Incident Responder 1

Bentley Systems•Philadelphia, PA
•Hybrid

About The Position

Bentley’s Information Security team is building a security operation where automation does the first pass and people do the judgment. Automated investigation agents already triage most of our alerts, investigate cloud risks, and test our own defenses around the clock. What they cannot do is decide whether they were right, handle the cases they could not resolve, or make the next detection better. As an Incident Responder I, you join the Security Operations Center at the point where an alert becomes a decision. You will verify what automation concluded, own the cases it hands back, take containment actions within clearly defined limits, and feed what you learn back into detections and playbooks. You will work with modern tooling — CrowdStrike, Wiz, a cloud-native SIEM and SOAR platform — across a global engineering and SaaS environment spanning three public clouds. This is an entry point, not a destination. The role is designed so that the share of your time spent on routine response falls as your share of engineering and improvement work grows, and it sits on a defined career path into detection engineering, security engineering, architecture, or governance.

Requirements

  • 1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration.
  • Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS).
  • A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference.
  • Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why.
  • Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system.
  • Availability for a shift rotation as part of a 24×7 operation.
  • Applicants must be authorized to work in the U.S. without current or future employer sponsorship.

Nice To Haves

  • Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL.
  • Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM.
  • Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications.

Responsibilities

  • Monitor and respond to alerts and cases from the SIEM, SOAR, endpoint, and cloud security platforms, including the output of automated investigation agents.
  • Review automated verdicts — malicious, not malicious, inconclusive — and act on them: confirm and close, escalate, or contain within the approved autonomy tier (isolate a host, revoke a session, block an indicator).
  • Own the inconclusive queue: investigate what automation could not resolve and document the outcome so the same class of case can be automated next time.
  • Hand off and receive incidents cleanly across shifts with complete, structured notes; escalate to senior responders and management per the incident response procedure.
  • Sample automated verdicts for accuracy (false positives and false negatives) and report findings; your sampling doubles as audit evidence for our compliance program.
  • Tune existing detections and playbooks based on what your shift observed; keep runbooks current.
  • Watch the health of the tooling the SOC depends on — sensor coverage, connector status, log sources — and raise gaps before they become blind spots.
  • Contribute to detection-as-code: propose new detections and playbook steps, version them, and test them with a senior engineer.
  • Learn the behavioral baselines of AI agents operating in our environment and flag abnormal agent activity — a new class of alert this SOC owns.
  • Take part in post-incident reviews and turn lessons into automation requests for the engineering team.

Benefits

  • We fund training and certifications.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service