Job Closed
This listing is no longer active.
Incident Response & Security Operations Engineer
Location
United States
Posted
135 days ago
Salary
0
Job Description
Incident Response & Security Operations Engineer
Magnet Forensics
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This isn’t just another security operations role. As the Incident Response & Security Operations Engineer, you will play a critical role in protecting Magnet Forensics by leading security incident response efforts, strengthening operational security practices, and ensuring that detection and response functions work effectively at scale. You will serve as the central authority during security incidents, coordinating response activities across Information Security, IT, Business Systems, and third‑party security providers. Your work will directly influence how quickly and effectively the organization identifies threats, responds to incidents, and reduces operational risk. This role blends incident leadership, security operations judgment, and continuous improvement. You’ll be empowered to make decisions, improve processes, and ensure security operations remain resilient as the organization grows. What You'll Do - Incident Response Leadership - Lead security incidents from initial triage through containment, remediation, recovery, and closure. - Assess alert severity, scope, and business impact to determine appropriate response actions. - Coordinate response efforts across IT, Business Systems, Compliance, Legal, and other stakeholders as needed. - Lead incident bridges and response coordination during active events. - Ensure incidents conclude with clear outcomes, documentation, and follow-through. - Availability to respond and investigate incidents as part of the 365/24/7 SOC/NOC. - Managed SOC & Security Service Oversight - Own the operational relationship with managed detection and response providers. - Review and validate alert quality, relevance, and escalation decisions. - Ensure third‑party security services align with Magnet’s risk tolerance and operational needs. - Drive improvements in alert routing, escalation paths, response workflows, and automation. - Act as the internal authority on what constitutes actionable security signal. - Security Operations & Vulnerability Effectiveness - Ensure vulnerability management and detection processes reduce exposure windows and support timely remediation. - Improve visibility into vulnerability trends and patching progress over time. - Identify and resolve operational bottlenecks that slow remediation or response efforts. - Partner with IT teams to improve workflows, ownership, and accountability. - Digital Investigation & Forensic Enablement - Learn and utilize Magnet Forensics Axiom as part of incident investigation and response activities. - Support investigations involving computer, mobile device, and cloud data using a unified forensic platform. - Apply Axiom workflows to interrogate and analyze digital evidence during security incidents. - Leverage Magnet Axiom microlearning to build practical, real‑world forensic capability. - Ensure investigative findings support incident understanding, decision‑making, and documentation. - Vendor & Tool Accountability - Serve as the escalation point for security tooling vendors when issues impact response timelines or risk reduction. - Hold vendors accountable to operational expectations and support commitments. - Evaluate tooling effectiveness from an operational and risk‑reduction perspective. - Ensure security tools integrate cleanly into existing workflows. - Documentation & Continuous Improvement - Produce clear incident documentation including root cause, impact, response actions, and lessons learned. - Lead post‑incident reviews and ensure corrective actions are tracked and implemented. - Identify recurring incident patterns and drive long‑term improvements to reduce repeat issues. - Cross‑Functional Communication & Readiness - Act as the primary security point of contact during incidents for IT and Business Systems teams. - Communicate clearly and calmly during high‑pressure situations. - Translate technical security findings into business‑relevant risk and impact. - Support readiness activities such as tabletop exercises and response testing. Qualifications - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience. - Demonstrated experience leading or coordinating security incident response efforts. - Experience working in a co‑managed SOC or managed detection and response environment. - Broad security operations experience across endpoint, email, identity, vulnerability management, SaaS, and cloud environments. Requirements - Strong judgment in assessing alert severity, business impact, and escalation needs. - Ability to operate effectively with incomplete or ambiguous information. - Strong written communication skills, including incident summaries and RCA documentation. - Proven ability to coordinate across multiple teams during operational events. - Process‑oriented mindset with a focus on continuous improvement. Benefits - Generous time off policies. - Competitive compensation. - Volunteer opportunities. - Reward and recognition programs. - Employee committees & resource groups. - Healthcare and retirement benefits.
Job Requirements
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
- Demonstrated experience leading or coordinating security incident response efforts.
- Experience working in a co‑managed SOC or managed detection and response environment.
- Broad security operations experience across endpoint, email, identity, vulnerability management, SaaS, and cloud environments.
- Strong judgment in assessing alert severity, business impact, and escalation needs.
- Ability to operate effectively with incomplete or ambiguous information.
- Strong written communication skills, including incident summaries and RCA documentation.
- Proven ability to coordinate across multiple teams during operational events.
- Process‑oriented mindset with a focus on continuous improvement.
Benefits
- Generous time off policies.
- Competitive compensation.
- Volunteer opportunities.
- Reward and recognition programs.
- Employee committees & resource groups.
