Senior Security Engineer - CSIRT
Core
Lead technical response for critical cybersecurity incidents (Level 2/3), performing digital forensics, threat hunting, and automation to guide recovery and strengthen security posture.
Role type
Senior Security Engineer (Incident Response & Digital Forensics)
Builds
Incident response playbooks, automated detection workflows, and actionable threat intelligence
Domain
Cybersecurity / Incident Response / Digital Forensics
Deliverable
client delivery
Required skills
Incident Response leadership, Digital Forensics, Threat Hunting, Malware analysis, Cloud security (AWS/GCP), SOAR automation, Risk assessment
Preferred skills
Memory forensics, SIEM/EDR tuning, Cross-functional stakeholder management
Technologies
AWS, GCP, SIEM, EDR, SOAR, Windows, Linux, macOS
Responsibilities
Lead response efforts for Level 2 and Level 3 security incidents; Coordinate activities with MSSPs and 24/7 SOC teams; Conduct digital forensics including evidence analysis and root cause investigation; Develop and improve incident response playbooks and automated workflows; Manage the Cyber Threat Intelligence lifecycle; Facilitate post-mortem processes and translate findings into improvements.
Seniority
Senior, hands-on IC