> Markdown version of [/jobs/ext/2711312-security-response-engineer-cyber-defense](https://www.wearedevelopers.com/jobs/ext/2711312-security-response-engineer-cyber-defense). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Response Engineer, Cyber Defense - **Company:** NuScale Power Corporation - **Location:** Seattle, United States - **Experience:** Expert - **Salary:** $100,000.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software as a Service, Cloud Computing, Cyber Security, Data Centers, Query Languages, Intrusion Detection and Prevention, Regression Testing, Phishing, AI Infrastructure, Scripting, High Performance Computing, Cybercrime, Process Control Systems - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/security-response-engineer-cyber-defense-nscale-8705790 ## About the Role * 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles. * Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary. * Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration. * You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook. * Sound judgement on containment under time pressure, including knowing where your authority ends. * You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit. * Calm and methodical when facts are incomplete or contradict each other. * Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong. * Ability to work effectively with engineering, infrastructure, and service owners who do not report to you. Strong pluses * Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily. * Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments. * Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents. * Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house. * Detection testing, shadow-rule validation, threat hunting, or forensic readiness. * Follow-the-sun, shift-based, or on-call operations. * Certifications are useful, but not required. ## Description We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments., * Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act. * Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence. * Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly. The solve * Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test. * Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous. Investigation and evidence * Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us. * Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up. Detection judgement * Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage. * Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call. Provider quality * Reconcile the managed provider's case work, which lives in their platform rather than ours, against our standards. * Hold the provider accountable for evidence, analysis, routing, and closure quality. Readiness * Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest. First 90 days * Independently own escalations across common classes, with defensible dispositions and evidence that stands up. * Ship your first solve: an engineering artifact that permanently retires a recurring alert class. * Learn the incident command, escalation, evidence, and handover model, and take a rotation slot. * Review the managed provider's case quality against our standard and raise the first reconciliation findings. * Judge and promote your first shadow detections to live. * Take part in a threat hunt, tabletop, or recovery exercise. * Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see. KPIs * Share of escalations permanently solved * Quality and defensibility of security dispositions and evidence * Containment judgement and response effectiveness * Quality and actionability of engineering artifacts * Managed provider quality and reconciliation, The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)