Job Closed

This listing is no longer active.

NBCUniversal logo
NBCUniversal

Here you can create the extraordinary. Join us.

Senior Cyber Incident Response Engineer

Incident Response AnalystSecurity AnalystFull TimeRemoteSeniorTeam 10,001+Since 2004H1B SponsorCompany SiteLinkedIn

Location

New York

Posted

18 days ago

Salary

$140K - $175K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishCloudCyber SecurityPythonSQL

Job Description

Senior Cyber Incident Response Engineer

NBCUniversal

• Design, build, and improve automated evidence collection capabilities that increase the speed, consistency, and completeness of incident investigations. • Create and maintain SOAR playbooks that orchestrate investigation, enrichment, containment, notification, and recovery workflows. • Integrate SIEM, EDR, IAM, cloud, email, case management, and threat intelligence platforms to enable unified response actions and stronger analyst context. • Develop and deploy response tooling that may utilize AI to improve response capabilities across cloud, endpoint, identity, SaaS, email, and data platforms. • Develop scripts, tools, and integrations that support triage, containment, enrichment, forensic collection, and operational response workflows. • Ensure responders have the logs, telemetry, access, and tooling needed to investigate and respond without unnecessary delay. • Build dashboards, operational views, and incident metrics that measure response performance, workflow health, and process effectiveness. • Identify repeated manual analyst tasks and turn them into safe, scalable, and repeatable automation. • Review incident response plans, identify readiness gaps, and help develop practical strategies to improve preparedness. • Design and optimize incident response playbooks aligned to relevant threats, operating models, and business needs to allow for quick identification and response to potential incidents. • Collaborate with Response Operations and Automation team stakeholders for prioritization, automation creation, and integrations with security tooling. • Facilitate or support tabletop exercises, drills, and readiness activities to validate plans and improve operational performance. • Lead or support complex investigations involving host, network, identity, email, and cloud artifacts to determine nature, scope, and root cause. • Partner with cross-functional teams to guide containment, remediation, recovery, and post-incident improvement activities. • Brief technical teams and leadership on findings, risks, recommendations, and response decisions during and after incidents. • Contribute to incident response standards, methodologies, documentation, and internal knowledge sharing. • Participate in an incident response on-call rotation, including weekend coverage, as required.

Job Requirements

  • 5+ years of relevant cybersecurity experience in either incident response, DFIR, detection engineering, threat hunting, and or SOC escalation
  • 2+ years of security automation / cyber defense engineering
  • Strong proficiency with Python, PowerShell, Bash, or similar scripting languages used for automation and response engineering.
  • Ability to lead projects with little guidance, and strong communication
  • Knowledge of SIEM, SOAR, EDR, Data Lake, and enterprise security tooling and methodologies.
  • Experience handling security incidents and investigating a multitude of cyber threats with various TTPs across multiple enterprise platforms
  • Experience building and maintaining API integrations across security and enterprise platforms.
  • Working knowledge of SIEM query languages such as SPL, KQL, SQL, or equivalent analytics languages.
  • Experience with EDR response actions, investigation workflows, and endpoint containment techniques.
  • Experience designing, building, or operating SOAR platforms and automated playbooks.
  • Strong understanding of endpoint, identity, network, cloud, email, and SaaS telemetry, including logging, evidence collection, and containment actions across modern environments.
  • Experience collecting and using forensic artifacts to support investigations across endpoints, identities, cloud services, email, or SaaS platforms.
  • Ability to design for scale, repeatability, automation, reliability, and reduced response time in a production security environment.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Digital Forensics, or a related field, or equivalent practical experience.

Benefits

  • medical, dental and vision insurance
  • 401(k)
  • paid leave
  • tuition reimbursement
  • a variety of other discounts and perks

Related Job Pages

More Incident Response Analyst Jobs

Honeywell logo

Fire Department Incident Response Expert

Honeywell

Honeywell is an award-winning Fortune 100 company that aims to make the world a more sustainable, cleaner, secure, productive, and connected place with the help of its innovative t

Role Description As a Fire Emergency Services Success Expert here at Honeywell, you will be instrumental in ensuring the success of our fire emergency services solutions. You will have the opportunity to work closely with customers to provide expert guidance and support, ensuring that their fire safety systems are effectively implemented and maintained. Your expertise will be critical in driving customer satisfaction and enhancing the overall performance of our fire emergency services. In this role, you will work remotely in the US. You will impact the safety and security of our customers' facilities by providing exceptional support and solutions that meet their fire safety needs. Your commitment to excellence will help ensure that our customers can rely on our systems for their safety and compliance requirements. Qualifications - Expertise in fire emergency services solutions - Strong customer support and guidance skills - Ability to ensure effective implementation and maintenance of fire safety systems - Commitment to customer satisfaction and safety compliance Requirements - Remote work capability in the US Benefits - Opportunity to work with a trusted partner in automation and safety - Access to innovative solutions and technologies Company Description Honeywell helps organizations solve the world's most complex challenges in automation, the future of aviation and energy transition. As a trusted partner, we provide actionable solutions and innovation through our Aerospace Technologies, Building Automation, Energy and Sustainability Solutions, and Industrial Automation business segments – powered by our Honeywell Forge software – that help make the world smarter, safer and more sustainable.

