Job Closed
This listing is no longer active.
Here you can create the extraordinary. Join us.
Senior Cyber Incident Response Engineer
Location
Florida
Posted
16 days ago
Salary
$140K - $175K / year
Seniority
Senior
Job Description
Senior Cyber Incident Response Engineer
NBCUniversal
• Design, build, and improve automated evidence collection capabilities that increase the speed, consistency, and completeness of incident investigations. • Create and maintain SOAR playbooks that orchestrate investigation, enrichment, containment, notification, and recovery workflows. • Integrate SIEM, EDR, IAM, cloud, email, case management, and threat intelligence platforms to enable unified response actions and stronger analyst context. • Develop and deploy response tooling that may utilize AI to improve response capabilities across cloud, endpoint, identity, SaaS, email, and data platforms. • Develop scripts, tools, and integrations that support triage, containment, enrichment, forensic collection, and operational response workflows. • Ensure responders have the logs, telemetry, access, and tooling needed to investigate and respond without unnecessary delay. • Build dashboards, operational views, and incident metrics that measure response performance, workflow health, and process effectiveness. • Identify repeated manual analyst tasks and turn them into safe, scalable, and repeatable automation. • Review incident response plans, identify readiness gaps, and help develop practical strategies to improve preparedness. • Design and optimize incident response playbooks aligned to relevant threats, operating models, and business needs to allow for quick identification and response to potential incidents. • Collaborate with Response Operations and Automation team stakeholders for prioritization, automation creation, and integrations with security tooling. • Facilitate or support tabletop exercises, drills, and readiness activities to validate plans and improve operational performance. • Lead or support complex investigations involving host, network, identity, email, and cloud artifacts to determine nature, scope, and root cause. • Partner with cross-functional teams to guide containment, remediation, recovery, and post-incident improvement activities. • Brief technical teams and leadership on findings, risks, recommendations, and response decisions during and after incidents. • Contribute to incident response standards, methodologies, documentation, and internal knowledge sharing. • Participate in an incident response on-call rotation, including weekend coverage, as required.
Job Requirements
- 5+ years of relevant cybersecurity experience in either incident response, DFIR, detection engineering, threat hunting, and or SOC escalation
- 2+ years of security automation / cyber defense engineering
- Strong proficiency with Python, PowerShell, Bash, or similar scripting languages used for automation and response engineering.
- Ability to lead projects with little guidance, and strong communication
- Knowledge of SIEM, SOAR, EDR, Data Lake, and enterprise security tooling and methodologies.
- Experience handling security incidents and investigating a multitude of cyber threats with various TTPs across multiple enterprise platforms
- Experience building and maintaining API integrations across security and enterprise platforms.
- Working knowledge of SIEM query languages such as SPL, KQL, SQL, or equivalent analytics languages.
- Experience with EDR response actions, investigation workflows, and endpoint containment techniques.
- Experience designing, building, or operating SOAR platforms and automated playbooks.
- Strong understanding of endpoint, identity, network, cloud, email, and SaaS telemetry, including logging, evidence collection, and containment actions across modern environments.
- Experience collecting and using forensic artifacts to support investigations across endpoints, identities, cloud services, email, or SaaS platforms.
- Ability to design for scale, repeatability, automation, reliability, and reduced response time in a production security environment.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, Digital Forensics, or a related field, or equivalent practical experience.
Benefits
- medical, dental and vision insurance
- 401(k)
- paid leave
- tuition reimbursement
- a variety of other discounts and perks
Related Guides
Related Categories
Related Job Pages
More Incident Response Analyst Jobs
CIS SERVICE DELIVERY MANAGEMENT-CIS INCIDENT MANAGEMENT
ZensarAt Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.
Role Description - Own and deliver security governance and control activities, including ITGC execution, audit readiness, and evidence tracking. - Maintain and update the ISO27001 ISMS, including policy and standards refresh and controlled publication. - Drive Segregation of Duties (SoD) remediation across finance systems within defined timelines. - Coordinate and complete third-party assurance questionnaires, including SIG Lite and broader SIG processes. - Support GIA governance audits, ensuring evidence readiness and action tracking. - Deliver operational resilience and BCP artefacts, ensuring alignment with regulatory expectations. - Support cloud/platform security onboarding (GCP VMSP), ensuring controls and reporting are in place. - Manage IAM/IDAM onboarding, role management, and reporting discipline. - Drive data classification and labelling rollout activities aligned to global standards. - Coordinate penetration testing preparation, stakeholders, and follow-up actions. - Establish and maintain monthly security reporting, including 1st and 2nd line inputs. - Standardise and embed Security KRIs across reporting cycles. - Support TechComm reporting (UK and VN) ensuring clarity and consistency. - Drive Wiz deployment and operationalisation, embedding it into BAU processes. - Support security awareness and notification processes, including joiners/leavers activities. Company Description At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore Life at Zensar and join us to Grow. Own. Achieve. Learn. to be the best version of yourself. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.
Cyber Incident Handler
Kontoor Brands, Inc.A global apparel company with a portfolio led by two of the world’s most iconic consumer brands: Wrangler® and Lee®.
