Senior Incident Response Engineer
Archer · San Jose, California, United States
About this role
**Archer — Senior Incident Response Engineer** **Job Overview** Headquartered in Silicon Valley, California, Archer is a leader in next-gen aerospace, building an end-to-end advanced air mobility platform that delivers air taxis, unmanned aircraft systems (UAS), aviation-related AI solutions, and more for customers worldwide across commercial aerospace and defense. Archer is seeking a **Senior Incident Response (IR) Engineer** to lead detection and remediation efforts. You’ll be the primary technical liaison to the **Managed Security Service Provider (MSSP)**—translating alerts into actionable responses while ensuring compliance with **NIST SP 800-171**. This role requires deep expertise in **digital forensics**, **threat hunting**, and **enterprise security operations** across **SIEM**, **SOAR**, and security platforms to rapidly contain threats and improve Archer’s security posture. **Key Responsibilities** - Serve as Archer’s primary internal **SIEM engineer**: triage/validate alerts with internal resources and the MSSP, define escalation thresholds, and tune detection rules. - Lead technical response to validated incidents: **identify, contain, eradicate, and recover**, coordinating cross-functional teams during breaches, malware outbreaks, and insider threats. - Perform deep-dive forensics: **memory analysis, disk imaging, timeline reconstruction**, and evidence preservation; produce incident reports for HR, legal, and regulatory stakeholders. - Conduct proactive **threat hunts** using SIEM data to identify lateral movement, persistence mechanisms, and **IOCs**. - Develop/refine/validate custom detection rules mapped to **MITRE ATT&CK**, aligned to Archer-specific threats and compliance needs. - Design and maintain **incident response playbooks** and **SOAR workflows** to automate evidence collection, containment actions, and notifications. - Design log collection requirements and support external compliance audits to meet **NIST SP 800-171 (AU)**, **CMMC Level 2**, and **SOX ITGC** expectations. - Manage endpoint/system detection policies, deploy sensors, and perform live response to contain threats and collect forensic artifacts. - Identify and operationalize Archer-relevant **CTI feeds**; translate IOCs and threat actor TTPs into detection logic. - Own the IR documentation architecture: author, organize, and continuously maintain procedures, playbooks, and runbooks for consistency and audit-readiness. - Own and evolve Archer’s IR program strategy, metrics, and roadmap; report progress and risk posture to the **CISO** and executive leadership. - Provide technical guidance and facilitate tabletop exercises for IT, application, and leadership teams on incident reporting, response protocols, and lessons learned. **Required Qualifications** - **5+ years** in Incident Response or Security Operations (SOC), including experience managing MSSP relationships, alert triage, and SLA performance. - Hands-on experience investigating incidents from detection through containment/eradication (malware, phishing, ransomware, insider threats). - Deep understanding of **OS internals** (Windows/Mac/Linux), network protocols, and scripting automation (**Python, PowerShell, Bash**). - Working knowledge of SIEM platforms (**Google SecOps/Chronicle, Splunk, Microsoft Sentinel**) and query languages (**YARA-L/GoogleSQL, SPL, KQL**). - Hands-on experience with SOAR platforms (**Google SecOps/Chronicle, Palo Alto Cortex XSOAR, Splunk Phantom SOAR**). -
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.