United States
$120K - $160K / year
Rapid7 logo

Associate Detection and Response (MDR) Analyst

Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

Full TimeRemoteTeam 1,001-5,000Since 2000H1B Sponsor

Rapid7's Tactical Operations team is looking for an Associate Detection & Response Analyst to tackle time-critical security investigations and safeguard our global customers. This foundational role empowers you to hunt down malicious behavior, steer end-to-end incident analyses, and collaborate with a world-class team of analysts to stay ahead of the security curve. If you are a curious, driven problem-solver eager to launch your career in cybersecurity, this is your opportunity to make a collective impact from day one. About the Team The Tactical Operations team (TACOPS) handles the most time-critical tasks for all customers, executing the investigation and triage of high-priority security alerts using our cloud-hosted SIEM, InsightIDR. This collaborative team drives business and customer outcomes by combining individual technical skills with collective knowledge to identify threats and deliver robust remediation recommendations. About the Role As an Associate Detection & Response (MDR) Analyst, your primary responsibility will be to investigate and triage high-priority security alerts to identify malicious activity in customer environments. Specifically, your focus will be to: - Review alert data to identify malicious activity and potential security threats across diverse customer environments - Steer security investigations from initial alert through comprehensive evidence acquisition and root-cause analysis - Write technical incident reports documenting key findings, analysis methodologies, and actionable remediation recommendations for customers - Coordinate closely with SOC advisor colleagues to support effective communication of technical findings to the customer - Partner with Mid, Senior, and Lead Analysts to collaboratively solve complex challenges and share knowledge across the SOC team - Perform targeted investigation tasks and examine forensic artifacts during critical Remote Incident Response engagements - Track threat actor actions across an environment by analyzing system and forensic logs during security incidents - Maintain a flexible operational rhythm, working in the physical SOC two days per week (including Wednesdays) and adhering to the dedicated afternoon shift schedule The skills and qualities you'll bring include: - Adaptability to work a fixed shift rotation from Monday to Thursday, 11 AM - 9 PM, following a comprehensive 90-day onboarding period. - Professional or academic experience spanning 0-2 years within technology, systems administration, or information security environments - Foundational knowledge of core security concepts including lateral movement, privilege escalation, persistence methods, and command and control - Working familiarity with Windows and Linux operating systems and their underlying security architectures - Training in red team/blue team learning tools such as HackTheBox, TryHackMe, and LetsDefend and/or participation in CTF events is a plus - Scripting/coding ability and/or Security Certifications (GFACT, GSEC, GCIA, GCIH, CySA+, CASP+, Security+, etc.) is a plus - Creative problem-solving abilities, critical thinking capacity, and technical ingenuity when addressing complex challenges - Insatiable curiosity and a strong forward focus, demonstrating a passionate commitment to learning and developing your cybersecurity craft - Eagerness and open communication when navigating change, adapting smoothly to evolving business needs, shift structures, and group dynamics - Capacity to make efficient, structured choices that resolve challenges and maintain analytical momentum during high-pressure incidents - Clear accountability for actions and behaviors while driving outcomes that deliver genuine value for the business and our customers - Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. #LI-SIM About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.

Czechia
Job Closed
TEKsystems logo

Incident Response Lead

TEKsystems

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia.

ContractRemoteTeam 10,001H1B No Sponsor

Role Description The Incident Response, Lead will work with IT stakeholders across the Health Care System to develop policies, procedures, and risk management activities that will efficiently contain and/or minimize the impact of business interruption due to disasters and/or information systems not being available. This role carries 24/7 on-call rotation responsibilities and active incident command expectations during major and critical events. - Perform risk and triage analysis to develop incident response plans and runbooks for the most likely and highly impactful disasters. - Assist IT and business stakeholders in testing incident response plans by developing downtime scenarios, tabletops, and other exercises. Qualifications - BS/BA degree in Information Technology, Business Administration, Risk Management, or a related field required. In lieu of the BS/BA degree, may accept a high school diploma and 7 years of experience. - 4+ years' experience in incident response management or a related field required. - Strong knowledge of industry standards and frameworks such as ISO 22301 or NIST SP 800-34. - Strong understanding of project management principles and data technologies, expert-level knowledge of IT Service Management principles, best practices, and frameworks such as ITIL. - Expert-level knowledge of IT Service Management principles, frameworks, and best practices (ITIL) preferred. - Expert-level ServiceNow experience — incident workflows, ticket quality, auditing, and reporting preferred. - Proven ability to lead live incident response under pressure. - On-call availability; experience in 24/7 rotation environments. - Strong understanding of project management principles and data technologies preferred. Requirements - Experience in healthcare IT environments preferred. - ITIL 4 Foundation certification or higher preferred. - Hands-on experience building or facilitating DR tabletop exercises preferred. - Experience building or auditing runbook libraries preferred. - Familiarity with clinical system availability requirements preferred. - Strong executive communication and reporting skills preferred. Benefits - Medical, dental & vision. - Critical Illness, Accident, and Hospital. - 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available. - Life Insurance (Voluntary Life & AD&D for the employee and dependents). - Short and long-term disability. - Health Spending Account (HSA). - Transportation benefits. - Employee Assistance Program. - Time Off/Leave (PTO, Vacation or Sick Leave). Job Type & Location This is a Contract position based out of Fort Worth, TX. Fully remote but MUST SIT IN TEXAS. Pay and Benefits The pay range for this position is $53.00 - $82.00/hr. Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. Application Deadline This position is anticipated to close on Jun 12, 2026.

