> Markdown version of [/jobs/ext/1447402-engineer-ii-cyber-incident-response](https://www.wearedevelopers.com/jobs/ext/1447402-engineer-ii-cyber-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineer II - Cyber Incident Response - **Company:** Cencora - **Location:** Frisco, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Data Analysis, CompTIA Security+, Cyber Security, Intrusion Detection and Prevention, Phishing, Security Information and Event Management, Wireshark, Software Vulnerability Management, Forensic Toolkit, Mitre Att&ck, Falcon Platform, Information Technology, Cyber Warfare, Splunk - **Published:** July 26, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17211366?backUrl=%2Fcareer%2F17211366%2FEngineer-Ii-Cyber-Incident-Response-Texas-Frisco ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience. * Strong knowledge of cybersecurity fundamentals, incident response methodology, and adversary tactics. * Familiarity with industry frameworks such as NIST, MITRE ATT&CK, and ISO 27035. Preferred Certifications * GIAC Certified Incident Handler (GCIH) * GIAC Certified Intrusion Analyst (GCIA) * CompTIA Security+ or CySA+ * Certified Ethical Hacker (CEH) Work Experience * 3-5 years of progressive experience in cybersecurity, with at least 2 years in SOC operations or incident response. * Hands-on experience with SIEM, EDR, and forensic tools (e.g., Splunk, CrowdStrike, Wireshark). * Demonstrated ability to analyze logs, alerts, and artifacts to support incident investigations. * Strong written and verbal communication skills for documenting findings and briefing stakeholders. ## Description The Engineer II, Cyber Incident Response, is a mid-level technical role within the Security Operations Center (SOC) responsible for detecting, investigating, and responding to cybersecurity incidents. This role performs in-depth analysis of alerts, escalates complex cases, and contributes to the improvement of response processes and playbooks. The Engineer II will collaborate with global cyber defense teams to contain threats, minimize business impact, and strengthen detection capabilities. This position requires strong analytical skills, hands-on technical expertise, and the ability to operate effectively in a fast-paced environment., * Investigate and respond to cybersecurity incidents, including phishing, malware, ransomware, and unauthorized access attempts. * Perform analysis of logs, alerts, and forensic data to determine the scope and impact of incidents. * Escalate complex or high-severity incidents to Engineer III, Lead, or Principal staff, providing clear documentation and evidence. * Assist in containment, eradication, and recovery activities during incident response. * Contribute to the development and maintenance of SOC playbooks, runbooks, and standard operating procedures. * Collaborate with threat intelligence, vulnerability management, and forensics teams to strengthen detection and response strategies. * Participate in lessons-learned sessions and recommend improvements to SOC processes and tooling. * Support junior analysts (Engineer I) by sharing knowledge and providing guidance on investigative techniques. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)