist tooling (summaries, guided investigations, draft IR reports, playbook step suggestions) with strong controls (auditability, prompt safety, data handling).

o Apply ML techniques to improve signal quality (e.g., anomaly detection, prioritisation scoring), ensuring outputs are explainable and operationally usable.

o Establish evaluation methods for AI features (precision/recall where relevant, time saved, false-positive reduction, robustness testing).

  • Support the identification, development and implementation of new detections (use cases) and ensure engineering output is tightly coupled to detection and response outcomes.
  • Develop and define detailed processes and procedures that enable repeatable, reliable, and automated response to cyber security events.

Certifications, Qualifications & Experience:

  • Significant experience in incident response and/or computer forensics (8+ years ).
  • Strong capability in analysing attacker TTPs and converting learnings into changes across the control plane.
  • Experience with common IR/forensic tooling: EnCase, FTK, Sleuthkit, Kali Linux, Ghidra, REMnux, SANS SIFT .
  • Expert scripting/programming and proven experience delivering production-grade tools
  • Experience building integrations across enterprise security tooling, such as: SIEM/log platforms and "Big Data" / cloud-based solutions for collection and real-time analysis
  • Common security technologies: IDS/IPS/HIPS, firewalls, proxies, advanced anti-malware
  • Practical engineering experience with:
    • APIs, event-driven systems, queues/workflows, CI/CD, automated testing
    • Reliability engineering concepts (observability, error handling, rollback, audit logging)
    • Secure coding and threat modelling for IR automation.
  • Hands-on experience building and operating AI/ML solutions in production (not just experimentation), ideally in security operations contexts desirable.
  • Working knowledge of: LLM application design (RAG patterns, tool use/function calling, prompt engineering, evaluation) - Data handling controls for sensitive/security data, and safe deployment patterns (human-in-the-loop for high-impact actions; strong logging/audit trails)
  • Expert knowledge of enterprise platforms: Windows, Linux, MacOS , infrastructure management and networking hardware.
  • Expert knowledge of network protocols: TCP/UDP/DNS/DHCP/IPSEC/ and protocol analysis.
  • Cloud expertise: AWS, Azure, Google Cloud .

Qualifications

  • Security certifications : CEH, CRISC, GSEC, GCIA, CISSP .
  • Forensics/tooling certifications: GCFA/GNFA/GCFE/GCIH/CHFI , EnCE/ACE etc.
  • Degree in Information Security/Cyber-security/Computer Science (or equivalent experience).
  • (Highly desirable) Evidence of AI engineering practice: applied ML/LLM delivery, MLOps, or equivalent demonstrable experience.

Success measures

  • Reduced time to contain/mitigate via delivered automations and orchestrated workflows.
  • Increased investigation throughput and consistency (playbooks-to-automation coverage).
  • Measurable improvements from post-incident reviews translated into engineering deliverables.
  • AI-assisted capabilities that demonstrably improve speed/quality (e.g., triage time reduction, better prioritisation, improved analyst experience) with controlled risk and strong
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Incident Response Principal Engineer in California vacancy
  • $180k - $218k

    Cydecor, Inc. is seeking a Lead Cyber Mission Threat Analyst to support critical U.S. Navy cybersecurity operations in Port Hueneme...  ...in cyber operations, particularly in threat detection and incident response. The ideal candidate will lead cybersecurity efforts, conduct... 
    Cyber

    Cydecor, Inc.

    Port Hueneme, CA
    19 hours ago
  • EY is seeking a Senior Cyber Incident Response Coordinator to lead global incident response efforts and coordinate across multiple business units. You will manage complex incidents from detection through resolution, communicating with executives and legal teams as needed... 
    Cyber

    EY

    Los Angeles, CA
    4 days ago
  • $102k - $123k

     ...looking for candidates who have a passion for Cyber Security, Threat Detection, Threat Hunting, and Incident Response. You will be a key part of our efforts to build...  ...as required for a global environment Design, engineer, and implement runbooks and playbooks for Incident... 
    Cyber
    Work at office

    Creative Artists Agency

    Los Angeles, CA
    19 hours ago
  • $38.46 - $50.48 per hour

    Overview As the Incident Response Specialist, you will be responsible for managing and responding to security incidents, performing detailed...  ...You will be a critical thinker with a deep understanding of cyber threats and vulnerabilities, and a strong knowledge of IT systems... 
    Cyber
    Hourly pay
    Contract work
    Local area

    ePlus

    Irvine, CA
    1 day ago
  • $168k - $243k

     ...customer teams to investigate and contain incidents.Conduct host forensics, network...  ...and malware triage in support of incident response investigations.Lead complex client-facing...  ...Mandiant is a recognized leader in dynamic cyber defense, threat intelligence and incident... 
    Cyber
    Remote work

