SOC/Incident Response Engineer
$112k - $139kBenesch
Benesch is proud to announce the opening for a SOC/Incident Report Engineer in our Chicago office! This position is hybrid and has work from home flexibility. Position Summary Are you excited about detecting and resolving cybersecurity threats and incidents? Do you find it a challenge to help an organization reduce threats and enhance their security? Does working with teams to develop strategies to improve detection capabilities? Then you may be interested in our SOC/Incident Report Engineer position. This role is perfect for the individual looking to play a crucial role in Benesch's security initiatives. The SOC/Incident Response Engineer is responsible for detecting, investigating, and responding to cybersecurity incidents across the Firm. This role combines threat detection, digital forensics, malware triage, and cloud security expertise to protect organizational assets, reduce risk, and strengthen security posture. The SOC/Incident Response Engineer will operate within a 24/7 security operations environment, collaborating with cross-functional teams to analyze threats, develop response strategies, and improve detection capabilities. Position Responsibilities Security Monitoring & Threat Detection Monitors SIEM, EDR, NDR, and cloud-native security tools to identify suspicious activity and potential security incidents. Creates, tunes, and optimizes detection rules, correlation logic, and analytic use cases. Conducts threat hunting based on emerging TTPs, threat intel, and anomaly patterns. Maintains and improves alerting fidelity to reduce false positives and enhance detection precision. Incident Response & Triage Performs initial triage of security alerts to assess severity, impact, and required response actions. Leads full incident lifecycle activities including investigation, containment, eradication, recovery, and post‑incident analysis. Coordinates with IT, cloud, and business teams to execute IR playbooks and minimize operational impact. Documents incidents, findings, and lessons learned; contribute to after‑action reviews. Digital Forensics & Malware Analysis Conducts forensic acquisition and analysis of endpoints, servers, cloud resources, and network artifacts (disk, memory, logs). Examines artifacts such as registry hives, event logs, file systems, network captures, browser history, and persistence mechanisms. Performs malware triage (dynamic and static) to determine malware behavior, indicators of compromise, and propagation mechanisms. Mants chain-of-custody processes and ensure forensic data integrity for potential legal or compliance requirements. Cloud Security & IR Monitors and responds to security events within cloud environments (e.g., Azure, AWS, Google Cloud). Investigates cloud-native logs: Azure Activity Logs, AWS CloudTrail, GCP Audit Logs, identity events, network flows, and storage access. Evaluates cloud security posture, identifying misconfigurations, risky access patterns, and drift. Assists in development of cloud detection logic using native tooling (e.g., Azure Sentinel/Microsoft Defender XDR, AWS GuardDuty, GCP SCC). Security Tooling & Automation Maintains and enhances SOC tooling, dashboards, and automation workflows (SOAR). Builds automated playbooks to speed up triage, enrichment, and response. Integrates new data sources and improves log ingestion pipelines for SIEM/EDR. Threat Intelligence & Research Utilizes internal and external threat intelligence to contextualize alerts and strengthen detections. Tracks adversary TTPs based on frameworks such as MITRE ATT&CK. Researches emerging threats, vulnerabilities, and malware families. Collaboration, Compliance & Reporting Partners with governance, engineering, and IT teams to ensure effective remediation and long‑term control improvements. Supports audit, compliance, and regulatory requirements related to incident management. Prepares clear, concise technical and executive‑level reports. Key Competencies Analytical mindset with strong problem‑solving skills. Ability to work under pressure during active incidents. Excellent written and verbal communication skills. Strong attention to detail and a commitment to continuous improvement. Qualifications The SOC/Incident Response (IR) Engineer should have 3–7 years of experience in a Security Operations Center (SOC), incident response, digital forensics, or a closely related cybersecurity discipline. A strong technical foundation in networking, operating system internals across Windows, Linux, and macOS, identity systems, and modern cloud architectures is essential. The role requires hands‑on experience with leading security technologies, including SIEM platforms such as Microsoft Sentinel or Splunk, endpoint detection and response (EDR) and antivirus tools like Microsoft Defender for Endpoint or CrowdStrike, and forensic toolsets including Velociraptor, Autopsy, FTK, and KAPE. Experience utilizing malware analysis sandboxes and static analysis frameworks, as