FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading incident response for high-severity security events, utilizing DFIR methodologies, and collaborating across teams to enhance security posture. Proficient in developing automation workflows and maintaining operational documentation while applying threat intelligence and detection engineering principles.
Highest-signal resume keywords
Security Incident ResponseCloud EnvironmentsSIEM AdministrationAutomation with PythonThreat Intelligence
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseDFIR MethodologiesRoot Cause AnalysisAutomationSIEMEDRAWSGCPGit/GitLabMITRE ATT&CK
Soft Skills
Analytical SkillsProblem-SolvingWritten CommunicationGrowth MindsetProactive Approach
Tools & Technologies
SOAR PlatformsTelemetry PipelinesAlerting StrategiesOperational DocumentationPlaybooks
Industry Keywords
Cloud-First EnvironmentsHigh-Severity IncidentsIncident Response MaturityTriage WorkflowsAdversary Tactics
Tech Stack
Tools & technologiesAWSCloudGoogle Cloud PlatformPython
About the role
Key responsibilities & impact- Lead and coordinate end-to-end incident response for high-severity security events
- Prepare clear executive communications during incidents
- Investigate complex security incidents across cloud environments using DFIR methodologies
- Partner with Detection Engineering to design and implement SIEM use cases, alerting strategies, and telemetry pipelines
- Build and enhance automation and AI-assisted workflows for triage, investigations, and response
- Partner with Threat Intelligence to contextualize threats and improve detection coverage
- Conduct root cause analysis and lead post-incident reviews
- Develop and maintain runbooks, playbooks, and operational documentation
- Collaborate with Engineering, Infrastructure, Legal, Product, and Communications during incidents
- Lead proactive initiatives such as tabletops
- Mentor other engineers and improve incident response maturity
Requirements
What you’ll need- Strong experience in security incident response and investigations in cloud-first environments
- Experience using or administering Git/GitLab in a security or engineering context
- Hands-on experience with SIEM, EDR, and/or detection engineering
- Experience with AWS and GCP
- Familiarity with threat intelligence and adversary tactics, including MITRE ATT&CK
- Experience building or working with automation, such as Python, scripting, or SOAR platforms
- Interest or experience applying AI/ML or data-driven techniques to detection, triage, or response workflows
- Strong analytical and problem-solving skills
- Ability to operate effectively during high-severity incidents
- Excellent written communication skills
- Passion for clear, actionable documentation
- Growth mindset with a proactive approach to identifying and mitigating security risks
- Ability to participate in a rotating on-call schedule
- Ability to work the APAC window in a 24/7 follow-the-sun operating model
Benefits
Comp & perks- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
- Remote work arrangement
