> Markdown version of [/jobs/ext/1228856-incident-response-engineer-cyber-defense](https://www.wearedevelopers.com/jobs/ext/1228856-incident-response-engineer-cyber-defense). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Engineer - Cyber Defense - **Company:** CTECH NY INC - **Location:** Dallas, TX, United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Email Production, Log Analysis, Microsoft Security Essentials, Kusto Query Language, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Information Technology, Cybercrime - **Published:** July 10, 2026 - **Apply:** https://career-techniques.com/job/incident-response-engineer/?form=apply#wpjb-scroll ## About the Role * 6+ years of hands-on experience in Cybersecurity Operations / Incident Response * Strong experience within Microsoft Security Ecosystem * Proven experience investigating incidents across cloud (Azure/AWS), identity, endpoint, and email platforms * Demonstrated experience integrating or leveraging AI/automation in security operations (e.g., security copilots, ML-based detections, automated triage) * Strong proficiency in KQL (Kusto Query Language) for threat hunting and investigation * Strong analytical and critical thinking skills with the ability to operate under pressure * Excellent written and verbal communication skills, including executive-level reporting * Ability to lead incidents, influence stakeholders, and drive rapid decision-making * Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) * Certified in one or more of the following: CISSP, CISM, CISA,SANS GIAC Security Certifications. ## Description This role is responsible for the end-to-end execution of the Incident Response lifecycle, leveraging AI-assisted tools, automation, and threat intelligence to accelerate detection, triage, investigation, and containment. You will operate as both a hands-on technical responder and incident leader, driving rapid mitigation actions while improving detection fidelity, response speed, and operational efficiency., * Act as Incident Commander for high-impact security incidents, coordinating cross-functional response efforts and driving containment, eradication, and recovery actions * Execute the full Incident Response lifecycle (detect, triage, investigate, contain, remediate, recover) with a focus on reducing time-to-detect and time-to-contain * Leverage frameworks such as MITRE ATT&CK and the Cyber Kill Chain to guide investigations and response strategies * Lead real-time decision-making during active incidents, ensuring business risk is clearly understood and mitigated * Utilize AI-assisted platforms to pre-triage alerts, enrich incidents, and prioritize high-risk activity in the response queue * Drive the adoption of AI-based correlation and context aggregation across SIEM/XDR, case management, and threat intelligence sources * Conduct deep-dive investigations across endpoint, identity, email, network, and cloud environments * Perform host forensics, log analysis, and malware triage to determine scope, impact, and persistence mechanisms * Drive operational efficiency by reducing manual touchpoints and enabling automated containment and remediation actions * Provide technical leadership and mentorship to junior and mid-level analysts, elevating team capability and consistency * Collaborate with IT, Engineering, Legal, HR, and business stakeholders during investigations and incident response activities * Serve as a key contributor across multiple concurrent initiatives, including tool enablement, process improvement, and security strategy * Deliver clear, concise, and executive-ready incident reports, including impact assessments and recommended actions * Conduct post-incident reviews and root cause analysis, driving improvements to detection, response, and prevention controls ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence)