Source Job

Canada

  • Lead security incidents end-to-end, from detection and triage through containment and post-incident review, acting as incident commander.
  • Conduct hands-on investigations across cloud and endpoint environments to determine root cause and impact, and partner with Observability & Automation to improve detections and build automated playbooks.
  • Collaborate with Security, Infrastructure, and Product teams to identify gaps, strengthen the incident response lifecycle, and communicate effectively with both technical and non-technical stakeholders.

AWS Incident Response SIEM Python

20 jobs similar to Sr. Security Operations Engineer, Incident Response

Jobs ranked by similarity.

India

  • Receive and own L2 escalations across all severity levels; take over technical lead role on Sev2+.
  • Perform deep-dive endpoint triage via EDR: process tree analysis, remote artifact collection, behavioral event review, and custom detection rule evaluation.
  • Conduct structured threat hunts in the SIEM using detection rule logic, event correlation queries, and multi-source pivoting.

AlphaSense empowers the world’s most sophisticated companies to make decisions with confidence, providing market intelligence and search built on proven AI. We have over 2,000 employees across the globe with offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland and are trusted by over 6,000 enterprise customers.

$145,000–$155,000/yr
US

  • Participate in a rotating on-call, based on the number of team members.
  • Serve as a hybrid Incident Response (IR) and Digital Forensics (DFIR) function.
  • Perform forensic analysis on a variety of networks, hosts, digital media, and operating systems/environments.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. We pride ourselves on providing our employees with great benefits and career development opportunities and are committed to growing careers as we are to building world-class IT solutions.

$231,089–$265,930/yr
US

  • Execute on milestones for end-to-end SecOps & Threat initiatives in accordance with the Security roadmap.
  • Identify and respond to complex security incidents, including system compromise, intrusion attempts, and/or denial of service attacks by conducting continuous monitoring, vulnerability assessments, and log analysis.
  • Research emerging threats, publicly disclosed vulnerabilities or attack vectors, and proactively push mitigating controls to products and services.

6sense's mission is to multiply what matters: growth, retention, and efficiency. They envision a future where companies, teams and people reach their full potential. People are the heart and soul of the company with a growth mindset culture that is represented in all that they do.

$110,000–$140,000/yr
US

  • Perform systems administration and maintenance including patching and vulnerability scanning.
  • Primarily support AWS environments, including Windows and Linux virtual machines.
  • Troubleshoot issues across network, compute, application, and identity layers.

Tyto Athene delivers mission-focused digital transformation through IT services and solutions. They have over 50 years of experience and foster a collaborative, innovative, and mission-driven environment.

$172,279–$249,640/yr
US Canada

  • Build and maintain a SIEM to collect and analyze logs, writing detections and alerts.
  • Design and deploy canary tokens and early warning mechanisms to detect threats.
  • Investigate security incidents end-to-end and build runbooks to scale response capabilities.

Quora's mission is to grow the world's collective intelligence, providing platforms for knowledge sharing and AI interaction. It's a remote-first company with passionate, collaborative, and high-performing global teams, fostering a culture rooted in transparency, idea-sharing, and experimentation.

$140,000–$160,000/yr
US Canada Unlimited PTO

  • Build detections and security signal pipelines in Datadog.
  • Serve as the subject matter expert on AWS Cloud and on-prem infrastructure security.
  • Act as the technical lead during security incidents, including investigation and remediation.

Voltus is the leading platform connecting distributed energy resources to electricity markets, delivering less expensive, more reliable, and more sustainable electricity. Our company appears to be a remote-first company, and values diversity and inclusion.

$140,000–$175,000/yr
US 2w PTO

  • Lead security strategy across infrastructure, cloud systems, and enterprise applications.
  • Drive SOC 2, ISO 27001, and ISO 42001 readiness/certifications.
  • Own vulnerability management, threat monitoring, and incident response workflows.

SaaS Talent is a recruiting company, and a hiring, business development and growth partner with 20+ years of experience in SaaS and Hi-Tech that helps you scale and transform your business. They've worked with 100+ companies and helped them achieve their goals.

$149,000–$271,500/yr
US

  • Own the roadmap for detection and response, making key platform and architecture decisions.
  • Build and mature the security observability platform, owning the security telemetry layer.
  • Partner with AI platform teams on safety patterns, building detection and response capabilities with AI at the center.

Life360's mission is to keep people close to the ones they love through their mobile app and tracking devices. They are a remote-first company with over 500 employees, aiming to provide peace of mind and enhance everyday family life with seamless coordination.

Canada

  • Play a pivotal role in promoting a culture of security awareness and ensuring the protection of organizational assets against cyber threats.
  • Monitor various security systems to promptly detect and respond to any security incidents, and lead in investigating security breaches and incidents.
  • Conduct comprehensive assessments of security risks and evaluate third-party vendor security measures to gauge the effectiveness of existing security controls and identify areas for enhancement.

Numeris is Canada’s most trusted and authoritative source for broadcast measurement and consumer behaviour data. We have been recognized for over 75 years as providing the gold standard in audience intelligence. The company values continuous learning and career advancement opportunities with collaborative, curious, and dedicated teams.