well as cloud security tools such as Azure Defender, AWS GuardDuty, and Google Cloud Security Command Center (SCC), is also required. Familiarity with scripting and automation languages, particularly Python, PowerShell, and KQL, is highly desirable. Preferred certifications include GIAC GCIA, GCFA, GCIH, or GNFA; AWS Security Specialty or Google Professional Cloud Security Engineer; and industry‑recognized credentials such as CISSP, CEH, or CySA+ (or their equivalents). The salary range for this position is $112K to $139K. Please note that quoted salary ranges are based on Benesch's good faith belief at the time of the job posting and are not a guarantee of what final salary offers may be. Base pay is based on market location and may vary depending on job‑related knowledge, skills, and experience. Base pay is only one part of the Total Rewards that Benesch provides to compensate and recognize our staff professionals for their work. Full‑time positions are eligible for a discretionary bonus and a comprehensive benefits package. Benesch is an equal opportunity employer. We strongly value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability (where applicant is qualified to perform the essential functions of the job with or without reasonable accommodations), medical condition, protected veteran status, gender identity, genetic information, or any other characteristic protected by federal, state, or local law. Applicants who are interested in applying for a position and require special assistance or an accommodation during the process due to a disability should contact the Benesch Human Resources Department by phone at View phone number on click.appcast.io or email Christine Watson at View email address on click.appcast.io. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities #J-18808-Ljbffr Benesch
- ...seeking an Information Security Analyst (SOC) for a fully remote Direct Hire role.... ...growing security operations team, lead incident response activities, hunt threats, and help design... ...ideal candidate has a BS/BA in CS or engineering and 4+ years of security experience, strong...SuggestedRemote work
- 360-IT-Professional is seeking an accomplished Incident Response Manager to lead security response efforts for ICT4D initiatives and allied programs... ...and leadership skills. You will collaborate with SOC/NOC teams and support legal operations. Candidates must be able...SuggestedNight shift
- ...expertise. You'll lead production support triage efforts and ensure compliance with incident management policies. The position requires hands-on knowledge of Splunk and incident response in a fast-paced FinTech environment. The ideal candidate will have extensive...Suggested
- A technology solutions provider is seeking a skilled operations engineer to manage and optimize GCP infrastructure and applications. The role involves day-to-day operations, incident response, and system optimization. Candidates should have a minimum of 3 years in cloud...Suggested
- ...Associate to provide technical triage and operational support across core platforms. You will enhance incident response effectiveness and collaborate with engineering and business teams to diagnose issues and improve operational stability. The ideal candidate will have...Suggested
- ...Solutions LLC is seeking an Information Security Engineer - Security Automation and Response for a fully remote Direct Hire role. The... ...automation, and AI-driven workflows to streamline incident response and improve SOC efficiency. The candidate should have 5+ years in...Remote job
- ...global CSOC capabilities. The role combines hands-on technical leadership with strategic vision, overseeing threat detection, incident response, and continuous improvement of security operations across the organization. The Lead will serve as the primary escalation point...
- The Judge Group is seeking an AI SOC Engineer to identify, design, and prototype agent use cases for SOC operations. You will build... ...threat intel, and implement scalable, cost-efficient agent deployments shaping incident response workflows. #J-18808-Ljbffr The Judge Group
- ...hybrid to downtown Chicago. Responsibilities Identify, design, and prototype... ...agent use cases to address SOC operational gaps (alert... ...threat severity assessment, incident enrichment, etc.) Develop and... ...agent frameworks and prompt engineering Integration experience with...Long term contract
- RSM US LLP is seeking a Senior Threat Hunter/SOC Analyst to lead high-severity security investigations and guide technical direction... ...a dynamic security operations environment. The role encompasses incident analysis, mentorship of junior analysts, and contributions to the...
- Vizient, Inc. is seeking a senior SOC Engineer to lead security operations engineering, detect threats, and automate responses. You will design and optimize monitoring, detection, and incident response across cloud and on-prem environments. The role requires extensive...