- Healthcare and retirement benefits.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Principal Analyst Cyber Security Operations - SOAR
Fresenius Medical CareCreating a future worth living. For patients. Worldwide. Every day.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Fresenius Medical Care’s CSOC seeks a Principal Analyst to lead engineering and development of advanced enterprise-wide detection and threat analytics capabilities. The role drives security engineering strategy, AI enhanced detection logic, threat modeling, and continuous tuning across diverse platforms. It also leads SOAR engineering—building automations, integrating security tools, and creating workflows that reduce manual work and speed up response—while partnering closely with Security and Global IT teams. This is a U.S.-based remote position supporting Fresenius Medical Care’s Global Cyber Security Operations Center. Principal Duties and Responsibilities - Lead architecture, development, and maintenance of SOAR playbooks and automation pipelines. - Automate repetitive security operations and security engineering workflows (EDR, VM scanning, SIEM enrichment, IR actions). - Integrate security tools and platforms using APIs, scripting, and microservices. - Improve MTTR and reduce operational overhead through intelligent automation by closely partnering with Security Engineering, IT Operations, and Cloud Teams. - Develop KPIs to measure automation impact and report operational improvements. - Lead POCs for new automation platforms and evaluate opportunities for AI-based operations. - Provide mentorship and code reviews for automation engineers and analysts. - Partner with security engineering on telemetry strategy, logging requirements, and architectural standards for monitoring visibility. - Integrate AI/ML driven detection capabilities into existing pipelines, validating model performance and reducing false positives. - Maintain ingestion pipelines, parsing logic, normalization rules, and event taxonomies across critical log sources: identity, endpoint, cloud, network, application, and medical systems. - Lead the design, implementation, and optimization of enterprise-wide detection content, including correlation rules, behavioral analytics, machine learning assisted detections, and anomaly models. - Develop detection playbooks and logic focused on lateral movement, credential abuse, insider threats, privilege escalation, cloud compromise, and advanced persistent threats. - Tune, optimize, and enrich detection pipelines with contextual data (identity, asset, threat intelligence, vulnerability data). - Mentor analysts and engineers globally on detection logic development, data analytics, and platform best practices. - Serve as a senior escalation point for complex security incidents and investigations. Physical Demands and Working Conditions The physical demands and work environment characteristics represent those typically encountered while performing essential duties. Reasonable accommodation may be made as needed. This is a remote role with availability expected during core hours and during escalations as required. Supervision Provides technical leadership and mentorship to threat engineers, automation engineers, and security operations analysts globally. Does not directly manage staff. Education - Minimum Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent professional experience). Experience and Required Skills - 5+ years in automation engineering, SOAR engineering, or DevSecOps. - Strong scripting/programming experience (Python required; PowerShell, Go, or NodeJS a plus). - Hands-on experience with: - SOAR platforms (Cortex XSOAR, Splunk SOAR, Microsoft Sentinel automation) - API integrations and REST/JSON workflows - CI/CD tools (GitHub, GitLab, Azure DevOps) - Deep understanding of SOC processes, alerting workflows, and incident response. - Experience integrating EDR, VM, identity, and cloud security tools. Preferred - Experience with AI-driven automation or LLM-assisted workflow design. - Certifications: GCSA, GCFA, GCIH, scripting/DevOps certs. - Experience in hybrid or multi-cloud environments. Compensation The rate of pay for this position will depend on the successful candidate’s work location and qualifications, including relevant education, work experience, skills, and competencies. Annual Rate: $117,700.00 - $196,200.00 for Waltham, MA location. Benefits - Comprehensive benefits package including medical, dental, and vision insurance. - 401(k) with company match. - Paid time off. - Parental leave. - Potential for performance-based bonuses depending on company and individual performance.
