Source Job

$128,000–$161,000/yr
US

  • Design, implement, and maintain advanced detection rules across SIEM, EDR, and Cloud platforms.
  • Develop complex automated response playbooks for multi-stage incidents and integrate security tools via APIs.
  • Co-lead the organization's threat hunting program, defining strategy, methodology, and campaign planning.

Python SOAR

20 jobs similar to Senior Incident Response Engineer

Jobs ranked by similarity.

US

  • Lead incident response efforts for high-severity and complex security events.
  • Perform advanced threat analysis, including APT detection and analysis of threat actor tactics.
  • Lead continuous improvement initiatives for SOC processes, workflow automation, and detection coverage.

Brightspeed is providing fast, reliable internet connections and customer experience in twenty states throughout the Midwest and South. They are backed by funds managed by Apollo Global Management and are upgrading copper to fiber optic technologies.

$119,000–$127,000/yr
US

  • Using Red Canary’s detection platform to analyze EDR telemetry, alerts, and log sources.
  • Researching coverage opportunities then creating new detectors, and tune existing ones.
  • Improving the Detection Engineering workflow through orchestration & automation

Zscaler, founded in 2007, aims to make the cloud a safe place for business. They operate the world’s largest security cloud, using AI to protect enterprises from cyberattacks and data loss, fostering an inclusive and supportive culture.

$119,000–$127,000/yr
US

  • Using Red Canary’s detection platform to analyze EDR telemetry, alerts, and log sources.
  • Researching coverage opportunities then creating new detectors, and tune existing ones.
  • Improving the Detection Engineering workflow through orchestration & automation.

Zscaler accelerates digital transformation, protecting customers from cyberattacks and data loss. They value transparency and constructive debate, building high-performing teams focused on customer obsession, collaboration, ownership, and accountability.

Europe

  • Lead the design, develop, and implementation of incident response playbooks.
  • Be part of a weekly on-call rotation and support in detection engineering.
  • Identify areas for security improvement and translate that into workable solutions.

Ping Identity's cloud identity platform enables secure and seamless digital experiences. They are headquartered in Denver, Colorado, with offices and employees around the globe, serving large enterprises.

ANZ

  • Lead detection engineering initiatives end-to-end, from threat research and design documentation through implementation, testing, and production deployment.
  • Partner with Application Security, CTI, and Red Team to conduct threat modelling, translate threat intelligence into actionable detections, and validate detection effectiveness through threat simulation scenarios.
  • Create automation and enrichment pipelines that reduce manual context-switching and cognitive load for analysts, improving mean-time-to-detect, analyse, and respond to security events.

Canva is a design platform that enables users to create various visual content. They foster a fun and collaborative environment with flexible work arrangements.

Global

  • Own and lead incident response process and actively investigate events.
  • Prioritize alerts based on risk and collaborate with stakeholders for remediation.
  • Design, implement, and maintain comprehensive security dashboards and generate periodic reports.

Deel is the all-in-one payroll and HR platform for global teams with a vision to unlock global opportunity for every person, team, and business. As one of the largest globally distributed companies, Deel's team of 7,000 spans more than 100 countries and speaks 74 languages.

$162,000–$253,000/yr
US

  • Define security detection program strategy and roadmap.
  • Oversee development, testing, and maintenance of detection logic.
  • Lead and mentor a high-performing team of security operators.

Cribl helps solve IT and Security's data needs. They foster a collaborative, curious, and motivated team environment where employees are passionate about putting customers first and believe in empowering our employees to do their best work, wherever they are.

$137,065–$160,000/yr
US

  • Oversee Endpoint Detection and Response (EDR) by guiding mid-level engineers in deploying and fine-tuning EDR solutions.
  • Lead Next-Generation Antivirus (NGAV) implementation by supervising the setup and configuration of behavioral-based protection.
  • Direct Threat & Vulnerability Management by overseeing continuous vulnerability assessments and providing remediation recommendations.

EXPANSIA is a service-disabled veteran-owned company that empowers organizations to be mission ready now with data, people, and ecosystems. As experts in continuous-delivery methods that drive digital adoption, they are dedicated to innovation, efficiency, and technology that benefit the warfighter.

$300,000–$405,000/yr
US

  • Build automated detection systems that use disparate signals to identify abusive behavior.
  • Take systems from idea to proof-of-concept to production-grade with appropriate monitoring, documentation, and maintenance processes
  • Develop and maintain YARA rule infrastructure, including tools for writing, validating, and testing rules against real data

Anthropic's mission is to create reliable, interpretable, and steerable AI systems to be safe and beneficial for users and society. Their team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.

US

  • Monitor and analyze security alerts to identify potential threats.
  • Conduct proactive threat hunting across different environments.
  • Investigate security incidents and determine root cause.

