Haystack
← Back to Jobs
Remote
Technology
PT

Security Engineer Incident Response (SOC), Security Engineer | DFIR | SOC | SIEM | EDR | Remote | 12-Month Contract

Projas Technologies, LLCUnited States🇺🇸United StatesPosted Sep 17, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
22 hours ago
Stakeholder Management

Job Description

Security Engineer Incident Response (SOC) | Remote | 12-Month Contract

We are seeking an experienced Security Engineer to join our Threat Operations Security Operations Center (SOC) on a 12-month remote contract. This is a highly visible, hands-on incident response role focused on identifying, investigating, containing, and resolving sophisticated security threats across enterprise environments.

The ideal candidate brings strong expertise in Incident Response, Digital Forensics, Threat Investigation, Security Operations, SIEM, and EDR technologies, along with a deep understanding of attacker behaviors, tactics, and methodologies. You'll work alongside cross-functional security teams, leverage AI-assisted security platforms, and help continuously improve incident detection and response capabilities.

Key Responsibilities

  • Lead and respond to critical and escalated cybersecurity incidents from initial triage through containment, eradication, and closure.
  • Coordinate communications during active incidents and provide timely updates to stakeholders and senior leadership.
  • Conduct host, network, and cloud forensic investigations to determine root cause, scope, impact, and containment effectiveness.
  • Analyze and correlate security telemetry from SIEM, EDR, and other security platforms to validate threats and accelerate investigations.
  • Execute and refine incident response processes, playbooks, and runbooks to improve operational effectiveness.
  • Operate within ServiceNow Security Incident Response (SIR) workflows and contribute to process optimization efforts.
  • Identify detection gaps, monitoring deficiencies, and recurring false-positive patterns; partner with Detection Engineering teams on improvements.
  • Utilize AI-assisted SOC technologies to support investigation, triage, and response activities.
  • Collaborate with Compliance, Risk, Legal, and business stakeholders to ensure response activities align with organizational and regulatory requirements.
  • Assess vulnerabilities discovered during investigations and recommend remediation actions.
  • Stay current on emerging threats, attack techniques, and security best practices.
  • Mentor and support fellow incident responders through knowledge sharing and training.
  • Participate in post-incident reviews, lessons learned sessions, and continuous improvement initiatives.
  • Develop metrics and reporting that enhance visibility into incident response effectiveness.

Required Qualifications

  • Strong experience in Incident Response, Cybersecurity Operations, or Security Engineering.
  • Hands-on experience investigating and responding to security incidents.
  • Experience performing digital forensics across endpoint, network, and cloud environments.
  • Strong understanding of attacker methodologies and threat investigation techniques.
  • Experience analyzing and correlating security events from SIEM, EDR, and enterprise logging platforms.
  • Experience developing or maintaining incident response playbooks and operational procedures.
  • Experience working within structured incident management processes and workflows.
  • Strong analytical, troubleshooting, communication, and stakeholder management skills.
  • Ability to work independently in a fast-paced security operations environment.

Preferred Qualifications

  • Experience within enterprise SOC or Threat Operations environments.
  • Experience working with ServiceNow Security Incident Response (SIR).
  • Familiarity with AI-assisted security investigation and automation platforms.
  • Experience partnering with Detection Engineering, Risk, Compliance, and Legal teams.
  • Knowledge of vulnerability assessment and remediation practices.

Incident Response, Digital Forensics, DFIR, SOC, Security Operations Center, Threat Operations, Threat Detection, Threat Investigation, Security Engineering, Cybersecurity, Cyber Security, SIEM, EDR, XDR, Threat Analysis, Security Monitoring, Log Analysis, Security Incident Management, ServiceNow SIR, Host Forensics, Endpoint Forensics, Network Forensics, Cloud Forensics, Root Cause Analysis, Incident Triage, Containment, Malware Investigation, Detection Engineering, Vulnerability Assessment, Vulnerability Remediation, Security Automation, AI Security, AI SOC, Threat Response, Blue Team, Security Operations, Threat Intelligence, Security Events, Incident Handling

Security Engineer, Incident Response Engineer, Incident Responder, DFIR Engineer, DFIR Analyst, Digital Forensics Analyst, Security Operations Engineer, SOC Engineer, SOC Analyst, Senior SOC Analyst, Threat Operations Engineer, Threat Response Engineer, Cyber Incident Analyst, Cyber Incident Responder, Cybersecurity Engineer, Information Security Engineer, Security Investigator, Detection Engineer, Blue Team Engineer, Threat Detection Engineer, Cyber Defense Analyst, Security Operations Analyst, Security Incident Response Analyst, Senior Security Engineer, Information Security Analyst, Cybersecurity Analyst, Threat Analyst

  • Senior Security Engineer Incident Response
  • Incident Response Engineer (SOC)
  • DFIR Engineer Threat Operations
  • Security Operations Engineer
  • Cyber Incident Response Engineer
  • Threat Response Engineer
  • Digital Forensics & Incident Response Engineer (DFIR)
  • SOC Security Engineer
  • Cybersecurity Incident Responder
  • Security Engineer Threat Operations

Similar jobs