SOC/Incident Report Engineer
$112k - $139kBenesch
Who We Are At Benesch we pride ourselves on exceeding expectations and building trust not only with our clients but with our employees - Benesch's #1 asset. Committed to providing not only the highest level of legal service to our clients, Benesch also aspires to create a positive work environment for our employees. Our Firm continues to earn placement on Chicago and Cleveland's Top Workplaces list, along with Cleveland's NorthCoast 99 Top Workplaces rankings. We also continue to advance on the AmLaw 150 list, placing us among the top 150 law firms in the country. Benesch is proud to be recognized for being a Firm that attracts and retains top talent - making Benesch a great place to work. We offer a hybrid schedule, career development and growth, transparent and visible leadership teams, and a place where diversity, equity and inclusion is celebrated. In addition, the Firm offers a full array of benefits which can be viewed at Working with Us - Come and "Be Benesch!" We are one of the fastest growing firms in the nation, and have offices in Chicago, Columbus, San Francisco, New York City, and Wilmington. We continue to expand our geographic footprint and value the talent that comprises each of our locations. If you are someone who champions a First in Service approach and are ready to be part of an exciting and growing Firm, we would invite you to apply to join our team. Want to know more? To hear from some of our team, click here: Benesch is proud to announce the opening for a SOC/Incident Report Engineer in our Chicago office! This position is hybrid and has work from home flexibility. Position Summary Are you excited about detecting and resolving cybersecurity threats and incidents? Do you find it a challenge to help an organization reduce threats and enhance their security? Does working with teams to develop strategies to improve detection capabilities? Then you may be interested in our SOC/Incident Report Engineer position. This role is perfect for the individual looking to play a crucial role in Benesch's security initiatives. The SOC/Incident Response Engineer is responsible for detecting, investigating, and responding to cybersecurity incidents across the Firm. This role combines threat detection, digital forensics, malware triage, and cloud security expertise to protect organizational assets, reduce risk, and strengthen security posture. The SOC/Incident Response Engineer will operate within a 24/7 security operations environment, collaborating with cross-functional teams to analyze threats, develop response strategies, and improve detection capabilities. Position Responsibilities Security Monitoring & Threat Detection Monitors SIEM, EDR, NDR, and cloud-native security tools to identify suspicious activity and potential security incidents. Creates, tunes, and optimizes detection rules, correlation logic, and analytic use cases. Conducts threat hunting based on emerging TTPs, threat intel, and anomaly patterns. Maintains and improves alerting fidelity to reduce false positives and enhance detection precision. Incident Response & Triage Performs initial triage of security alerts to assess severity, impact, and required response actions. Leads full incident lifecycle activities including investigation, containment, eradication, recovery, and post-incident analysis. Coordinates with IT, cloud, and business teams to execute IR playbooks and minimize operational impact. Documents incidents, findings, and lessons learned; contribute to after-action reviews. Digital Forensics & Malware Analysis Conducts forensic acquisition and analysis of endpoints, servers, cloud resources, and network artifacts (disk, memory, logs). Examines artifacts such as registry hives, event logs, file systems, network captures, browser history, and persistence mechanisms. Performs malware triage (dynamic and static) to determine malware behavior, indicators of compromise, and propagation mechanisms. Maintains chain-of-custody processes and ensure forensic data integrity for potential legal or compliance requirements. Cloud Security & IR Monitors and responds to security events within cloud environments (e.g., Azure, AWS, Google Cloud). Investigates cloud-native logs: Azure Activity Logs, AWS CloudTrail, GCP Audit Logs, identity events, network flows, and storage access. Evaluates cloud security posture, identifying misconfigurations, risky access patterns, and drift. Assists in development of cloud detection logic using native tooling (e.g., Azure Sentinel/Microsoft Defender XDR, AWS GuardDuty, GCP SCC). Security Tooling & Automation Maintains and enhances SOC tooling, dashboards, and automation workflows (SOAR). Builds automated playbooks to speed up triage, enrichment, and response. Integrates new data sources and improves log ingestion pipelines for SIEM/EDR. Threat Intelligence & Research Utilizes internal and external threat intelligence to contextualize alerts and strengthen detections. Tracks adversary TTPs based on frameworks such as MITRE ATT&CK. Researches emerging threats, vulnerabilities, and malware families. Collaboration, Compliance & Reporting Partners with governance, engineering, and IT teams to ensure effective remediation and long-term control improvements. Supports audit, compliance, and regulatory requirements related to incident management. Prepares clear, concise technical and executive-level reports. Key Competencies Analytical mindset with strong problem-solving skills. Ability to work under pressure during active incidents. Excellent written and verbal communication skills. Strong attention to detail and a commitment to continuous improvement. Qualifications The SOC/Incident Response (IR) Engineer should have 3–7 years of experience in a Security Operations Center (SOC), incident response, digital forensics, or a closely related cybersecurity discipline. A strong technical foundation in networking, operating system internals across Windows, Linux, and macOS, identity systems, and modern cloud architectures is essential. The role requires hands‑on experience with leading security technologies, including SIEM platforms such as Microsoft Sentinel or Splunk, endpoint detection and response (EDR) and antivirus tools like Microsoft Defender for Endpoint or CrowdStrike, and forensic toolsets including Velociraptor, Autopsy, FTK, and KAPE. Experience utilizing malware analysis sandboxes and static analysis frameworks, as well as cloud security tools such as Azure Defender, AWS GuardDuty, and Google Cloud Security Command Center (SCC), is also required. Familiarity with scripting and