    Google

    Sacramento, CA
    13 hours ago
  • $165k - $210k

     ...looking for a long-term fit where you can grow in a role, and will be valued and empowered, then we invite you to apply to our Cyber Incident Response Associate Attorneyposition in our Los Angeles Office. This position offers a flexible, hybrid working arrangement.... 
    Cyber
    Part time
    Work at office
    Flexible hours

    Wilson Elser

    Bellflower, CA
    4 days ago
  • $38.46 - $50.48 per hour

     ...Overview As the Incident Response Specialist, you will be responsible for managing and responding to security incidents, performing detailed...  ...You will be a critical thinker with a deep understanding of cyber threats and vulnerabilities, and a strong knowledge of IT... 
    Cyber
    Hourly pay
    Contract work
    Local area

    ePlus Technology, inc.

    Irvine, CA
    11 hours ago
  •  ...The Incident Response Coordinator supports the end‑to‑end response to IT incidents and service disruptions, helping restore normal operations...  ...monitoring/ITSM data to route incidents; engage infra/app/cyber/vendor dependencies. Communications & Handoffs: Provide structured... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Sacramento, CA
    4 days ago
  •  ...The Incident Response Coordinator, Senior leads tactical coordination of complex IT incidents to minimize mission impact. The role facilitates...  ...governance and the Senior Incident Manager, integrates with cyber defenders when needed, and champions readiness and continual... 
    Cyber
    Contract work
    Work experience placement
    Work at office
    Shift work

    ASM Research, An Accenture Federal Services Company

    Sacramento, CA
    2 days ago
  • $102k - $123k

     ...looking for candidates who have a passion for Cyber Security, Threat Detection, Threat Hunting, and Incident Response. You will be a key part of our efforts to build...  ...activities as required for a global environment Design, engineer, and implement runbooks and playbooks for... 
    Cyber
    Permanent employment
    Work at office
    Local area

    Caa Executive Search

    Los Angeles, CA
    4 days ago
  • $118.65k - $182.71k

    10279- Manager, Security Incident Response  Location:  Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT...  ...helping strengthen organizational resilience against evolving cyber threats.    This role coordinates enterprise-wide... 
    Cyber
    Full time
    Work experience placement
    Local area

    Hyundai Autoever America

    Irvine, CA
    2 days ago
  •  ...Google LLC in Sunnyvale, CA is seeking an Software Engineering Manager for the Denial of Service Security SRE team to lead a distributed...  ...engineering group focused on proactive DoS defense and incident response. You will drive automation, threat intelligence initiatives... 

    Jobleads-US

    Sunnyvale, CA
    1 day ago
  •  ...in human history, and being responsible for the physical and logical...  ...feel small. Role Scope Lead incidents as a senior incident...  ...Operations for incidents that cross cyber, physical, and OT surfaces....  ...learnings back to detection engineering and threat intelligence.... 
    Cyber
    Local area

    Fluidstack

    San Francisco, CA
    3 days ago
  •  ...Apex Space, Inc. is seeking a Cybersecurity Lead to oversee the SOC, drive proactive threat detection, incident response, and team performance. The role reports to IT & Cybersecurity leadership and collaborates with IT and compliance to align security with business... 

    Jobleads-US

    Los Angeles, CA
    1 day ago
  •  ...Cybersecurity Lead to manage the Security Operations Center and drive proactive defenses. You will supervise SOC analysts and engineers, coordinate incident response, and align security operations with business needs. You'll apply expertise in SIEM, EDR/XDR, and threat hunting,... 

    Jobleads-US

    Los Angeles, CA
    8 hours ago
  •  ...Senior Specialist at Southern California Edison (SCE) and build a better tomorrow. In this job, you’ll serve as Cybersecurity Incident Response Team (CSIRT) Coordinator, leading the coordination of incident response activities across the enterprise, while partnering with... 
    Work at office
    Remote work
    Relocation

    Edison International

    Rosemead, CA
    3 days ago
  • $120k - $140k

    DescriptionThe Cyber Detection and Response Analyst supports day-to-day detection, investigation, and...  ...environment, working closely with Security Engineering and broader security stakeholders....  ...cloud, and identity systems.Support incident response activities including... 
    Cyber
    Full time
    Work at office
    Remote work
    Flexible hours
    Shift work

    Control Risks

    San Francisco, CA
    1 day ago
  • $163.4k - $322.1k

    Position Summary Senior Manager, Advanced Cyber Threat Response, Forensics and Technical Remediation Integration LeadDeloitte’s Cyber...  ...prepare for, respond to, and recover from cyber incidents. As a Senior Manager, Advanced Cyber Threat Response, Forensics... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    Los Angeles, CA
    1 day ago
  •  ...Athena is seeking a Head of InfoSec Operations to lead the day-to-day cybersecurity operations, monitoring, incident response, and client-facing security assurance. The role requires hands-on expertise and cross-functional collaboration across IT, DevOps, Product, Legal... 

