FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in incident response, including triaging alerts, leading investigations, and writing post-incident reports. Proficient in building and tuning detections in modern SIEMs and automating response workflows using programming languages like Python and TypeScript.
Highest-signal resume keywords
Incident Response ExperienceDetection Tuning in SIEMCloud Forensics ExpertiseKubernetes KnowledgeAutomation with Python or TypeScript
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident ResponseDetection TuningCloud ForensicsKubernetesPythonTypeScriptRustSIEMAutomationAlert Triage
Soft Skills
Clear WritingJudgment in AlertingCollaboration
Tools & Technologies
Cloud PlatformsLLM-based ToolingGPU InfrastructureHPC InfrastructureSIEM ToolsSecurity Tools
Certifications & Qualifications
SOC 2ISO 27001
Industry Keywords
Incident ResponseThreat HuntingPost-Incident ReviewsAudit LogsRBACIAM AbuseContainer EscapeCredential TheftSupply Chain CompromiseOn-Call Rotation
Tech Stack
Tools & technologiesCloudKubernetesPythonRustTypeScript
About the role
Key responsibilities & impact- Own detection and response end to end, including logging, alerting, triage, and recovery
- Write and tune detections as code across cloud environments, Kubernetes, identity systems, endpoints, and SaaS
- Measure detections by coverage and precision rather than alert volume
- Lead incident response from initial alert through containment and forensics
- Write post-incident reviews
- Build automation for triage enrichment, correlation, containment actions, and evidence collection
- Use LLM-based tooling where it withstands audit
- Monitor AI agents and developer tooling and develop telemetry and controls
- Partner with platform and research engineers to implement logging and response playbooks in new systems
- Run threat hunts and tabletop exercises and remediate findings
- Turn incident and detection metrics into evidence for SOC 2, ISO 27001, and enterprise customer security reviews
- Work with the GRC team
- Participate in a security incident on-call rotation
- Report to the head of security and partner with platform and research engineers
Requirements
What you’ll need- Hands-on incident response experience, including triaging live alerts, leading investigations, and writing post-incident reports
- Experience building and tuning detections in a modern SIEM, ideally managed as code
- Working knowledge of attacker movement through cloud and Kubernetes environments, including IAM abuse, container escape, credential theft, and supply chain compromise
- Ability to write Python, TypeScript, Rust, or another language to automate response work and connect security tools
- Familiarity with at least one major cloud platform
- Kubernetes knowledge covering audit logs, RBAC, and workload identity
- Clear writing for incident timelines, detection documentation, and leadership updates
- Judgment about alerting, automation, and escalation decisions
- Participation in an on-call rotation for security incidents
- Experience monitoring GPU or HPC-style infrastructure, research environments with large datasets, AI agents, LLM tooling, or MCP servers is advantageous
- Cloud forensics experience, including disk and memory acquisition, cloud audit trail reconstruction, and chain of custody, is advantageous
- Published open-source detection content is advantageous
