- Company Name
- Motive
- Job Title
- Lead Security Incident Response Engineer
- Job Description
-
Job title: Lead Security Incident Response Engineer
Role Summary: Lead the design, implementation, and continuous improvement of a comprehensive Incident Response (IR) program, integrating detection, automation, and threat hunting across multi‑cloud and containerized environments. Coordinate cross‑functional incident investigations, develop playbooks, and advocate for preventive controls.
Expections: • 5+ years in incident response or SOC roles. • Proven ability to manage priorities in fast‑paced settings. • Self‑starter, independent, and results‑driven. • Strong communication and cross‑team collaboration.
Key Responsibilities: • Architect, deploy, and refine SIEM, SOAR, EDR, and network forensics tooling. • Create advanced detection rules, alerts, and threat hunting workflows. • Lead end‑to‑end incident lifecycle: detection, triage, containment, eradication, recovery, and post‑mortem. • Develop and maintain IR playbooks, policies, and automation scripts. • Drive process automation; script and configure SOAR playbooks to reduce manual effort. • Collaborate with engineering, product, and operations to embed security controls and improve logging. • Identify systemic weaknesses and recommend preventive measures. • Serve as primary technical liaison during critical security events. • Document findings, lessons learned, and actionable intelligence for future prevention.
Required Skills: • Scripting: Python, Go, PowerShell. • Deep knowledge of SIEM/SOAR (e.g., Splunk, QRadar, Phantom, Sentinel), EDR, and cloud monitoring (AWS GuardDuty, Azure Sentinel, GCP Security Command Center). • Experience with container/ orchestration security (Docker, Kubernetes) and microservices. • Mastery of MITRE ATT&CK, threat intelligence, and digital forensics. • Cloud security best practices for AWS, Azure, GCP. • Strong technical documentation and playbook creation.
Required Education & Certifications: • Bachelor’s degree in Computer Science, Cybersecurity, or related field (or equivalent experience). • Relevant certifications (e.g., CISSP, GCIH, OSCP, CEH, CISM, or JPCERT as preferred).