Globe Life is committed to empowering employees with support and opportunities to succeed in their careers. They foster a caring and innovative culture that enables them to grow and overcome challenges in a connected and collaborative environment.

$93,500–$126,500/yr
US Unlimited PTO

  • Advise tuning of SIEM correlation rules and use cases to identify security incidents and anomalies.
  • Monitor SIEM alerts, triage, and respond to security incidents in a timely manner, escalating as necessary to the appropriate team(s) for further investigation and remediation.
  • Perform Third Party/Supply Chain Risk Management reviews, to include security research and audit report analysis.

Defense Unicorns delivers mission value by streamlining software delivery so our customers can focus on the most important challenges. Our team is composed of innovators, software engineers, and veterans with decades of experience delivering technology programs across the federal market.

Mexico

  • Serve as the lead strategic advisor and subject matter expert for customers undertaking a full-scale SOC modernization with XSIAM.
  • Lead multi-national SOC transformation programs, consolidating fragmented detection and response processes into a unified, AI-driven platform.
  • Direct enterprise-scale XSIAM deployments, guiding customers from initial strategy through full operationalization.

Palo Alto Networks' mission is to be the cybersecurity partner of choice, protecting our digital way of life. They challenge and disrupt the way things are done, and are looking for innovators committed to shaping the future of cybersecurity.

$115,747–$208,344/yr
US 4w PTO

  • Monitor the daily operations of the team, being the primary liaison between analysts and leadership
  • Oversee response activities for security events and alerts associated with cyber threats, intrusions, or compromises
  • Be a mentor to Cyber Defense Analysts, providing feedback on the quality of work to analyst(s) and management

Experian is a global data and technology company, powering opportunities for people and businesses around the world. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), they have a team of 22,500 people across 32 countries and corporate headquarters in Dublin, Ireland.

$115,600–$160,000/yr
US

  • Own the configuration, tuning, and management of our SIEM solution.
  • Perform architecture reviews, code reviews, and infrastructure configuration reviews.
  • Maintain and optimize a vulnerability management CI/CD pipeline within our container/application delivery infrastructure.

Engine is transforming business travel into something personalized, rewarding, and simple. More than 20,000 companies already rely on Engine to support over 1 million travelers and billions in annual bookings each year.

Australia New Zealand

  • Analyse incoming threat signals to produce actionable intelligence products.
  • Maintain intelligence infrastructure and automation workflows.
  • Conduct independent research on emerging threats and maintain a library of adversaries.

Canva is a design platform that enables users to create a variety of visual content. They have offices in Sydney and Melbourne, as well as co-working spaces in other Australian cities, and they values a flexible work environment.

US

  • Develop and implement AI-driven solutions for threat detection.
  • Automate security workflows, including vulnerability management.
  • Collaborate with security operations, architecture, and engineering teams.

Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories. They are dedicated to uplifting everyone, everywhere by being the best way to pay and be paid and offer the opportunity to create impact at scale.

US

  • Develop, deploy, and optimize bot-mitigation and service-abuse controls.
  • Develop and maintain automated detection capabilities leveraging IP/ASN intelligence.
  • Lead bot-related incident response activities, including triage, containment, and root-cause analysis.

Best Egg is a market-leading, tech-enabled financial platform helping people build financial confidence through a variety of installment lending solutions and financial health tools. They offer top-tier benefits and growth opportunities in a culture built on their core values and foster an inclusive, flexible, and fun workplace.

$83,200–$124,800/hr

  • Review detection alerts, triage workflows, and escalation pathways
  • Evaluate completeness, accuracy, and quality of incident response actions
  • Identify gaps in logging, detection coverage, and containment logic

Alignerr is a recruiting company. The job posting does not contain information about company size, employee count or culture.

US

  • Monitor, investigate, triage, and respond to security alerts.
  • Perform advanced network analysis and conduct log analysis.
  • Assist with EDR investigations and support the Incident Response Team.

Industrial Electric Mfg. (IEM) is the largest independent full-line manufacturer of custom power distribution systems in North America. With $1B+ in annual sales and 10,000+ commissioned projects across technology, data centers, commercial, energy, utilities, healthcare, industrial, and infrastructure markets, IEM continues to deliver exceptional product quality, dependable service, and the flexibility to meet complex technical requirements at scale.

$93,500–$126,500/yr
US Unlimited PTO

  • Monitor SIEM alerts, triage incidents, and escalate as needed to ensure timely resolution
  • Conduct third-party and supply chain risk management reviews, including audit report analysis
  • Collaborate with engineering, IT, and operations teams to integrate and maintain security controls

Jobgether uses an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. It identifies top-fitting candidates and shares this shortlist with the hiring company.