Cyber Incident Response Engineer
100% Remote
We are looking for a Cyber Incident Response Engineer to detect, analyze, and respond to cybersecurity incidents. This role involves monitoring security events, investigating threats, and implementing mitigation strategies to protect organizational systems and data.
Monitor and analyze security alerts from SIEM, EDR, and other security tools
Investigate and respond to cybersecurity incidents (malware, phishing, ransomware, etc.)
Perform root cause analysis and document incident findings
Contain, eradicate, and recover from security incidents
Develop and improve incident response playbooks and procedures
Conduct threat hunting and proactive security monitoring
Collaborate with IT, network, and application teams during incident response
Support digital forensics and evidence collection when required
Provide recommendations to strengthen security posture
Strong understanding of cybersecurity concepts and frameworks
Experience with SIEM tools (Splunk, QRadar, Sentinel, etc.)
Knowledge of endpoint detection and response (EDR) solutions
Familiarity with network protocols, firewalls, and intrusion detection/prevention systems
Experience in log analysis and threat investigation
Understanding of common attack vectors (MITRE ATT&CK framework)
Proficiency in scripting (Python, PowerShell, or Bash)
Knowledge of operating systems (Windows, Linux)
Experience with SOAR platforms and automation tools
Knowledge of cloud security (AWS, Azure, GCP)
Familiarity with vulnerability management tools
Exposure to digital forensics and malware analysis
Understanding of compliance frameworks (ISO 27001, NIST, etc.)
Strong analytical and problem-solving skills
Ability to work under pressure during critical incidents
Effective communication and reporting skills
Attention to detail and investigative mindset
Bachelor’s degree in Cybersecurity, IT, or related field
Relevant certifications (preferred):
CEH (Certified Ethical Hacker)
CISSP (Certified Information Systems Security Professional)
GCIH (GIAC Certified Incident Handler)
Experience working in a Security Operations Center (SOC)
Knowledge of threat intelligence platforms
Experience with automation and scripting for incident response