VoIP Operations Engineer: We are seeking a VoIP Operations Engineer with hands-on production experience to help operate and scale a carrier-grade voice platform. You will work directly with FreeSWITCH, Kamailio, SIP carriers and cloud infrastructure, owning troubleshooting, reliability and operational excellence. This role combines deep technical work, incident response and clear communication. You will be trusted not only to fix issues, but to explain them clearly and with evidence to internal teams. Experience: 2+ Years Hands-on VoIP/Telecom/Voice Infrastructure experience, production exposure to FreeSWITCH and/or Kamailio and operating real-time systems in Linux environments Location: Remote working EST hours Type: Full -time Reports to: Operations Lead Team: Voice Infrastructure/Operations Core Technical Requirements (Hands-On) VoIP & Telecom - You should be comfortable independently debugging: FreeSWITCH - Dialplans, gateways,SIP profiles - Codec negotiation, NAT handling - Log analysis and call failure diagnosis Kamailio - SIP routing logic - Dispatcher/load balancing - Acting as a SIP proxy in front of media servers SIP Signaling - Full call flows (INVITE→BYE) - Re-INVITEs, CANCELs, SIP error handling (4xx/5xx) SIP Tracing - sngrep, ngrep, packet captures, HOMER - Correlating multi-leg calls and Call-IDs RTP & media - RTP negotiation and flow - SDP analysis, codec mismatches - One-way/no-audio troubleshooting Telco layer - Origination vs termination - DIDs, carriers, SBCs, SIP interconnects - Voice KPIs (ASR, ACD, PDD, MOS) Networking - Comfortable with wireshark - Able to find and identify network issues Infrastructure, Automation and Reliability Cloud & Automation - AWS: EC2, security groups, basic VPC/networking - Terraform: modify and maintain existing modules - Ansible: configuration management and provisioning Containers and Delivery - Docker: containerized services networking, volumes - CI/CD: GitHub Actions, GitLab CI or similar - (build→deploy→rollback understanding) Observability & Capacity Monitoring & Alerting - Prometheus, Grafana, CloudWatch, or equivalents - Responding to alerts and troubleshooting in real time Infrastructure dimensioning - CPU, memory, disk, network sizing - Capacity planning for growth and peak traffic Configuration Management Deep familiarity with configuration management tools (Ansible, Terraform) not only for infrastructure but also for service deployment and maintenance of core applications (e.g., FreeSWITCH, Kamailio, web servers like Apache/Nginx). Linux & Operations (Must be Very Comfortable) - Strong Linux command-line skills - Reading and analyzing logs - Network and system-level troubleshooting - Comfortable operating on production systems - Automation and Scripting: Proficiency in at least one common scripting language (Python, Bash) for automating repetitive tasks, analyzing data, and performing system-level operations. Responsibilities - Operate and support a live VoIP platform - Respond to alerts and troubleshoot incidents - Debug SIP/RTP issues and call quality problems - Participate in a light on-call rotation - Work with carriers and vendors during incidents - Improve monitoring, alerting and automation - Support account executives with clear technical explanations - Contribute to scaling and architecture decisions - Identify cost-saving opportunities based on resource utilization On-Call Expectations - Participation in a light, shared on-call rotation - Alerts are infrequent and actionable - Focused on: call failures, Media RTP issues, carrier connectivity, initial triage, troubleshooting and escalation, no constant paging and no noisy or consumer-scale alerting - We run real-time systems, so on-call exists, but it is intentionally kept sane, meaningful and sustainable. Cross-Team & Customer Support Responsibilities - Work closely with Account Executives during incidents or escalations - Clearly determine and explain the following: - When an issue is on our side - When it is carrier side - When it is external or customer-side - Provide evidence-based explanations: SIP traces, logs, metrics - Must enable AEs to communicate accurately and confidently with customers. Communication & Collaboration (Very Important) - Strong written and verbal communication skills - Ability to explain complex technical issues clearly and calmly - Comfortable presenting conclusions backed by data - Understands the difference between: facts, assumptions and hypotheses - Clear and professional communication during incidents Nice to Have - Homer/HEP - Redis or message queues - Bash or Python scripting - STIR/SHAKEN, fraud detection or call analytics - Strong proficiency in Python for systems automation, tooling and data analysis - Advanced Bash/Shell scripting skills for routine operations and troubleshooting
Security Operations Intern
ZscalerWe make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
• Establish success criteria, metrics, milestones, and timelines for deployment projects and ensure projects remain on track. • Maintain project tracking and customer issue documentation within appropriate systems and databases. • Build and maintain well-established relationships with key customer stakeholders. • Perform welcome calls with customers, describing the service, tools, and process.
Federal Security Operations - SkillBridge Intern
ZscalerWe make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for a Federal Security Operations - SkillBridge Intern to join our Enterprise Security team. This is a remote role, reporting to the Director of Federal Security Operations and Insider Threat. Our Federal Security team is a mission-focused group dedicated to defending critical infrastructure and government data through proactive detection and rapid incident response. We leverage advanced telemetry and automation to identify innovative solutions to complex threats. Together, we foster a high-integrity, security-first culture that ensures our federal customers can operate securely in a cloud-first world. What you’ll do (Role Expectations) - Establish success criteria, metrics, milestones, and timelines for deployment projects and ensure projects remain on track. - Maintain project tracking and customer issue documentation within appropriate systems and databases. - Build and maintain well-established relationships with key customer stakeholders. - Perform welcome calls with customers, describing the service, tools, and process. Qualifications - Experience in a Military SOC: Prior experience operating within a Cyber Defensive Operations environment (e.g., NCDOC, CPT, or similar). - Technical Proficiency: Familiarity with SIEM/XDR platforms such as Crowdstrike Falcon Next-gen SIEM, Splunk, or Google SecOps. - Must have 180 days of service or fewer remaining prior to your date of discharge and at least 180 continuous days of active service. - Obtain approval from your unit commander. - MOU must be approved and submitted before start. Requirements - Professional experience or familiarity operating solutions built on Azure, AWS, and GCP. - Experience with Hypervisors such as VMware, Hyper-V, and KVM. - Working knowledge of authentication systems such as SAML, LDAP, and MS Active Directory. Benefits - Various health plans - Time off plans for vacation and sick time - Parental leave options - Retirement options - Education reimbursement - In-office perks, and more!


