FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in conducting forensic investigations and managing security incidents, with a strong focus on evidence handling, detection engineering, and corporate security methodologies. Proficient in collaborating with managed SOCs and external vendors while effectively communicating technical findings to diverse audiences.
Highest-signal resume keywords
Forensic InvestigationDetection Engineering As CodeEvidence Collection And PreservationSecurity Automation With Terraform And PythonManaged SOC Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Forensic AnalysisDetection Authoring And TuningChain-Of-Custody DisciplineEDiscovery WorkflowsIncident ResponseThreat Intelligence ProductionData Exfiltration ReviewsSecurity Requirements DefinitionEmail Security ControlsEndpoint Security Controls
Soft Skills
Strong Written CommunicationStrong Verbal CommunicationJudgment And Decision-Making
Tools & Technologies
SIEMSOARGoogle WorkspaceOktaGitHubAtlassianZoomSlack
Industry Keywords
Corporate SecurityWorkplace InvestigationsPCI ComplianceLegal Context In SecurityManaged Security Service Provider
Tech Stack
Tools & technologiesCloudPythonTerraform
About the role
Key responsibilities & impact- Author, tune, and maintain detections as code in the SIEM/SOAR pipeline
- Identify detection and tooling gaps and propose architecture improvements
- Serve on the on-call rotation and coordinate escalations with the third-party managed SOC
- Operate email security, endpoint security, and DLP controls
- Investigate and resolve high-sensitivity signals and tune controls
- Run tabletop exercises and deliver workforce security training
- Produce threat intelligence that shapes team priorities
- Restrict, suspend, or revoke employee system access when active risk is identified
- Define security requirements and detection coverage for identity and audit collection
- Conduct sensitive matter reviews using forensically sound evidence handling and chain-of-custody discipline
- Independently lead complex employee conduct, insider risk, access misuse, and data exfiltration reviews
- Conduct forensic analysis across endpoint, identity, email, cloud, and SaaS sources
- Produce findings, evidence summaries, technical analyses, and timelines
- Preserve evidence for legal holds and formal proceedings
- Interpret findings and recommend resolutions
- Improve Corporate Security methodology, evidence standards, and reporting standards
- Manage the SOC relationship and coordinate forensic vendors and external specialists
- Exercise independent judgment over review methodology and evidence handling
- Maintain chain-of-custody, evidence-handling, and confidentiality controls
Requirements
What you’ll need- 5 to 7 years of security experience, including hands-on experience leading complex corporate-security and workplace investigations
- Hands-on experience conducting forensic investigations across endpoint, identity, email, cloud, and SaaS data sources
- Practical fluency with detection engineering as code, including authoring, testing, and tuning detections in a version-controlled pipeline
- Working experience with forensically sound evidence collection and preservation, including chain-of-custody discipline, hashing, custodian-based collection, and eDiscovery / legal-hold workflows
- Sound judgment about what evidence to collect, how to preserve it, and what to share with whom
- Track record of producing review findings and recommendations that have held up to scrutiny
- Comfort working with internal or external counsel and directing forensic vendors
- Understanding of the legal context in which corporate-security matters arise
- Strong written and verbal communication, including explaining technical findings to non-technical audiences
- Experience working alongside a managed SOC or MSSP, including escalation management
- Experience with infrastructure-as-code workflows in Terraform and Python for logging, alerting, and security automation
- Experience securing Google Workspace, Okta, GitHub, and Atlassian environments
- Experience supporting PCI evidence collection and response
- Availability during established regular business hours and participation in an on-call rotation
- Proficiency with virtual communication tools such as Zoom and Slack
- ActBlue is unable to sponsor work visas at this time
- Background check required at time of offer, with consent
Benefits
Comp & perks- Flexible work schedules and an unlimited time-off policy
- Fully paid and trans-inclusive health, dental, and vision insurance for employees and their families
- Fully-paid health reimbursement arrangement for out of pocket expenses
- Fully-paid short- and long-term disability
- Fully paid basic and AD&D life insurance
- Voluntary supplemental life insurance option
- Dependent and health care flexible spending account options
- Employee Assistance Program (EAP) benefits
- Automatic 2% Employer-paid 401K contribution, plus up to an additional 6% match on employee contributions
- A minimum of three months paid medical, family and parental leave (for all new parents, adoptions included)
- Commuter or home-office benefits
- $1,000 home-office setup allowance for all new full-time remote employees
- Quarterly snack deliveries
- Digital subscriptions to the Boston Globe & New York Times
- Travel may be required to attend all-staff, departmental retreats, or select meetings
