
Engineer III – Cyber Incident Response
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in India.
• Oversee the investigation and resolution of intricate security incidents, including advanced persistent threats, ransomware, phishing attacks, and insider threats.
• Conduct forensic analysis across endpoints, networks, and cloud platforms to determine root causes and the extent of compromises.
• Create and refine incident response playbooks, runbooks, and detection use cases.
• Work in conjunction with threat intelligence, vulnerability management, and countermeasures teams to bolster defenses.
• Elevate high-severity incidents to senior management and provide concise, actionable reports.
• Serve as a technical escalation resource for Engineer I/II analysts during incident investigations.
• Participate in red team and purple team exercises.
• Engage in after-action reviews and lessons-learned sessions to enhance SOC processes.
• Mentor and instruct junior engineers on best practices in incident response and investigative techniques.
• Collaborate with global cyber defense teams to ensure prompt and effective responses to advanced threats.
• A Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field is required, or equivalent work experience.
• A Master’s degree is preferred.
• A minimum of 7 years of progressive experience in the cybersecurity field.
• At least 4 years of experience in incident response or SOC operations.
• Over 4 years of experience in incident response, digital forensics, or advanced threat hunting is mandatory.
• Strong understanding of incident response methodologies, digital forensics, and adversary tactics.
• Familiarity with NIST, MITRE ATT&CK, and ISO 27035 is required.
• Practical experience with SIEM, EDR, SOAR, and forensic tools such as Splunk, CrowdStrike, EnCase, and Wireshark.
• Proven capability to investigate advanced threats and coordinate response efforts across teams.
• Demonstrated success in mentoring junior analysts and enhancing SOC processes.
• Excellent written and verbal communication skills with the ability to document and present technical findings clearly.
• Advanced proficiency in a primary technical area with an expanding breadth across related security domains.
• Industry-relevant certifications such as GCFA, GCIH, and CISSP are preferred.
• Benefit offerings outside the US may vary by country and will be aligned with local market practices.
• Equal employment opportunity and reasonable accommodations during the employment process.
Cencora
Cencora
Cencora
HBK - Hottinger Brüel & Kjær
Get handpicked remote jobs straight to your inbox weekly.