← Все вакансии/Middle/jobgether
MiddleRemoteIndia

Engineer II - Cyber Incident Response

J
jobgether
Уровень
Middle
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Engineer II - Cyber Incident Response based in India.

Responsibilities
  • Investigate and respond to cybersecurity incidents, including phishing, malware, ransomware, unauthorized access attempts, and other security threats.
  • Analyze security logs, alerts, endpoint data, and forensic artifacts to determine the nature, scope, severity, and potential business impact of incidents.
  • Conduct detailed incident investigations using SIEM, EDR, network analysis, and forensic technologies.
  • Support containment, eradication, and recovery activities to minimize the impact of security incidents and restore normal operations.
  • Escalate complex or high-severity incidents to senior cybersecurity personnel, providing clear documentation, investigative evidence, and recommended actions.
  • Develop, maintain, and continuously improve SOC playbooks, runbooks, standard operating procedures, and incident response processes.
  • Collaborate with threat intelligence, vulnerability management, digital forensics, and other cyber defense teams to strengthen detection and response capabilities.
  • Participate in post-incident reviews and lessons-learned activities, identifying opportunities to improve processes, tooling, and security controls.
  • Support junior security analysts by sharing technical knowledge and providing guidance on investigative and incident response techniques.
  • Apply established cybersecurity frameworks and incident response methodologies to investigations and operational activities.
  • Maintain clear and accurate documentation of investigations, findings, escalations, and response actions.
  • Operate effectively in a fast-paced environment where rapid analysis, sound judgment, and timely escalation are essential.
Requirements
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related discipline, or equivalent professional experience.
  • At least 2 years of experience in incident response, SOC operations, security operations, or a related technical cybersecurity field, with the broader profile ideally reflecting approximately 5+ years of progressive cybersecurity experience.
  • Strong understanding of cybersecurity fundamentals, incident response methodologies, and common adversary tactics and techniques.
  • Hands-on experience with security technologies such as SIEM, EDR, and forensic tools, with experience using platforms such as Splunk, CrowdStrike, or Wireshark preferred.
  • Demonstrated ability to investigate and correlate logs, alerts, endpoint information, network activity, and other artifacts.
  • Solid proficiency in at least one primary technical cybersecurity area, such as endpoint forensics, together with working knowledge of an adjacent discipline such as cloud security.
  • Familiarity with recognized cybersecurity and incident response frameworks, including NIST, MITRE ATT&CK, and ISO 27035.
  • Strong analytical, investigative, critical-thinking, and problem-solving abilities, with the capacity to make sound decisions during high-pressure incidents.
  • Excellent written and verbal communication skills, including the ability to document technical findings clearly and brief relevant stakeholders.
  • Strong collaboration skills and the ability to work effectively with global cybersecurity and cross-functional teams.
  • Relevant certifications such as GCIH, GCIA, Security+, CySA+, or CEH are preferred.
  • A proactive mindset, strong attention to detail, and willingness to continuously develop technical expertise.
Conditions
  • Full-time, remote working opportunity in India.
  • Competitive total compensation package.
  • Comprehensive benefits programs designed to support employees' diverse needs, with specific offerings varying by location, role, and business unit.
  • Opportunities for professional growth and development within a global cybersecurity environment.
  • Exposure to advanced security operations, incident response, forensic investigation, and cyber defense technologies.
  • Collaborative environment with opportunities to work alongside global security specialists and cross-functional teams.
  • Opportunities to mentor junior cybersecurity professionals and expand leadership capabilities.
  • Inclusive workplace committed to equal employment opportunities and diverse perspectives.
Стек и навыки

С чем работаем