United States
$53 - $82 / hour
Job Closed
Autodesk logo

Senior Incident Commander

Autodesk

How the world gets designed and made. #MakeAnything

Full TimeRemoteTeam 10,001+Since 1982H1B No Sponsor

Role Description Want to help make a better world? As Incident Commander and Analyst at Autodesk you can do just that. You will shape the frontier of customer facing cloud services support at Autodesk by being an elite, Senior Incident Commander, and Analyst. Your finger will be on the pulse of Autodesk Cloud Services that empower our customers to “Make Anything”. At Autodesk, we believe that incidents are unplanned investments so, your focus will be as a member of a cadre that drives incidents to resolution and extracts deep learnings from them. Reporting to the Customer Facing technology operations organization, you demonstrate the ability to operate independently, collaborate with cross-functional teams to ensure that customer impact is mitigated, and incidents are fully understood. Above all, you help Autodesk deliver the highest quality of service for all the customers we serve. Responsibilities - You are a superior communicator. Written, verbal, and nonverbal language are all essential skills to be an effective and trustworthy leader. - You understand how to negotiate across multiple stakeholders and points of view. - You can develop and maintain strong relationships with team members by mutual earned respect and the ability to persuade with facts, logic, enthusiasm, and a proven track record. - Act in the role of an Incident Commander to facilitate high-severity incident triage. - Ensure that high-severity incidents achieve the necessary cross-functional engagement to drive them to resolution in a timely fashion. - Communicate clear updates to stakeholders in a timely fashion. - Participate in on-call rotation for Incident Commander role for after hours and weekends. - Participate in regular review of open Incidents and evaluate if Level1 (Cloud SOC) and Level2 (DevOps) teams are remediating incidents in a timely and effective manner. - Drive the use of incident metrics and perform a first-level analysis of incident data to gain insights as to service performance and patterns of emerging issues. - Run regular Incident Review meetings with Cloud Operations cross-functional teams. - Provide oversight for Cloud Service Operation Centre Level 1 engineer performance. - Run post-incident debrief meetings to drive engagement with incident responders. - Analyse incidents using an interview-based approach to extract deep learnings from incidents allowing the organization’s knowledge to grow as a result. - Engage with cross-functional Engineering Teams to ensure that Incident follow-up (forensic) activities are happening in a timely fashion. - Develop and implement data analyses, data collection, and other strategies that optimize platform resiliency and quality. - Work with Autodesk Engineering teams and leaders to recommend improvements based on analysis. - Act as a facilitator for on-boarding of new services to the Cloud SOC. - Perform required periodic review of new and revised runbooks, evaluating them for their efficacy and relevance. Qualifications - 10+ years of experience in a similar operations function within a high availability (HA), 24x7, mission critical operations environment providing or leading front-line support for a public-facing service with a high-volume, paying customer base. - 3-5 years’ experience leading or defining processes for high availability production environments or services. - Bachelor’s degree in computer science or a related technology field or equivalent experience. - Proficient in effectively communicating to a wide range of audiences in both written and oral form. - Ability to participate in an on-call rotation for the Incident Commander role including off-hours and weekends. - Must be process-oriented, energetic and an analytical thinker. - Ability to understand how technical deployments and outages impact customers and partners, and the experience to drive mitigation. - Solid understanding of basic Amazon Web Services infrastructure services, with exposure to serverless technologies, such as Aurora and Lambda. - Solid understanding of concepts and technologies such as cloud computing, server clusters, high availability network configurations, DNS, SMTP, NTP, NAS and HTTP. - Able to assimilate knowledge of new systems quickly and be adaptable. Preferred Qualifications - 8+ years of experience in a similar operations function within a high availability (HA), 24x7, mission critical operations environment. - Experience with Jira, Confluence and ServiceNow. - AWS Certifications. - Knowledge of incident analysis, problem, and change management practices. - Understanding of Dynatrace, Catchpoint, and similar observability tools. - Experience with defining and maintaining operational processes. - Experience administering Amazon Web Services accounts and instances, or network infrastructure (switches, routers, firewalls, etc.). - Experience defining, analysing, and maintaining Operational Reports such as SLA and Outage reports, Operations Performance reports, Maintenance reports, Operations Containment reports, etc. - Experience with Managed Service Providers particularly with global accounts. Benefits - From health and financial benefits to time away and everyday wellness, we give Autodeskers the best, so they can do their best work.

United States
$112K - $200.9K / year
Job Closed