> Markdown version of [/jobs/ext/1373539-incident-response-eng](https://www.wearedevelopers.com/jobs/ext/1373539-incident-response-eng). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response Eng - **Company:** American Technology Services - **Location:** Libertyville, IL, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Apple IOS, Applicant Tracking Systems, Microsoft Azure, Network Analysis, Software as a Service, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Computer Programming, Linux, Electronic Data Interchange (EDI), Intrusion Detection and Prevention, Log Analysis, Security Software, Security Information and Event Management, Software Engineering, Scripting, Cloud Platform System, Software Security, Mitre Att&ck, Malware - **Published:** July 22, 2026 - **Apply:** https://www.workingnomads.com/job/go/1742752/ ## About the Role * Bachelor's degree in a related field or equivalent experience required; Cybersecurity certifications strongly preferred. * 6+ years of experience in Cybersecurity, including direct incident handling/response. * Strong understanding of Cybersecurity tools, technologies, and methodologies. * Working knowledge of common IT technologies and operational processes. * Familiarity with relevant frameworks and standards, such as MITRE ATT&CK and ITIL. * Solid understanding of risk management principles and practices. * Proven ability to translate abstract requirements into clear, actionable steps. * Excellent written and verbal communication skills, including the ability to convey technical concepts to non-technical audiences. * Strong work ethic with exceptional attention to detail and organizational skills. * Ability to prioritize and multitask effectively in a fast-paced environment. * Capable of working both independently and collaboratively within a team. * Conceptual understanding of software development methodologies. * Experience with application security, SaaS, or cloud security is a plus. * Experience with programming or scripting languages is a plus. * Familiarity with cloud environments (e.g., AWS, Azure) and automation frameworks. ## Description At ATS, you'll join a dedicated team focused on Incident Detection & Response, working to protect the people, processes, and technology of our organization. We are seeking an experienced and adaptable Security Operations Engineer to join our Cybersecurity team. This role reports to the Cybersecurity Manager and will play a critical part in responding to cybersecurity incidents across the enterprise. What you'll do * Serve as a primary responder to security incidents, including the monitoring, triaging, and investigation of security alerts in a timely manner. * Collaborate with cross-functional teams to document, enhance, and coordinate Incident Response processes. * Maintain and organize Cybersecurity documentation, including the creation and upkeep of incident response playbooks. * Participate in and/or lead incident post-mortems, distilling lessons learned into actionable recommendations and comprehensive written reports. * Analyze logs and EDR telemetry across a variety of systems, including medical devices, cloud applications, workstations, and data exchange platforms. * Conduct investigations across Windows, Linux, iOS, and cloud platforms using SIEM tools and manual log analysis. * Participate in a global on-call rotation. * Identify opportunities for automation and for improving detection capabilities. * Perform proactive threat hunting to identify emerging tactics, techniques, and procedures (TTPs). * Assess and respond to new and evolving threats using threat intelligence to evaluate likelihood and organizational impact. * Assist in forensic acquisition, malware analysis, and network analysis. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Xcode development redefAIned](https://www.wearedevelopers.com/videos/100195-xcode-development-redefained) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)