> Markdown version of [/jobs/ext/2694216-senior-cybersecurity-engineer-cyber-threat-intelligence-response](https://www.wearedevelopers.com/jobs/ext/2694216-senior-cybersecurity-engineer-cyber-threat-intelligence-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response - **Company:** XPLOR LLC - **Location:** Atlanta, GA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Cyber Security, Content Analysis, Identity and Access Management, Python (Programming Language), Simple Mail Transfer Protocols, Network Forensics, PCI Data Security Standards, Windows PowerShell, Kusto Query Language, Security Information and Event Management, Jupyter Notebook, Scripting, Software Security, Mitre Att&ck, Malware, Cyber Threat Analysis, Data Analytics, Microsoft Sentinel, Network Server - **Published:** September 3, 2026 - **Apply:** https://jobs.smartrecruiters.com/Xplor/744000147209259-senior-cybersecurity-engineer-cyber-threat-intelligence-response ## About the Role We're looking for someone who genuinely loves incident response. Someone who gets calmer and sharper when an incident kicks off, who is confident making decisions when the picture isn't complete, and who doesn't wait to be told what to look at. If you're a self-starter who takes ownership from the first alert to the final report, you'll fit right in., People who want to make a real difference in security, and who care about incident response in particular. * 3 to 6 years experience in security operations or incident response, with genuine passion for running incidents, not just watching a queue. * Confidence managing incidents through the full incident-handling lifecycle, and the judgement to make sound calls under pressure. * Strong triage and root cause analysis, with a solid understanding of different log sources and how to correlate events across them. * Comfortable reading logs (HTTP, SMTP, network), Windows and Active Directory, and common operating systems and servers. * Hands-on experience with a SIEM to investigate, hunt and build detections. Microsoft Sentinel and KQL preferred. * Practical experience across EDR, advanced threat protection, identity management and API security. * Threat-hunting experience across network flow, user behaviour and threat intelligence, plus the ability to design new ways to detect and contain attacks using scripting, analytics and automation. * Familiar with a broad range of attacker tools and techniques (TTPs), with the ability to map adversary activity across the Cyber Kill Chain to identify, assess, and communicate potential attack progression. * A self-starter who works independently, delivering projects without being chased, and keeps learning as the industry develops. * A critical thinker with strong problem-solving instincts and exceptional communication skills, capable of translating complex technical risks into clear, actionable insights for both the immediate team and cross-functional partners, including engineers, administrators, and leadership, through both verbal and written communication. * Good understanding of ITIL processes and standards such as ISO 27001 and PCI DSS, including change, incident and problem management. Nice to have * Malware analysis experience. * Preferred certifications such as GCIH, GCFA, AZ-500 or SC-100. * Experience with Jupyter Notebooks for threat-hunting. * Python and PowerShell scripting. * Experience building and tuning SOAR automation for response. ## Description Our Cyber Threat Intelligence & Response (CTIR) engineers are the people we count on when something goes wrong, and the people who make sure it goes wrong far less often. This is a hands-on incident response role. You'll lead the response to security events across our platforms and applications: triage, investigate, contain, eradicate and recover, then make sure we come out of it stronger., * Own incidents as part of the CTIR team: detect, triage, investigate, contain and eradicate, driving each one until the threat is under control. * Work live incidents alongside the team and be ready to step up and take the lead yourself when the situation calls for it. * Lead investigations across our systems, digging into logs, endpoints, email and network data to work out what happened, how far it reached, and how to resolve. * Perform host and network forensics, malware triage, and email analysis (including PDF and document analysis) to understand attacker activity and build a reliable timeline. * Coordinate with engineering, IT and the wider security team during a response, and communicate clearly to both technical teams and leadership. * Hunt proactively for threats across system logs, user behaviour and threat intelligence, turning what you find into new detections and indicators of compromise. * Build and automate incident response workflows and playbooks so routine response is fast and repeatable. * Strengthen our detection coverage using the MITRE ATT&CK framework, closing monitoring gaps, and tuning to reduce noise. * Feed what you learn from each incident back into how the team detects and responds, so an attack pattern we've seen once is caught faster next time. * Analyse threat intelligence, research emerging threats, and recommend practical mitigation. * Be ready to work incidents as they arise, including on-call and out-of-hours cover when needed. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)