Incident Response Engineer
The job description
Tech stack. SIEM platforms, EDR telemetry, Volatility and memory forensics, Wireshark, Autopsy or EnCase, SOAR playbooks, Python, MITRE ATT&CK, timeline analysis tools
About the role
You will be the calm in the storm for a technology company's security operations team, owning breaches from the first alert through complete recovery and verified eradication. The incident response function handles everything from commodity malware outbreaks to targeted intrusions by determined adversaries, and you will be the engineer responders call when scoping gets genuinely hard. You will develop playbooks, run realistic exercises, and make the consequential calls during live incidents. This role matters because the difference between a contained incident and a headline breach is measured in the quality of the first responder's decisions, and your forensic work determines what leadership, legal, and customers are ultimately told. You will also lead the post-incident reviews that turn each breach into detection improvements, ensuring the same attacker technique never works twice against this environment.
What you will achieve
- Contain confirmed intrusions within 4 hours of formal declaration through practiced, rehearsed playbooks and rapid, decisive scoping.
- Perform memory and disk forensics establishing complete attacker timelines and blast radius with evidence rigorous enough to withstand external scrutiny.
- Run quarterly tabletop exercises exposing gaps in tooling, process, and coordination before real attackers find them.
- Reduce repeat incident classes 50 percent by driving verified root-cause fixes into engineering backlogs and confirming they actually land.
- Maintain a living incident knowledge base so the next responder starts from your documented lessons instead of from zero.
What you will bring
Must-haves
- 2 to 5 years in incident response, SOC Tier 3 escalation, or digital forensics roles with real breach experience.
- Hands-on forensic skills: memory analysis with Volatility, disk imaging, and detailed timeline reconstruction.
- Deep familiarity with attacker techniques spanning initial access, persistence, privilege escalation, and exfiltration.
- Experience with SIEM and EDR platforms for hunting, scoping, and containing active compromises.
- Ability to write clear incident timelines and executive summaries under genuine, unforgiving time pressure.
- Composure and structured decision-making during active, high-stakes incidents with incomplete information.
- Willingness to carry the on-call burden for true emergencies and lead when others freeze.
Nice-to-haves
- GCIH, GCFA, or GNFA certification.
- Malware triage or reverse engineering fundamentals that deepen investigation capability.
- Experience coordinating with legal, corporate communications, and external counsel during breach response.
- Familiarity with cyber insurance notification and evidence preservation requirements.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta