> Markdown version of [/jobs/ext/2648132-dfir-engineer-ii-incident-response](https://www.wearedevelopers.com/jobs/ext/2648132-dfir-engineer-ii-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DFIR Engineer II - Incident Response - **Company:** The Northwestern Mutual Life Insurance Company - **Location:** Milwaukee, WI, United States - **Salary:** $98,320.0 - $147,480.0 - **Contract:** Permanent contract - **Skills:** .NET Framework, Amazon Web Services, Microsoft Azure, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Python (Programming Language), Windows PowerShell, Regular Expressions, Red Team (Cyber Security), Security Information and Event Management, Scripting, Cloud Platform System, Office365, Mitre Att&ck, Firewalls (Computer Science), Containerization, Kubernetes, Cybercrime, Docker - **Published:** August 19, 2026 - **Apply:** https://northwesternmutual.wd5.myworkdayjobs.com/CORPORATE-CAREERS/job/Milwaukee-WI-Corporate/DFIR-Engineer-II---Incident-Response_JR-45842 ## About the Role * Experience with security tools including SIEM, EDR, AV, CASB, Next-gen Firewalls, and VPN. * Experience with system and network artifacts. * Working knowledge of the MITRE ATT&CK framework. * Familiarity with various cloud environments and containerization technologies (AWS, Azure, O365, Docker, Kubernetes). * Functional and practical experience with at least one development or scripting language/framework (e.g. PowerShell, Python, .Net) and regular expressions. * Strong analytical, problem-solving, and communication skills. * Demonstrated curiosity and passion for cybersecurity. ## Description As a DFIR Engineer II on the Threat Detection & Response team, your role will include responding to, investigating and containing anomalous or malicious activity that could indicate a security threat. You'll be responsible for staying up to date on the latest cybersecurity threats and assisting in the continual development and refinement related to monitoring, detecting and responding to abnormal network and host activity. What You'll Do: * Triage, pivot and correlate across multiple network and host-based log sources. * Analyze system artifacts and memory for evidence of compromise. * Proactively hunt for and identify malicious activity in various log sources using threat intelligence and other indicators of compromise. * Document detailed findings including timelines of events or incidents * Continually improve incident response procedures and documentation. * Engage with Detection Engineering and Red Team to identify opportunities to better monitor/detect suspicious behavior and automate response capabilities. * Keep up to date on evolving cyber threats and identify methods to detect them. * Participate in an on-call rotation with other Incident Response Engineers ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)