Crypto Pro Logo

Crypto Pro

Incident Response Engineer

Posted 10 Days Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in United States
Senior level
Remote or Hybrid
Hiring Remotely in United States
Senior level
The Incident Response Engineer will manage cybersecurity incidents, performing analysis, containment, and recovery while collaborating globally and developing incident response documentation.
The summary above was generated by AI
As a member of the ETMSA team at Crypto.com, you will be integral to responding to and managing cybersecurity threats and incidents throughout their lifecycle – from Preparation to Identification, Containment, Eradication, Recovery, and Lessons Learned – collaborating with a global team of incident responders.

You will apply your comprehensive skills in cyber defense, digital forensics, log analysis, and intrusion analysis to address security incidents across our endpoints, network, and cloud infrastructure. In this role, you will be responsible for prevention, detection, response, and remediation activities, ensuring that information assets and technologies are adequately protected by leveraging various technologies such as Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP), and more.

You will also leverage your collaboration and communication skills to work effectively with all relevant stakeholders in multicultural and global environments.


Responsibilities

- Report to Director to facilitate all phases in the incident response lifecycle
- Be involved in various incident prevention projects to improve Security posture

Preparation:
- Understand different regulatory and compliance requirements like critical time to report, escalation flows, etc.
- Take part in self-assessment exercises like Tabletop Exercises, Attack Simulations, Red/Purple Team exercises to make sure the incident response process is working smoothly
Develop incident response runbooks, playbooks and SOPs with reference to different regulatory requirements
- Evaluate the incident response readiness of different layers - people, process, technology

Detection & Analysis:
- Respond to the cyber security incidents escalated from various channels including the 24/7 SOC team.
- Respond to cyber security incidents in compliance with the local authority / regulatory requirements.
- Assess the risk, impact and scope of the identified security threats
- Perform deep-dive incident analysis of various data sources by analysing and investigating security related logs against medium-term threats and IOCs

Containment, Eradication and Recovery:
- Communicate with the stakeholders and provide guidance, recommendations to contain and eradicate the security incident
- Participate in root cause analysis using forensic and other custom tools to identify any sources of compromise and/or malicious activities taking place.
- Document and present investigative findings for high profile events and other incidents of interest.

Post incident activities:
- Provide lessons learnt meeting to the stakeholders
- Lead and keep track on the follow-up activities
- Document the incident in the case management system and provide incident reports

Always ready to jump in, in the event of security incidents.

Requirements

  • At least 5 years experience in the Cyber Security industry
  • Strong technical and analytical skills
  • Familiar with the cyber security incident response process
  • Familiarity with AI tools and their application in automating security tasks and processes.
  • Hands-on experience on performing incident response activities
  • Have scripting experience like Bash, PowerShell, Python, Go, etc, and the ability to use these skills to aid in responding to incidents involving Windows, Linux, macOS, as well as cloud environment
  • Have knowledge of cybersecurity tools and software like NGFW, EDR, IDS/IPS, EDR, DLP, SIEM, other log management platforms, etc.
  • Be familiar with the MITRE ATT&CK Framework and/or Cyber Kill Chain
  • Be passionate on exploring new technologies and having creative initiative to boost the team capabilities
  • Holders of security related certifications is a plus (e.g.Azure, AWS, CISSP, GCIH, GCIA, GCFA, GNFA, GREM, or other equivalent)
  • Awareness of regulatory and compliance requirements like GDPR, MAS, PSD2 etc is a plus.

Preferably

  • Fast learner with can do attitude and ready to get the hands dirty
  • A strong team player who can collaborate with compassion
  • Passionate to learn and willing to put in the extra effort
  • Understand the concept of ownership and accountability coupled with sense of urgency and prioritisation
  • Confidence in handling incidents and managing relevant senior and technical stakeholders
  • Possess business acumen/mindset (not only technical) when making critical decisions

Top Skills

Bash
Dlp
Edr
Go
Ids/Ips
Ngfw
Powershell
Python
SIEM

Similar Jobs

15 Days Ago
Easy Apply
In-Office or Remote
4 Locations
Easy Apply
198K-267K
Senior level
198K-267K
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
As a Senior Security Engineer, you'll lead incident response, automate workflows, enhance security processes, and collaborate on improving security operations.
Top Skills: AWSCeleryDatadogFastapiGitKafkaPagerdutyPostgresPython 3React/RemixSemgrepSnowflakeSnykSqlalchemyTypescript
Senior level
Cybersecurity
Lead OT incident-response engagements, perform deep forensics, and help clients mitigate threats in critical infrastructure environments.
Top Skills: ArmisClarotyDragosElkForescoutFortinet OtGoHmiIsa/Iec 62443Nerc CipNetwork CapturesNist 800-82Nist-CsfNozomiPlcPowershellPythonSplunkTenable OtWireshark
3 Days Ago
In-Office or Remote
Bala Cynwyd, PA, USA
125K-165K Annually
Senior level
125K-165K Annually
Senior level
Insurance
The Senior Incident Response Engineer will handle security incidents, improve security operations, mentor team members, and communicate effectively with all stakeholders.
Top Skills: BashLarge Language ModelsLinuxWindowsPerlPowershellPythonRubySecurity Log InfrastructureTcp/Ip

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account