$40 - $45 per hour
Job Summary Our client is seeking a highly skilled Incident Response Analyst to detect, respond to, and mitigate security incidents. The analyst... ...work experience) At least 1 year of experience as a SOC or Incident Response Analyst Proficiency in cybersecurity EDR...Hourly payWork experience placement$115k - $130k
A logistics technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will... ...implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years...Remote jobFull time$120k - $140k
Join to apply for the Principal Incident Response Engineer role at Acrisure . Get AI-powered advice on this job and more exclusive features. About Acrisure A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions...Full timeTemporary workFlexible hours- ...closely with local communities. We are seeking an accomplished Incident Response Manager. Job Description Must Have: 5+ years’ hands‑on... ...IT Experience with legal operations Experience working with a SOC/NOC Hands‑on experience with security and access technologies...Local areaNight shift
- ...Job Responsibilities Provide direct day-to-day management to an initial team of 5 security analysts... ...and continuously optimize end-to-end incident response workflows. Leverage specialized... ...experience within a Security Operations Center (SOC) or Incident Response team. Specialized,...
- ...base plus 10.5% bonus depending on level of experience. No visa sponsorship. Job Description Continue to develop the company's incident response program. Utilize and adhere to defined workflow and processes driving Incident Response and mitigation efforts. Provide root...Work at officeLocal areaRemote workRelocationVisa sponsorship
$86.1k - $170.5k
...is $86,100.00 - $170,500.00 per year. Essential Job Functions Incident Detection and Analysis: Monitor security alerts and logs to... ...: Evaluate the severity and urgency of incidents to prioritize response efforts effectively. Containment and Mitigation: Implement strategies...Local area- Niche Talent Finders seeks a Cyber Incident Response Manager in Chicago to advance the incident response program and coordinate remediation across the organization, with a flexible blend of in‑office and remote work. You will conduct technical analyses, develop metrics...Work at officeRemote workRelocationFlexible hours
$40 - $45 per hour
KellyMitchell Group is seeking an Incident Response Analyst to work onsite in Arlington Heights, IL. This role involves monitoring security incidents, conducting analyses, and preparing incident reports. The selected candidate will work closely with cross-functional teams...Hourly pay- ...at this time. About the Role Resilience Engineering is a subset of the Site Reliability... ...culture of continuous improvement through incident analysis, process evolution, and problem... ...systems. Your work will focus on our incident response, reporting and analysis processes,...Full timeSummer workWork at officeLocal areaRemote workMonday to FridayShift work
- ...Threat And Incident Response Analyst Location: Chicago, IL Contract Duration: 6 months Key Responsibilities: Monitor and analyze security events, incidents, and vulnerabilities to identify potential threats and risks to the organization's IT infrastructure....Contract work
- ...Accenture is seeking a hands-on technical leader for their Cyber Investigation and Forensic Response (CIFR) practice in Chicago. The candidate will excel in incident response and digital forensics, conducting complex analyses, mentoring investigators, and communicating...
- ...As the Security Operations Engineer at Hopscotch, you will lead... ...wouldn’t otherwise be possible. RESPONSIBILITIES Define systems security... ...interpret policy documents. SOC / SIEM / IPS monitoring, alerting... .... Commanded or led security incident response in real world...Live inWork at office
- Crowe is seeking an Incident Response Manager in Chicago, United States, to manage complex cybersecurity incidents and mentor a team of responders. This senior position involves technical leadership and client relationship management. The ideal candidate will combine deep...
- ViziRecruiter,LLC. is seeking a Major Incident Management (MIM) Analyst responsible for leading incident responses across teams. This role ensures effective communication and management of major incidents. Candidates must have a bachelor's degree and 3+ years of relevant...Flexible hours
- ...Analyst in Chicago, Illinois. Under the direction of the Chief Information Security Officer, you will analyze security events, lead incident response efforts, and develop incident response documentation. Ideal candidates should possess a Bachelor's degree in a related field...
$63k - $73k
Amount is seeking a talented Incident Manager to enhance incident response and management processes in Chicago, Illinois. The ideal candidate will have a technical background, strong leadership skills, and the ability to navigate complex environments. Responsibilities include...3 days per week- Ahold Delhaize USA is looking for a Major Incident Management (MIM) Analyst to lead the response to major incidents, ensuring swift resolution and effective communication. This role requires a Bachelor's degree and 3+ years of incident management experience, overseeing...Remote workFlexible hours
$86.1k - $170.5k
Crowe in Chicago is looking for a professional in incident detection and response. The candidate will monitor security alerts and logs, prioritize incident responses, and implement containment strategies. This role also involves conducting thorough investigations and collaborating...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SOC/Incident Response Engineer. Be the first to apply!

