Why This Role Stands Out
This remote IT Security Engineer IV role offers a competitive hourly rate and the chance to lead critical incident responses and conduct in-depth forensic analysis. You'll thrive here if you possess strong DFIR expertise and a passion for safeguarding digital environments, so seize this opportunity to advance your career.
Quick Overview
Salary
$80 - $83/hr
Seniority
Mid Senior
Work mode
Remote
Location
San Diego, CA, United States
Posted
Yesterday
Job Description
Apply today for consideration!
Title: IT Security Engineer IV- DFIR
Location: Remote
Pay rate: $80.00 - 83/hour DOE
Duration: 12+Months (Possibility of extension)
Duties
Title: IT Security Engineer IV- DFIR
Location: Remote
Pay rate: $80.00 - 83/hour DOE
Duration: 12+Months (Possibility of extension)
Duties
- Respond to and lead critical, escalated security incidents: coordinating communications, executing the Incident Response Plan, and delivering clear, timely status updates to stakeholders and senior leadership.
- Perform comprehensive host, network, and cloud forensic analysis to determine root cause, scope, and impact, ensuring containment is validated against Client control-testing standard before an incident is closed.
- Analyze and correlate signals across SIEM, EDR, and other platform logs to triage and validate threats.
- Develop, maintain, and improve incident response playbooks and runbooks in partnership with the SOC's Analysis Champ and other capability owners.
- Operate within existing automated workflows in ServiceNow SIR, following and refining established processes.
- Flag detection gaps and false-positive patterns identified during live incidents to Detection Engineering for tuning and new detection development.
- Use outputs from Mate AI SOC platform to inform triage and investigation decisions.
- Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements.
- Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures.
- Provide training and mentorship to other incident responders on best practices.
- Contribute to post-incident reviews and help build metrics that drive continuous program improvement.
Preferred Experience
- Respond to and lead critical, escalated security incidents: coordinating communications, executing the Incident Response Plan, and delivering clear, timely status updates to stakeholders and senior leadership.
- Perform comprehensive host, network, and cloud forensic analysis to determine root cause, scope, and impact, ensuring containment is validated against Client control-testing standard before an incident is closed.
- Analyze and correlate signals across SIEM, EDR, and other platform logs to triage and validate threats.
- Develop, maintain, and improve incident response playbooks and runbooks in partnership with the SOC's Analysis Champ and other capability owners.
- Operate within existing automated workflows in ServiceNow SIR, following and refining established processes.
- Flag detection gaps and false-positive patterns identified during live incidents to Detection Engineering for tuning and new detection development.
- Use outputs from Mate AI SOC platform to inform triage and investigation decisions.
- Collaborate with Compliance, Legal, and Risk to ensure response workflows meet business and regulatory requirements.
- Assess vulnerabilities, propose remediation, and stay current on emerging threats and countermeasures.
- Provide training and mentorship to other incident responders on best practices.
- Contribute to post-incident reviews and help build metrics that drive continuous program improvement.
Education Required
Bachelor’s degree in an IT-related or Engineering field.
Education Preferred
Bachelor’s degree in an IT-related or Engineering field.
Additional Information
Work is expected to be done on 100% Remote.
Russell Tobin offers eligible employees comprehensive healthcare coverage (medical, dental, and vision plans), supplemental coverage (accident insurance, critical illness insurance and hospital indemnity), a 401(k)-retirement savings, life & disability insurance, an employee assistance program, identity theft protection, legal support, auto and home insurance, pet insurance, and employee discounts with some preferred vendors.
Equal Employment Opportunity
Russell Tobin is an equal opportunity employer. We do not discriminate on the basis of the race, religious creed, color, national origin, ancestry, physical disability, mental disability, reproductive health decision making, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other characteristic protected by applicable federal, state, or local law.
Fair Chance Employment
Russell Tobin is a Fair Chance employer. We consider all qualified applicants, including those with criminal histories, in a manner consistent with applicable state and local Fair Chance laws and ordinances, including, the California Fair Chance Act and all applicable local Fair Chance ordinances.
Accommodations
We are committed to providing reasonable accommodations to applicants and employees with disabilities. If you require a reasonable accommodation to participate in the application or interview process, or to perform the essential functions of this role, please contact us.
Only applicable for San Francisco Candidates: Under the San Francisco Lactation in the Workplace Ordinance, we will provide written notice of lactation accommodation rights, and this notice will automatically be given upon hiring, any inquiry of parental leave or lactation accommodation.
#LI-RS3
#RTA
#RTA-ZR
Similar jobs
- NS
Security Analyst/Technical Support Analyst /EHR
NewNovaLink Solutions
Richmond, VA🇺🇸Hybrid16 hours agoActive DirectorySSOMFA+1Technology - TE
Cyber Security Engineer - Raleigh, NC, Durham, NC, Orlando, FL, Columbia, SC, Atlanta, GA, Charlotte, NC, Tampa, FL.
NewTechniPros, LLC
Raleigh, NC🇺🇸Hybrid16 hours agoDockerAWSAzure+8Technology - WI
EHR Security Analyst / Technical Support Analyst 3
NewWiserHunt Inc.
Richmond, VA🇺🇸On-site16 hours agoActive DirectorySSOMFA+1Technology - CI
AI-Assisted Cyber Analysis Specialist
NewCACI International, Inc.
United States🇺🇸$90.3k - $189.6k/yrHybrid16 hours agoAWSSplunkAzure+5Technology - NS
Security Analyst/Technical Support Analyst
NewNovaLink Solutions
Richmond, VA🇺🇸Hybrid16 hours agoActive DirectorySSOMFA+1Technology - OL
Transmit Security Engineer - Mosaic Platforms exp - Remote - W2
NewOutcome Logix LLC
null🇺🇸Remote16 hours agoAWSEncryptionMFA+8Technology