This position serves as a senior technical authority for response operations on the most critical and complex events, spanning both advanced (Tier III) security operations and incident response engineering. On the operations side, this role leads immediate containment, investigation, and management of remediation actions for critical incidents, acting as the primary escalation point for Tier I and Tier II analysts and driving the most difficult investigations through to resolution. It also turns the knowledge gained throughout each response into stronger defenses, developing and tuning threat detection content across tools to identify anomalous, suspicious, and malicious behavior within security data lake architectures. On the engineering side, this person works with a team to develop and maintain automated workflows that orchestrate incident response actions and optimize security operations for our clients across all phases of the incident response lifecycle. The role requires deep, cross-product expertise and close collaboration with SOC leadership, service delivery, and clients to provide ongoing communication of status and timely, decisive response to tickets and events.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
Associate degree