Senior Incident Response Engineer

Hays Specialist Recruitment LLC
United States
3 days ago
Apply on www.hays.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Microsoft Azure Cloud Computing Security Cyber Security Intrusion Detection and Prevention Python (Programming Language) Log Analysis Microsoft Security Essentials Windows PowerShell Security Information and Event Management EndPointSecurity Mitre Att&ck
+2 more
Azure Security Center SentinelOne Expertise

Job description

We are seeking a highly skilled and experienced Senior Incident Response Engineer to lead and manage the detection, investigation, and resolution of cybersecurity incidents. This role requires deep expertise in Microsoft security technologies and a strong understanding of incident response frameworks and processes. The ideal candidate will be a proactive problem solver, capable of working under pressure and collaborating across teams to protect organizational assets. You will also serve as the US Lead for incident response management.

  • Lead and coordinate incident response efforts across the organization, ensuring timely and effective resolution. * Utilize Microsoft security tools (e.g., Microsoft Defender for Endpoint, Microsoft

  • Sentinel, Microsoft Purview, Microsoft Defender XDR) to detect, analyze, and respond to threats. * Develop and maintain incident response playbooks, workflows, and escalation procedures. * Perform root cause analysis and post-incident reviews to identify gaps and improve security posture. * Collaborate with SOC analysts, threat hunters, and other stakeholders to enhance detection and response capabilities. * Provide mentorship and guidance to junior incident response team members. Stay current with emerging threats, vulnerabilities, and security technologies. * Participate in threat intelligence sharing and integrate findings into incident response strategies. * Ensure compliance with regulatory requirements and internal policies during incident handling.

Requirements

The final salary or hourly wage, as applicable, paid to each candidate/applicant for this position is ultimately dependent on a variety of factors, including, but not limited to, the candidate’s/applicant’s qualifications, skills, and level of experience as well as the geographical location of the position.

Applicants must be legally authorized to work in the United States. Sponsorship not available., * 5+ years of experience in Incident Response & Incident Management * Extensive hands-on experience with Microsoft security tools and platforms - Defender for Endpoint, Sentinel SIEM, SentinelOne etc. * Strong understanding of incident response lifecycle, NIST and MITRE ATT&CK frameworks. * Proficiency in log analysis, forensic investigation, and threat detection. * Excellent communication and documentation skills. * Ability to work independently and manage multiple incidents simultaneously. * Certifications such as GCFA, GCIH, CISSP, or Microsoft Certified: Security Operations Analyst Associate. * Experience with automation and scripting (PowerShell, Python). * Familiarity with cloud security (Azure, Microsoft 365). * Experience in regulated industries (e.g., finance, healthcare) is a plus.

Benefits & conditions

This position is a contract/temporary role where Hays offers you the opportunity to enroll in full medical benefits, dental benefits, vision benefits, 401K and Life Insurance ($20,000 benefit).

Why Hays?

You will be working with a professional recruiter who has intimate knowledge of the industry and market trends. Your Hays recruiter will lead you through a thorough screening process in order to understand your skills, experience, needs, and drivers. You will also get support on resume writing, interview tips, and career planning, so when there’s a position you really want, you’re fully prepared to get it.

About the company

Hays is committed to building a thriving culture of diversity that embraces people with different backgrounds, perspectives, and experiences. We believe that the more inclusive we are, the better we serve our candidates, clients, and employees. We are an equal employment opportunity employer, and we comply with all applicable laws prohibiting discrimination based on race, color, creed, sex (including pregnancy, sexual orientation, or gender identity), age, national origin or ancestry, physical or mental disability, veteran status, marital status, genetic information, HIV-positive status, as well as any other characteristic protected by federal, state, or local law. One of Hays’ guiding principles is ‘do the right thing’.

We also believe that actions speak louder than words.

In that regard, we train our staff on ensuring inclusivity throughout the entire recruitment process and counsel our clients on these principles. If you have any questions about Hays or any of our processes, please contact us.

In accordance with applicable federal, state, and local law protecting qualified individuals with known disabilities, Hays will attempt to reasonably accommodate those individuals unless doing so would create an undue hardship on the company. Any qualified applicant or consultant with a disability who requires an accommodation in order to perform the essential functions of the job should call or text 813.336.5570.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.hays.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all