Role Description Reporting to the Manager of Cyber Defense, the Cyber Incident Handler will be a highly technical individual who will, along with internal and external partners, drive the monitoring, detection and incident management capabilities within Kontoor’s Global Information Security organization. This position will heavily influence the implementation of a forward thinking cyber defense program, including next generation cloud based monitoring solutions; developing threat hunting capabilities within that platform. The Cyber Incident Handler must be comfortable working in a fast-paced, collaborative, entrepreneurial environment. The person in this role must be comfortable working with ambiguity and demonstrate outstanding communication skills. Responsibilities - Provide Tier 2 support for escalations from an MDR service - Drive improvements to event analysis operations and security automation - Develop threat hunting capabilities and new Use Cases for implementation in the SIEM - Review and take a proactive approach to false positives and work with the various Security teams to tune and provide feedback to improve accuracy of the alerts - Lead small to medium size projects as directed by management Qualifications - Intern or similar entry level experience in an IT role desired - Security certification/accreditation from Offensive Security, ISC2 (CISSP), and/or GIAC are highly desired - Bachelor’s degree in computer science, information systems, computer engineering, electrical engineering, system analysis or related field of study, or equivalent experience Requirements - Exceptional interpersonal skills, including teamwork, facilitation, and negotiation - Excellent written, verbal, communication, and presentation skills Leadership Competencies Expected for this Role - Foundational Leader - Global Agility – Be open and adapt quickly when things change - Purposeful Integrity – Do the right thing, even when no one is watching - Strategic Foresight – Think ahead and plan for what’s coming - Customer Centric Innovation – Find better ways to serve our customers - Urgency for Impact – Act fast and get results that matter - Bold Accountability – Take ownership of your work and results - Empowered Collaboration – Work well with others to get things done Benefits - Comprehensive benefit package to fit your lifestyle - Competitive benefits program that provides choice and flexibility - Resources to support your physical, emotional, social, and financial wellbeing - Discounts on our apparel - Four weeks of Paid Parental Leave to eligible employees who are new parents - Flexible Fridays - Tuition Reimbursement Company Description Kontoor Brands is a portfolio of three of the world’s most iconic lifestyle, outdoor and workwear brands: Wrangler®, Lee® and Helly Hansen®. Kontoor Brands is a purpose-led organization focused on leveraging its global platform, strategic sourcing model and best-in-class supply chain to drive brand growth and deliver long-term value for its stakeholders.
Critical Incident Clinician
LifeWorksTELUS Health is empowering every person to live their healthiest life. Guided by our vision, we are leveraging the power of our leading edge technology and focusing on the uniqueness of each individual to create the future of health. Global-leading health and well-being provider encompassing physical, mental, and financial health. Improving health outcomes for consumers, patients, healthcare professionals, employers, and employees.
Role Description TELUS Health is looking for a Critical Incident Management Clinician to join our Australia team and deliver critical psychological support when it matters most. In this role, you'll be at the frontlines of crisis response—providing immediate, compassionate psychological support to individuals and organizations affected by traumatic events. You'll conduct rapid risk assessments, facilitate group interventions, liaise with organizational stakeholders, and maintain the clinical excellence that saves lives. Qualifications - Minimum 3 years of post-qualification experience - Experience in crisis management and trauma response - Full registration with AHPRA or AASW - Mastered critical incident stress management and psychological first aid - Confident conducting risk assessments in high-pressure situations Requirements - Flexible - Ready to shift your schedule, hop on an early flight, or travel inter-state at short notice - Thrives under pressure - Stays calm, focused, and clinically sound when others are in crisis - Communicates with sensitivity - Words de-escalate, stabilize, and support - Thinks independently - Makes sound judgments in the field without hesitation - Embraces cultural competency - Works respectfully with diverse populations across Australia - Commits to excellence - Engages in ongoing supervision, training, and professional development Benefits - Meaningful Impact - Direct contribution to TELUS Health's mission of improving health outcomes and building a healthier future - Professional Growth - Access to clinical supervision, training, and ongoing professional development - Flexibility - 100% remote when not onsite - Diverse Reach - Support individuals and organizations across Australia - Expert Community - Collaborate with experienced multidisciplinary teams
• Design, build, and improve automated evidence collection capabilities that increase the speed, consistency, and completeness of incident investigations. • Create and maintain SOAR playbooks that orchestrate investigation, enrichment, containment, notification, and recovery workflows. • Integrate SIEM, EDR, IAM, cloud, email, case management, and threat intelligence platforms to enable unified response actions and stronger analyst context. • Develop and deploy response tooling that may utilize AI to improve response capabilities across cloud, endpoint, identity, SaaS, email, and data platforms. • Develop scripts, tools, and integrations that support triage, containment, enrichment, forensic collection, and operational response workflows. • Ensure responders have the logs, telemetry, access, and tooling needed to investigate and respond without unnecessary delay. • Build dashboards, operational views, and incident metrics that measure response performance, workflow health, and process effectiveness. • Identify repeated manual analyst tasks and turn them into safe, scalable, and repeatable automation. • Review incident response plans, identify readiness gaps, and help develop practical strategies to improve preparedness. • Design and optimize incident response playbooks aligned to relevant threats, operating models, and business needs to allow for quick identification and response to potential incidents. • Collaborate with Response Operations and Automation team stakeholders for prioritization, automation creation, and integrations with security tooling. • Facilitate or support tabletop exercises, drills, and readiness activities to validate plans and improve operational performance. • Lead or support complex investigations involving host, network, identity, email, and cloud artifacts to determine nature, scope, and root cause. • Partner with cross-functional teams to guide containment, remediation, recovery, and post-incident improvement activities. • Brief technical teams and leadership on findings, risks, recommendations, and response decisions during and after incidents. • Contribute to incident response standards, methodologies, documentation, and internal knowledge sharing. • Participate in an incident response on-call rotation, including weekend coverage, as required.

