Mid- Senior Cyber Security Incident Responder

Guaranteed Rate•Chicago, IL
•Remote

About The Position

Every week, somewhere in our environment, something tries to break. A credential gets phished. A mule account starts moving money it shouldn't. An adversary finds a gap between two systems that were never designed to talk to each other. Most people at Rate never see it happen, because a tight, sharp, and relentless team already did. That team is the Risk Operations Center (ROC), and Rate is looking for a mid-to-senior level response engineer who wants to be the one that gets the page, reads the signal that no one else caught, and calls the shots when the room goes quiet and everyone looks at you. This opportunity is not simply a one-lane job. You will rotate and flex across five unique, yet overlapping terrains, often in the same week. You'll work from a real IR plan mapped to NIST CSF 2.0, a growing playbook library, and a team that has already done the hard work of building the scaffolding — you're here to run on it, sharpen it, and push it further. The five domains are: Incident Response — Take incident command on active events. Establish ground truth fast, drive containment and eradication, and own the post-incident review that makes the next one shorter. Threat Hunting — Don't wait for the alert. Go looking for what the tooling missed — hypothesis-driven hunts across endpoint, identity, and network telemetry. Detection Engineering — Turn every incident and hunt into a new detection. Write, tune, and retire rules; you're building the team's muscle memory into code. Threat Intelligence — Track the actors and techniques relevant to financial services. Translate raw intel into detections, playbooks, and briefings people actually use. Fraud Investigations — Cross into fraud ops when account takeover, mule activity, or payment fraud overlaps with a security incident — which, in this environment, is often.

Requirements

  • 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role.
  • Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures).
  • Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms.
  • Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies.
  • Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews.
  • Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS.
  • Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership.
  • Bachelor’s degree in cybersecurity, information technology, or equivalent experience.

Nice To Haves

  • Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus.
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)

Responsibilities

  • Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned.
  • Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps.
  • Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes.
  • Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents.
  • Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time.
  • Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively.
  • Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness.
  • Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization.
  • Collaborate with engineering teams to continuously strengthen detection and response capabilities.

Benefits

  • eligibility to participate in a company-sponsored 401(k)
  • vacation benefits
  • eligibility for medical, dental, vision, and prescription drug benefits
  • flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts)
  • life insurance and death benefits
  • critical care insurance
  • personal accidental insurance
  • commuter benefits
  • pet insurance
  • certain time off and leave of absence benefits
  • well-being benefits (e.g., employee assistance program)
  • other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service