    Jobleads-US

    Los Angeles, CA
    8 hours ago
  • $225k - $250k

     ...Magic.™ We're looking for a Principal Firmware Engineer to serve as a hands-on...  ...the world. You will be responsible for the development, review...  .... Reliability & Incident Leadership: Diagnose complex...  ...Familiarity with RED, EN 18031, the Cyber Resilience Act, secure... 
    Cyber
    Summer work
    Work at office
    Local area

    Fellow

    San Francisco, CA
    3 days ago
  • $152.3k - $165k

     ...Rocket Lab’s IT team is responsible for how our global...  ...to launch operations.PRINCIPAL CLOUD SECURITY ENGINEERBased...  ...Cloud Security Engineer must demonstrate a firm...  ...automation in pursuit of cyber team objectives.Provide...  ...matters, including incident response, compliance,... 
    Cyber
    Permanent employment
    Work experience placement
    Work at office
    Local area
    Flexible hours

    Rocket Lab

    Long Beach, CA
    1 day ago
  • $260k - $365k

     ...Job Description Job Description Cybersecurity & Incident Response Managing Associate Attorney Direct Counsel is seeking a Cybersecurity & Incident Response Managing Associate with 3–5 years of experience to join a leading global law firm and its nationally recognized... 
    Flexible hours

    Direct Counsel

    San Francisco, CA
    a month ago
  • $145k - $252k

     ...development, regulatory compliance, data protection assessments, incident response, and cyber risk management across all major markets around the world...  ...practice. This person will lead the delivery of privacy engineering engagements, bringing deep technical expertise to help... 
    Cyber
    Full time

    FTI Consulting

    Los Angeles, CA
    4 days ago
  • $163.4k - $322.1k

    Senior Manager, Advanced Cyber Threat Response, Forensics and Technical Remediation Integration Lead Deloitte's Cyber Defense & Resilience...  ...prepare for, respond to, and recover from cyber incidents. As a Senior Manager, Advanced Cyber Threat Response, Forensics... 
    Cyber
    Visa sponsorship

    Deloitte LLP

    California
    2 days ago
  •  ...Senior Specialist at Southern California Edison (SCE) and build a better tomorrow. In this job, you’llserve as Cybersecurity Incident Response Team (CSIRT) Coordinator, leading the coordination of incident response activities across the enterprise, while partnering with... 
    Work at office
    Remote work
    Relocation

    Thomson Reuters Markets Espana SL.

    Rosemead, CA
    1 day ago
  • $125.3k - $187.9k

     ...Classified Solutions team is seeking Principal Cyber Systems Engineers to support information systems and...  ...date yet to be determined. Responsibilities Perform Lab Infrastructure Design...  ...detect and respond to security incidents. Ability to work multiple shifts... 
    Cyber
    Full time
    Remote work
    Flexible hours
    Shift work

    Jobleads-US

    Edwards Air Force Base, CA
    2 days ago
  • $119.77k - $140.9k

     ...Implement and maintain backup, recovery, cyber resiliency, Safeguarded Copy, and data...  ...reliability, and risk management.Collaborate with engineering, application, infrastructure, operations...  ...skills with expertise in incident management, root cause analysis, problem... 
    Cyber
    Full time
    Work experience placement
    Local area
    3 days per week

    US Bank

    Cupertino, CA
    13 hours ago
  • $108.2k - $162.4k

    Principal Or Sr. Principal Cybersecurity Systems Engineer (CSSE) At Northrop Grumman, our employees have incredible opportunities...  ...Systems Mission Defense Cyber Team has an opening for a...  ...salary offers such as the scope and responsibilities of the position and the... 
    Cyber
    Shift work

    Northrop Grumman

    Redondo Beach, CA
    3 days ago
  • $89.4k - $155.4k

     ...differentiated battle management and Cyber ( solutions deliver timely, mission-enabling...  ...in Salt Lake City, Utah is seeking a Principal Engineer Supplier Quality (Level 3) to join the...  ...salary offers such as the scope and responsibilities of the position and the candidate's... 
    Cyber
    Full time
    Work experience placement
    Local area
    Relocation
    Shift work

    Northrop Grumman Corp. (AU)

    San Diego, CA
    4 days ago
  • $100.5k - $153.25k

     ...Description Summary The Sr. Mechanical Engineer applies engineering techniques to...  ...testing of these systems. Position Responsibilities Designs structural components, electro...  ...across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions... 
    Cyber
    Permanent employment
    Contract work
    Work experience placement

    InvestedintheMission

    Moorpark, CA
    19 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Incident Response Principal Engineer. Be the first to apply!