Bentley’s Information Security team is building a security operation where automation does the first pass and people do the judgment. Automated investigation agents already triage most of our alerts, investigate cloud risks, and test our own defenses around the clock. What they cannot do is decide whether they were right, handle the cases they could not resolve, or make the next detection better. As an Incident Responder I, you join the Security Operations Center at the point where an alert becomes a decision. You will verify what automation concluded, own the cases it hands back, take containment actions within clearly defined limits, and feed what you learn back into detections and playbooks. You will work with modern tooling — CrowdStrike, Wiz, a cloud-native SIEM and SOAR platform — across a global engineering and SaaS environment spanning three public clouds. This is an entry point, not a destination. The role is designed so that the share of your time spent on routine response falls as your share of engineering and improvement work grows, and it sits on a defined career path into detection engineering, security engineering, architecture, or governance.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level
Education Level
No Education Listed