Cyber Incident Response Principal Engineer Job at Gennte Technologies, Wisconsin

  • Gennte Technologies
  • Wisconsin

Job Description

Hiring Partners We currently have an open position for Cyber Incident Response Principal Engineer role in USA. I would like to request your support in souring suitable and qualified profiles for this role as per the below details.

Position Description: Cyber Incident Response Principal Engineer (Area Cybersecurity)

No. of positions - 1

Location : Remote, US (EST time preferred)

Salary Range $130k

Role Description

Bring deep Incident Response (IR) experience plus strong engineering capability to design, build and evolve IR automation and orchestration that improves speed and consistency of containment, analysis, and mitigation. A key focus is applying AI/ML and modern data engineering approaches to accelerate collection, triage, enrichment, investigation, and response decisioning, safely and in a controlled, auditable way.

  • Lead the continued evolution of incident response and forensic capabilities and processes, including automation and orchestration, with strong emphasis on engineering delivery.
  • Engineer and enhance security platforms by designing integrations and workflows that reduce manual IR effort and shorten time-to-contain.
  • Build and maintain automation pipelines that connect detections (use cases), enrichment, investigation steps, evidence capture, and response actions.
  • Translate incident response playbooks into automated workflows (e.g., decision trees, conditional branching, approvals, safe-guards, rollback).
  • Develop bespoke tooling/solutions to solve unique problems
  • AI for IR acceleration:

o Build AI-assisted capabilities to speed up triage and investigations (e.g., alert clustering, entity resolution, log summarisation, enrichment recommendations).

o Develop and maintain LLM-enabled analyst-assist tooling (summaries, guided investigations, draft IR reports, playbook step suggestions) with strong controls (auditability, prompt safety, data handling).

o Apply ML techniques to improve signal quality (e.g., anomaly detection, prioritisation scoring), ensuring outputs are explainable and operationally usable.

o Establish evaluation methods for AI features (precision/recall where relevant, time saved, false-positive reduction, robustness testing).

  • Support the identification, development and implementation of new detections (use cases) and ensure engineering output is tightly coupled to detection and response outcomes.
  • Develop and define detailed processes and procedures that enable repeatable, reliable, and automated response to cyber security events.

Certifications, Qualifications & Experience:

  • Significant experience in incident response and/or computer forensics (8+ years ).
  • Strong capability in analysing attacker TTPs and converting learnings into changes across the control plane.
  • Experience with common IR/forensic tooling: EnCase, FTK, Sleuthkit, Kali Linux, Ghidra, REMnux, SANS SIFT .
  • Expert scripting/programming and proven experience delivering production-grade tools
  • Experience building integrations across enterprise security tooling, such as: SIEM/log platforms and "Big Data" / cloud-based solutions for collection and real-time analysis
  • Common security technologies: IDS/IPS/HIPS, firewalls, proxies, advanced anti-malware
  • Practical engineering experience with:
    • APIs, event-driven systems, queues/workflows, CI/CD, automated testing
    • Reliability engineering concepts (observability, error handling, rollback, audit logging)
    • Secure coding and threat modelling for IR automation.
  • Hands-on experience building and operating AI/ML solutions in production (not just experimentation), ideally in security operations contexts desirable.
  • Working knowledge of: LLM application design (RAG patterns, tool use/function calling, prompt engineering, evaluation) - Data handling controls for sensitive/security data, and safe deployment patterns (human-in-the-loop for high-impact actions; strong logging/audit trails)
  • Expert knowledge of enterprise platforms: Windows, Linux, MacOS , infrastructure management and networking hardware.
  • Expert knowledge of network protocols: TCP/UDP/DNS/DHCP/IPSEC/ and protocol analysis.
  • Cloud expertise: AWS, Azure, Google Cloud .

Qualifications

  • Security certifications : CEH, CRISC, GSEC, GCIA, CISSP .
  • Forensics/tooling certifications: GCFA/GNFA/GCFE/GCIH/CHFI , EnCE/ACE etc.
  • Degree in Information Security/Cyber-security/Computer Science (or equivalent experience).
  • (Highly desirable) Evidence of AI engineering practice: applied ML/LLM delivery, MLOps, or equivalent demonstrable experience.

Success measures

  • Reduced time to contain/mitigate via delivered automations and orchestrated workflows.
  • Increased investigation throughput and consistency (playbooks-to-automation coverage).
  • Measurable improvements from post-incident reviews translated into engineering deliverables.
  • AI-assisted capabilities that demonstrably improve speed/quality (e.g., triage time reduction, better prioritisation, improved analyst experience) with controlled risk and strong

Job Tags

Permanent employment, Full time, Part time, Seasonal work, Remote work

Similar Jobs

HIMALAYAN WELLNESS SPA

Licensed Massage Therapist Job at HIMALAYAN WELLNESS SPA

 ...talented and passionate (Florida or United State only) Licensed Massage Therapist to join our elegant, client-focused wellness space....  ...wellness experience Qualifications: ~ Active Florida Massage Therapy License ~ Strong knowledge of massage techniques and body... 

Confidential

Property Claims Examiner (Trainee) Job at Confidential

 ...you ready to start a career in insurance claims? Join our team as a Claims Examiner...  ...ability to process, evaluate, negotiate, adjust, and resolve non-complex, standard claims...  ...Years of experience: 1 year Experience level: Entry Level Randstad is a world leader in matching... 

FLC Haus

Lead Generator Job at FLC Haus

 ...Entry-Level Lead Generators We are looking for friendly and motivated individuals to join our team as Lead Generators. No prior experience is required - training is provided. Responsibilities: Reach out to potential customers Gather basic information ... 

Emerald Energy Solutions

In-Home Solar Sales Representative Job at Emerald Energy Solutions

 ...In-Home Solar Sales Representative 1099 Independent Contractor | 100% Commission Only | Uncapped Earnings Potential Job Summary We...  ...Qualifications Required Minimum 12 years of in-home sales experience, preferably in solar, roofing, windows, HVAC, alarms, or... 

Coalition Technologies

Remote Graphic Designer Job at Coalition Technologies

 ...Coalition Technologies is seeking a creative, detail-oriented, and highly skilled **Remote Graphic Designer** to create high-quality visual assets for digital marketing, advertising, branding, social media, email marketing, and web design projects. This role is ideal...