Canada 4w PTO

  • Design and build scalable infrastructure to support rapid growth in data volume, service usage, and engineering velocity.
  • Implement and maintain core security infrastructure and controls including, service-to-service authentication, secrets management, application security primitives.
  • Partner closely with Security Engineering to implement infrastructure that supports best-in-class security and compliance practices.

Vanta helps businesses earn and prove trust by providing a platform that continuously monitors and verifies security. They empower companies to practice better security and prove it with ease. Vanta has a kind and talented team with offices in SF, NYC, London, Dublin, Tel Aviv, and Sydney.

US

  • Partner with Security Engineering, Risk, Product, and Infrastructure teams to bake security and compliance into the process.
  • Dive deep into the security stack to identify execution blockers and actively architect the technical solutions to implement them.
  • Define the technical milestones for high-stakes initiatives like Zero Trust and IAM overhauls, translating a broad vision into a precise execution roadmap.

Human Interest aims to provide all workers access to retirement benefits. They are a high-growth fintech company that is financially backed by investors such as BlackRock, TPG, and SoftBank.

$63,000–$103,000/yr
US

  • Monitor and analyze security alerts in Splunk to identify suspicious or malicious activity.
  • Support incident handling activities, including triage, investigation, escalation, and documentation of security events.
  • Collaborate with internal teams to resolve security issues and improve monitoring and response processes.

Signet Jewelers is the world's largest retailer of diamond jewelry, operating more than 2,800 stores worldwide under iconic brands. Signet Jewelers is a people-first company, proud of their heritage, international presence, diversity, inclusion and equity.

US

  • Analyze, investigate, document and report on security alerts and/or potential security incidents identified in customer environments.
  • Process security investigation cases in a thorough, yet timely manner.
  • Serve as an incident coordinator for security events that require urgent response, containment, and remediation.

CyberSheath Services International LLC is a rapidly growing Security and IT Managed Services Provider primarily focused on providing Cybersecurity services to the Defense Industrial Base (DIB). They integrate compliance and threat mitigation efforts and eliminate redundant security practices.

EMEA

  • Lead implementation of PCI DSS controls across infrastructure and application layers
  • Design and secure AWS infrastructure using best practices around IAM, networking, and encryption
  • Own Infrastructure as Code and improve deployment reliability across environments

Pragmatike is recruiting on behalf of a fast-growing fintech company building modern payment infrastructure for the travel and airline industry. Their platform enables complex multi-party and multi-method payment orchestration, helping enterprise clients recover revenue and process transactions more efficiently at scale.

US

  • Enhance the security of cloud infrastructure.
  • Ensure the protection of patient data and all of the technology behind our platform.
  • Work helps ensure the best outcomes for patients as we strive to make mental healthcare work for everyone.

Rula strives to create a world where mental health is embraced as part of overall well-being. They are dedicated to providing quality, evidence-based care and making a positive impact on the lives of individuals struggling with mental health issues.

$190,000–$230,000/yr
US Canada Unlimited PTO

  • Build, operationalize, and scale the security engineering practices that protect our benefits platform.
  • Partner with teams building web and mobile applications, backend services, system integrations and data platforms.
  • Set direction and mature security capabilities; introduce strong standards and ship incremental improvements.

Benepass is making benefits easy by tailoring them to the unique needs of the workforce with an easy-to-use and highly customizable fintech platform. They are backed by leading investors and have raised approximately $75 million in equity capital, fostering an inclusive environment for its employees.

Europe 6w PTO

  • Tune EDR, SIEM, and XDR detections to reduce false positives and improve alert quality.
  • Build and maintain detection rules, correlation searches, dashboards, watchlists, and response workflows.
  • Translate Red Team, Purple Team, incident, and Threat Intelligence findings into repeatable defensive checks.

Sporty’s is a remote first company in pursuit of sustainability. They provide networking opportunities. They are likely a smaller company based on culture.

$113,850–$126,500/yr
Europe 5w PTO

  • Design, build, and maintain infrastructure using Infrastructure as Code tools such as Terraform.
  • Improve system reliability, scalability, resilience, and performance across the Mast platform.
  • Build systems and tooling that automate infrastructure management and operational workflows wherever possible.

Mast is on a mission to make complex lending simple by building modern, cloud-native lending technology purpose-built for specialist lenders. It is a high-performance team of engineers and lending experts that values radical honesty, transparency, and speed.

US

  • Supports 24x7 cybersecurity monitoring, incident detection, alert triage, ticket response, escalation management, and operational reporting activities.
  • Assists in monitoring enterprise, cloud, and tactical network environments, identifying potential security events and incident response.
  • Role supports continuous monitoring operations utilizing SIEM, IDS/IPS, EDR/XDR, vulnerability management, and cloud security.

By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.

$61,232–$104,094/yr
US

  • Supports the day‑to‑day operation of ICF’s information security program under the guidance of senior security staff and the Cyber Security Manager.
  • Assists with monitoring, maintaining, and documenting security controls and technologies, including endpoint protection, access controls, vulnerability management, and security event monitoring.
  • Helps identify, document, and escalate security issues, supports routine security operations, and contributes to security assessments and reporting.

ICF is a global advisory and technology services provider that combines unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. They have approximately 9,000 employees, from business analysts and policy specialists to digital strategists, data scientists and creatives.