automation languages, particularly Python, PowerShell, and KQL, is highly desirable. Preferred certifications include GIAC GCIA, GCFA, GCIH, or GNFA; AWS Security Specialty or Google Professional Cloud Security Engineer; and industry‑recognized credentials such as CISSP, CEH, or CySA+ (or their equivalents). The salary range for this position is $112K to $139K. Please note that quoted salary ranges are based on Benesch's good faith belief at the time of the job posting and are not a guarantee of what final salary offers may be. Base pay is based on market location and may vary depending on job‑related knowledge, skills, and experience. Base pay is only one part of the Total Rewards that Benesch provides to compensate and recognize our staff professionals for their work. Full‑time positions are eligible for a discretionary bonus and a comprehensive benefits package. Benesch is an equal opportunity employer. We strongly value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability (where applicant is qualified to perform the essential functions of the job with or without reasonable accommodations), medical condition, protected veteran status, gender identity, genetic information, or any other characteristic protected by federal, state, or local law. Applicants who are interested in applying for a position and require special assistance or an accommodation during the process due to a disability should contact the Benesch Human Resources Department by phone at View phone number on click.appcast.io or email Christine Watson at View email address on click.appcast.io. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities #J-18808-Ljbffr
$112k - $139k
...A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and responding to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience...SuggestedWork at office$84.72k - $125k
...The Role The Customer Application Support Engineer will work closely with the Product... ...availability of applications. The role emphasizes incident management and response, monitoring,... ...working with SQL for querying and reporting. PostgreSQL, MySQL knowledge is a plus Messaging...Suggested- ...Ryan Specialty, LLC is seeking a SOC Analyst to enhance our Chicago team. This position involves monitoring network security, managing incidents, and developing security procedures. Candidates should have a bachelor's degree in a related field and at least one year of...SuggestedVisa sponsorship
- ...A leading tech company is seeking an experienced SOC Analyst to maintain cybersecurity posture through monitoring and incident response. Candidates should have at least 4 years of SOC experience and familiarity with EDR and SIEM tools. This role offers remote work options...SuggestedRemote work
- ...Senior Microsoft Fabric Data Engineer is responsible for architecting... ...that support advanced reporting, self-service analytics, and... ...regulatory compliance (eg., GDPR, SOC 2). Monitor and optimize system... ...practices. Support incident response and root-cause analysis...SuggestedTemporary workFlexible hours
$62k - $75k
...SummaryRyan Specialty is looking for a SOC Analyst to join our Chicago... ...issues, investigating incidents, handling tickets and... ...delivers accurate and timely reports on security incidents and resolutions... ...; Computer Science, Software Engineering, Information Technology, or...Full timeWork experience placementRemote workWork visa- ...leading IT solutions provider is seeking a Network Operations Engineer (Tier II) to join their team, focusing on maintaining and troubleshooting... ...technical degree. Responsibilities include resolving network incidents, monitoring network performance, and providing Tier 2...
- ...Protera a great place to work. Job Title- SOC Analyst Shift Timing- Rotational (24 × 7)... ...continuous monitoring, detection, and incident response. Using advanced technologies such... ...risks and ensure secure baselines. Track and report on vulnerability remediation metrics....Remote workWork from homeShift work
- U.S. Forensic is seeking a Professional Engineer specializing in Structural Forensics based in Chicago, IL. This role involves investigating... ...defects, performing site inspections, and preparing technical reports. A strong background in structural engineering and the ability...Full time
$75k - $80k
...distributing detailed Daily Construction Reports (DCRs) Attend weekly trade partner... ...corrections Report same day accident / incident to Director of Field Operations, Safety... ...Bachelor's degree in Construction Management, Engineering, or similar program or relative...For contractorsFor subcontractorInternshipLocal area$84.9k - $104k
...JOB DESCRIPTION JOB TITLE: Chief Building Engineer LOCATION/DEPT: Harbor Light REPORTS TO: Executive Director PEOPLE MANAGER : Yes... ...bus stops, fences, and light poles. # Report any incidents, which may include photographs and a written account...For contractorsWork at officeWeekend work$50k - $65k
...Job Description Job Description Reports to: Manager, SOC Support Location: Remote US Compensation... ...phone, email, and chat for Huntress incident reports, escalations, and SIEM-... ...move through investigation and engineering. Embraces change and excels in evolving...Full timeRemote workWorldwideHome office- ...Summary We are looking for a SOC Analyst to join our Chicago team... ...issues, investigates incidents, handles tickets, and documents... ...and deliver security incident reports and recommend improvements. Stay... ...Computer Science, Software Engineering, Information Technology, or related...Work experience placementRemote workVisa sponsorship
- ...The Controls Engineer in the After Sales Department within the Operations Department is... ...they are completed properly and on time, reporting deviations to the After Sales Manager. Track and report issues and tickets (incidents, improvements, preventive maintenance)....Immediate startRemote workFlexible hours
$27 - $31 per hour
...Pay range: $27 - $31 per hour The Assistant Building Engineer maintains all Park District facilities, oversees construction... ...training and coaching staff, promptly investigating and reporting accidents/incidents, and proactively addressing hazards in the workplace....Hourly payFull timeFor contractorsWork experience placementSeasonal workFlexible hoursWeekend work- ...Job Title : JAMS Automation Engineer Experience : 7+ years Acceptable Locations... ...tasks. • Create and maintain a JAMS incident tracker for logging dates and times of... ...Client tools, JAMS software updates and\or reporting tools. • Liaise with JAMS account...
