Senior Incident Response Engineer

Watts Water Technologies•North Andover, MA
•$152,000 - $168,000•Hybrid

About The Position

This highly skilled individual, as part of the Information Security team, will serve as a senior technical escalation point for the global Information Security program. This is a hands-on senior individual contributor role responsible for leading complex security investigations, advancing detection engineering capabilities, and providing deep technical expertise across incident response activities. The Senior Incident Response Engineer will own complex investigations from initial escalation through containment, remediation, and closure; investigate security incidents across cloud and enterprise environments; and drive improvements in detection, response, and investigation capabilities. This role will also serve as a technical authority and escalation resource for other members of the Information Security team.

Requirements

  • Bachelor's degree in cybersecurity, information technology, computer science, or a related field and a minimum of five years of hands-on incident response, security operations, or related cybersecurity experience. In the absence of a degree, relevant work experience may be considered.
  • Demonstrated experience investigating cloud compromise and application exploitation within AWS, Azure, and/or GCP environments.
  • Hands-on experience with endpoint detection and response (EDR) technologies, including detection engineering, alert tuning, and investigation.
  • Experience conducting host, network, identity, email, and/or cloud-based forensic investigations.
  • Experience serving as a technical point of contact or escalation resource for an MDR or managed security service provider.
  • Working knowledge of MITRE ATT&CK, the Cyber Kill Chain, and identity-based attack techniques within Entra ID and Active Directory environments.
  • Ability to analyze complex security incidents, synthesize information from multiple telemetry sources, and independently drive investigations through resolution.
  • Understanding of and adherence to applicable laws, codes, policies, regulations, and security practices and procedures.
  • Must successfully establish employment eligibility and satisfactorily complete required background checks and pre-employment testing as a condition of employment.

Nice To Haves

  • Hands-on experience with CrowdStrike Falcon, including detection engineering and tuning.
  • Experience working with CrowdStrike Falcon Complete and/or NG SIEM MDR.
  • GCIH, GCFA, GCIA, GCFE, or equivalent incident response or digital forensics certification.
  • Experience supporting security operations within a global or multi-site enterprise environment.
  • Experience investigating incidents within newly acquired or integrating business environments.

Responsibilities

  • Serve as the senior technical escalation point for Level 2 and Level 3 security incidents, owning complex investigations end to end through scoping, containment, remediation, and closure.
  • Investigate cloud application compromise and exploitation across AWS, Azure, and GCP, including identity compromise, misconfiguration exploitation, privilege escalation, and data exposure across production and newly acquired environments.
  • Own detection engineering and tuning within CrowdStrike Falcon, including reviewing alert quality and volume, adjusting detections, reducing false positives, and validating the impact of changes before and after implementation.
  • Serve as the primary technical liaison to CrowdStrike Falcon Complete and NG SIEM MDR, managing partner escalations, responding to requests for information, validating partner findings against internal telemetry, and driving service quality.
  • Conduct host, network, identity, email, and cloud forensics to establish root cause, incident scope, persistence, lateral movement, and potential data exposure.
  • Build and maintain detection content, queries, and automation to improve investigation speed, strengthen security monitoring, and reduce manual triage effort.
  • Provide senior technical guidance and escalation support to the Incident Response Associate when investigations require deeper technical expertise.
  • Develop and maintain incident response playbooks, runbooks, and standard operating procedures for incident types within the scope of the role.
  • Identify opportunities to continuously improve incident detection and response capabilities, investigation processes, and security operations in alignment with Watts' commitment to continuous improvement.
  • Assume responsibility for other projects and duties as assigned by the Senior Manager, Information Security or Company management.

Benefits

  • Competitive compensation based on your skills, qualifications and experience
  • Comprehensive medical and dental coverage
  • Retirement benefits
  • Family building benefits, including paid maternity/paternity leave
  • 10 paid holidays
  • Paid Time Off
  • Continued professional development opportunities
  • Educational reimbursement
  • Fitness reimbursements
  • Employee discount programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service