For Employers

Pearl Consulting Group

Engineer - Security Operations and Incident Response

Posted 4 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The engineer will lead the transformation of security operations and incident response programs by performing deep-dive investigations and digital forensics. They are also responsible for developing automated remediation workflows, refining detection rules, and maintaining threat models to protect the global enterprise.

Job Title: Engineer - Security Operations and Incident Response 

Location: USA or Canada (Remote or Hybrid) 

Description

This role is a critical function responsible for the ongoing transformation of the organization’s Security Operations & Incident Response program. With a focus on maintaining resilience and protecting the global enterprise from cybersecurity threats, the team operates an advanced security operations and incident response program focused on the identification, analysis, and eradication of cybersecurity threats and incidents across the global enterprise. In support of the rapid growth of this critical program, we are looking for an experienced, passionate, and highly organized engineer who will drive operational delivery excellence and continuous advancement across processes and technologies.

Primary Responsibilities

  • Expert-level support for deep dive investigations, including digital forensics (memory, network, and malware analysis).
  • Author and refine IR playbooks and operational guidelines to ensure the team remains agile in an evolving threat landscape.
  • Develop and maintain threat models, incorporating findings from penetration tests into detection strategies.
  • Design, implement, and refine complex detection rules and automated remediation workflows to identify adversarial behavior.
  • Utilize threat intelligence and the MITRE ATT&CK framework to identify gaps in visibility and proactively mitigate emerging risks.
  • Maintain comprehensive documentation of detection strategies, active investigations, and incident timelines.
  • Work with the SIEM team to continuously tune SIEM rules to maximize detection fidelity while minimizing alert fatigue.
  • Review and tune threat intelligence systems, including brand protection and dark web monitoring.
  • Proficiency in scripting and query building using Python, XQL, PowerShell, or Bash, and experience with automation and/or orchestration (SOAR) tools.
  • Support IR leadership as backup on IR-related activities.

Qualifications

  • Bachelor’s degree and 5+ years of relevant experience in incident response and SOC tooling.
  • In-depth knowledge of SIEM/SOAR platforms (e.g., Microsoft Sentinel, Palo Alto Cortex XSIAM/XSOAR) and incident response processes in hybrid cloud environments (GCP, Azure).
  • Experience leading incident response as incident commander, performing root cause analysis and continuous optimization for SOC tools and processes.
  • Familiarity with scripting languages (Python, PowerShell, Bash, XQL) is highly preferred.
  • Understanding of regulatory compliance and frameworks such as MITRE ATT&CK, NIST, or ISO.
  • Ability to prioritize tasks effectively, manage multiple priorities, and work both independently and as part of a team.
  • Strong communication skills, with the ability to translate sophisticated technical issues or concepts to non-technical audiences in a clear and concise manner that focuses on business value.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Assistant Vice President - Data Analytics – Retirement Division - Remote

Full Time United States $188K - $314K per year Software Development

Sr AI/ML Engineer (LATAM Remote)

Full Time Mexico, United States Software Development

Solution Architect

Full Time Portugal Software Development

Infrastructure Reliability Engineer

Full Time United States $100K - $150K per year Software Development

AI Operations Engineer

Full Time United States $150K - $165K per year Software Development

AI Data Platform Engineer

Full Time United States $100K - $150K per year Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 220,094+ Jobs in Software Development

Answer easy questions

Answer easy questions

220,094+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified