CronJobs

security jobs

Senior Incident Response Engineer

Archer · San Jose, California, United States

unknownsenior$144,000–$180,000Posted Sep 24, 2026PythonPowerShellBashSplunkMicrosoft SentinelGoogle SecOps/ChroniclePalo Alto Cortex XSOARAWS

Apply on the employer site

About this role

**Archer — Senior Incident Response Engineer** **Job Overview** Headquartered in Silicon Valley, California, Archer is a leader in next-gen aerospace, building an end-to-end advanced air mobility platform that delivers air taxis, unmanned aircraft systems (UAS), aviation-related AI solutions, and more for customers worldwide across commercial aerospace and defense. Archer is seeking a **Senior Incident Response (IR) Engineer** to lead detection and remediation efforts. You’ll be the primary technical liaison to the **Managed Security Service Provider (MSSP)**—translating alerts into actionable responses while ensuring compliance with **NIST SP 800-171**. This role requires deep expertise in **digital forensics**, **threat hunting**, and **enterprise security operations** across **SIEM**, **SOAR**, and security platforms to rapidly contain threats and improve Archer’s security posture. **Key Responsibilities** - Serve as Archer’s primary internal **SIEM engineer**: triage/validate alerts with internal resources and the MSSP, define escalation thresholds, and tune detection rules. - Lead technical response to validated incidents: **identify, contain, eradicate, and recover**, coordinating cross-functional teams during breaches, malware outbreaks, and insider threats. - Perform deep-dive forensics: **memory analysis, disk imaging, timeline reconstruction**, and evidence preservation; produce incident reports for HR, legal, and regulatory stakeholders. - Conduct proactive **threat hunts** using SIEM data to identify lateral movement, persistence mechanisms, and **IOCs**. - Develop/refine/validate custom detection rules mapped to **MITRE ATT&CK**, aligned to Archer-specific threats and compliance needs. - Design and maintain **incident response playbooks** and **SOAR workflows** to automate evidence collection, containment actions, and notifications. - Design log collection requirements and support external compliance audits to meet **NIST SP 800-171 (AU)**, **CMMC Level 2**, and **SOX ITGC** expectations. - Manage endpoint/system detection policies, deploy sensors, and perform live response to contain threats and collect forensic artifacts. - Identify and operationalize Archer-relevant **CTI feeds**; translate IOCs and threat actor TTPs into detection logic. - Own the IR documentation architecture: author, organize, and continuously maintain procedures, playbooks, and runbooks for consistency and audit-readiness. - Own and evolve Archer’s IR program strategy, metrics, and roadmap; report progress and risk posture to the **CISO** and executive leadership. - Provide technical guidance and facilitate tabletop exercises for IT, application, and leadership teams on incident reporting, response protocols, and lessons learned. **Required Qualifications** - **5+ years** in Incident Response or Security Operations (SOC), including experience managing MSSP relationships, alert triage, and SLA performance. - Hands-on experience investigating incidents from detection through containment/eradication (malware, phishing, ransomware, insider threats). - Deep understanding of **OS internals** (Windows/Mac/Linux), network protocols, and scripting automation (**Python, PowerShell, Bash**). - Working knowledge of SIEM platforms (**Google SecOps/Chronicle, Splunk, Microsoft Sentinel**) and query languages (**YARA-L/GoogleSQL, SPL, KQL**). - Hands-on experience with SOAR platforms (**Google SecOps/Chronicle, Palo Alto Cortex XSOAR, Splunk Phantom SOAR**). -

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord