IT Security Engineer IV

Russell TobinSan Diego, CA
Remote

About The Position

The IT Security Engineer IV role focuses on Digital Forensics and Incident Response (DFIR). This is a remote, 12+ month contract position with the possibility of extension. The role involves responding to and leading critical security incidents, performing forensic analysis, analyzing security logs, developing incident response playbooks, and collaborating with various teams to ensure compliance and security best practices.

Requirements

  • Bachelor’s degree in an IT-related or Engineering field.

Nice To Haves

  • Respond to and lead critical, escalated security incidents: coordinating communications, executing the Incident Response Plan, and delivering clear, timely status updates to stakeholders and senior leadership.
  • Perform comprehensive host, network, and cloud forensic analysis to determine root cause, scope, and impact, ensuring containment is validated against Client control-testing standard before an incident is closed.
  • Analyze and correlate signals across SIEM, EDR, and other platform logs to triage and validate threats.
  • Develop, maintain, and improve incident response playbooks and runbooks in partnership with the SOC's Analysis Champ and other capability owners.
  • Operate within existing automated workflows in ServiceNow SIR, following and refining established processes.
  • Flag detection gaps and false-positive patterns identified during live incidents to Detection Engineering for tuning and new detection development.
  • Use outputs from Mate AI SOC platform to inform triage and investigation decisions.
  • Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements.
  • Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures.
  • Provide training and mentorship to other incident responders on best practices.
  • Contribute to post-incident reviews and help build metrics that drive continuous program improvement.

Responsibilities

  • Respond to and lead critical, escalated security incidents: coordinating communications, executing the Incident Response Plan, and delivering clear, timely status updates to stakeholders and senior leadership.
  • Perform comprehensive host, network, and cloud forensic analysis to determine root cause, scope, and impact, ensuring containment is validated against Client control-testing standard before an incident is closed.
  • Analyze and correlate signals across SIEM, EDR, and other platform logs to triage and validate threats.
  • Develop, maintain, and improve incident response playbooks and runbooks in partnership with the SOC's Analysis Champ and other capability owners.
  • Operate within existing automated workflows in ServiceNow SIR, following and refining established processes.
  • Flag detection gaps and false-positive patterns identified during live incidents to Detection Engineering for tuning and new detection development.
  • Use outputs from Mate AI SOC platform to inform triage and investigation decisions.
  • Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements.
  • Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures.
  • Provide training and mentorship to other incident responders on best practices.
  • Contribute to post-incident reviews and help build metrics that drive continuous program improvement.

Benefits

  • Comprehensive healthcare coverage (medical, dental, and vision plans)
  • Supplemental coverage (accident insurance, critical illness insurance and hospital indemnity)
  • 401(k)-retirement savings
  • Life & disability insurance
  • Employee assistance program
  • Identity theft protection
  • Legal support
  • Auto and home insurance
  • Pet insurance
  • Employee discounts with some preferred vendors
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service