- ...Inventory of all JAMS Scheduler Jobs. Create and maintain a JAMS incident tracker for logging dates and times of all warnings and errors... ...of JAMS Client tools, JAMS software updates and/or reporting tools. Liaise with JAMS account representative and Sompo procurement...
- ...(need local) JD: Assisting in QA duties across all SOC shifts to ensure timely reporting and tracking of all SOC issues for management review. This... ...development. Collaborate with SOC, Intelligence, Incident Response and Enterprise Security Teams for incident investigations...Work at officeLocal areaAll shifts
- ...requiring the performance of a variety of civil engineering and Project Management tasks for city... ...estimating, field inspection, field reports, approval of contractor pay estimates,... ...addressed. Ability to obtain National Incident Management System (NIMS) certification in...Contract workFor contractorsWork at officeAfternoon shift
$75k - $95k
...Project Engineer Job Overview: Project Engineers work closely with Field Application Engineers to create proposals... ...confidential data, complete required training, and report any suspected security incidents to support our information security controls. About...For subcontractorNight shift$28.37 - $32 per hour
...other software applications, compiling reports, and responding to customer requests. May... ...tickets in VA's ServiceNow customer incident ticketing system to ensure adherence to... ...Surge Support Travel Team Customer Service Engineer will be a dedicated surge support resource...Weekly payDaily paidFull timeWork at officeLocal areaRemote workNight shift$118k - $140k
Job Description Job Title: Site Operations (SiteOps) Engineer Location: US Reports To: US Engineering Manager Job Overview Join an innovative... ...contribute to improving operational processes, monitoring, and incident response. You will play a key role in ensuring our...Temporary workWork experience placementWork at officeVisa sponsorship$115k - $125k
...perspectives at AHEAD. Managed Services Cloud Engineer - FinOps This role supports cloud... ...operational stakeholders. Create dashboards, reports, budgets, forecasts, showback and... ...reporting deadlines, change windows, critical incidents, or urgent cost‑related issues when...- ...Project Engineer The primary function of the Project Engineer is to assist the project team in the administration and management... ...assist the Project Superintendent(s) with generating and issuing incident reports Collect all Injury and Illness Prevention Plans (IIPP)...Permanent employmentContract workTemporary workFor contractorsFor subcontractorWork at office
- ...experienced Industrial Controls Software Engineer with strong technical depth, hands-on... ...a matrixed organization without direct report management responsibilities Confident... ...Engineering Change Management methodology Lead incident response activities, technical risk...For contractorsImmediate startWorldwideFlexible hours
- ...Responsibilities: - Experience supporting documentation, reporting, and compliance activities - Understanding of network monitoring... ...security posture and compliance. - Maintain documentation, incident logs, and runbooks to support auditability, traceability, and...Minimum wageContract workTemporary workWork experience placementRemote work
- DV Trading is looking for a Trade Desk Support Engineer in Chicago. The role involves providing L1 to L3 support for technical issues, monitoring critical trading systems, and ensuring production stability. Candidates should have a minimum of 3 years relevant experience...Remote jobWork at office
- ...Coordination: Working with field personnel, electrical engineers, subcontractors, and vendors to ensure compliance with... ...Project safety ownership including weekly audits and incident investigation and reporting; positive contributor to company safety culture Management...Full timeContract workFor subcontractorLocal area
$133k - $166k
...Are you a hands‑on security engineer ready to deepen your expertise... ...supporting detection engineering, incident response, and security... ...alerting logic. Dashboards & Reporting – Create and enhance dashboards... ...searches, and reports to support SOC (Security Operations Center)...WorldwideFlexible hours$36 - $40 per hour
...-Exempt Pay range: $36 - $40 per hour The Building Engineer is a working supervisor responsible for managing the building... ...and coaching your staff, promptly investigating and reporting accidents/incidents, and proactively addressing hazards in the workplace....Hourly payFull timePart timeFor contractorsWork experience placementWork at officeAll shiftsMonday to FridayFlexible hoursShift workNight shiftWeekend work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC/Incident Report Engineer. Be the first to apply!



