Lead incident response efforts for a global fintech focusing on Microsoft E5 security capabilities and DLP. Drive detection, containment, and proactive security measures for the enterprise.
Responsibilities
The Senior Incident Response Engineer will lead advanced security incident response efforts
focusing on Microsoft E5 security capabilities and Data Loss Prevention (DLP)
Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers
Lead post-incident reviews and drive process improvements
Perform advanced threat hunting using Microsoft Defender and related tools
Integrate threat intelligence and adapt detection strategies based on real world threats observed by the organization
Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents
Develop and maintain incident response playbooks and runbooks across the security operations toolset
Collaborate with analysts and other IR engineers to identify opportunities for improvement and tuning of detection rules
Collaborate with IT, legal, HR, communications, and other business units
Requirements
Minimum 5 years of progressive information security experience
At least 4 years focused on incident response, including investigations across different security domains (endpoint, application, DLP, and more)
Proficiency with Microsoft 365 Security Suite as well as other security tooling such as SentinelOne, Google SecOps, Abnormal Security, and others
Strong experience with incident response, digital forensics, and threat hunting across a hybrid environment
Knowledge of endpoint operating systems (Windows, macOS, and Linux)
Experience with cloud environments such as Azure, AWS, and GCP
Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing desired
Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, MS SC-200, MS SC-400 or similar
Benefits
Comprehensive medical insurance, dental insurance, and vision insurance
life and disability insurance
fertility benefits
wellness resources
paid sick time
Generous paid time off and holidays
Employee Assistance Program (EAP)
complimentary Calm app subscription
Immediate vesting in a 401(k) plan
Health Savings Account (HSA) and Flexible Spending Account (FSA) options
commuter benefits
employee discount programs
Paid maternity leave and paid paternity leave (including for adoptive parents)
Cyber Operations Lead ensuring coordination of cyber operations between the Security Operations Center and internal business units. Enhancing security through effective incident response and threat management initiatives.
Solution Sales Manager enhancing revenue in financial services, focusing on ServiceNow IRM and Tanium solutions. Collaborating with teams and engaging C - level executives in Austria and Switzerland.
Senior Internal SOC Analyst leading security triage and investigations for Darktrace, utilizing AI - driven cybersecurity technology. Collaborating on incident response and mentorship within a hybrid work environment.
Security Operations Intern responsible for security monitoring at Paddy Power Betfair. Involves data loss prevention investigations and content filtering analysis with a commitment to improving security posture.
SOC Analyst L2 responsible for managing and analyzing security incidents in digital transformation. Contributing directly to the protection of companies and infrastructures.
Senior Manager leading global IT security operations to protect company data and assets at Keenova. Overseeing incident response, monitoring, and cybersecurity capabilities with strategic oversight.
Security Operations Center leader at Woven by Toyota, managing triage and response to security alerts in Japan. Collaborating with global SOCs to ensure 24/7 operations.
GSOC Analyst responsible for security operations at Paramount Studios. Developing workflows, incident response, and risk monitoring in a dynamic team environment.