Lead Senior Security Engineer, Incident Response, CSIRT, Cloud Security

FICO

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$136,500–$214,500 / yr
Employment
Full-time
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $186k
This role $176k
$125k most similar roles pay here $241k

This role pays less than 59% of similar roles. Most pay $156,312–$216,571 — the shaded band above. At the midpoint, this role pays about $176k versus about $186k for comparable roles.

Based on 240 similar postings.

Employer

About FICO

FICO (Fair Isaac Corporation) is a data analytics company best known for the FICO credit score, and provides analytics software and tools for fraud detection, credit scoring, and decision management. Industry: Data Analytics & Financial Technology

FICO currently has 3 open roles on FindRole.

Most-posted roles

View all roles at FICO

At a glance

TL;DR · Lead Senior Security Engineer, Incident Response, CSIRT, Cloud Security

Lead/ Senior Security Engineer- Incident Response - CSIRT - Cloud Security will lead defensive security operations with a focus on preparedness and cross-team readiness. This role involves owning the full incident lifecycle, including detection, triage, containment, eradication, recovery, and post-incident review. The engineer will design and facilitate tabletop exercises for stakeholders across security, IT, engineering, legal, and business teams to identify gaps and improve response capabilities. Key responsibilities include building IR plans, playbooks, and runbooks while partnering with threat intelligence and SOC teams to enhance detections. The role requires expertise in the PICERL and NIST frameworks, along with experience in cloud environments using SIEM, CSPM, and other cloud security tools. Required skills include digital forensics using Magnet Axiom, Velociraptor, Volatility, FTK, or Autopsy, alongside knowledge of AWS, AI security, and automation.

What you'll do

  • Design and facilitate incident response tabletop exercises for cross-functional teams to test preparedness and identify gaps.
  • Manage the full incident lifecycle including detection, triage, containment, eradication, recovery, and post-incident review.
  • Develop and maintain incident response plans, playbooks, and runbooks to ensure consistent and repeatable responses.
  • Collaborate with threat intelligence, SOC, and engineering teams to improve detections and security controls based on findings.
  • Conduct digital forensics investigations using industry-standard tools and frameworks like PICERL and NIST.
  • Manage incident response activities within cloud environments using SIEM, CSPM, and other cloud security tools.
  • Integrate AI and automation into incident response workflows and tabletop exercise processes.
  • Communicate clearly with stakeholders at all levels during active incidents and in formal reporting.

What we're looking for

  • Experience in enterprise incident response across the full lifecycle including detection, triage, containment, eradication, and recovery.
  • In-depth experience designing and facilitating incident response tabletop exercises for cross-functional teams.
  • Good working knowledge of forensics tools such as Magnet Axiom, Velociraptor, Volatility, FTK, or Autopsy.
  • Knowledge of AWS cloud security fundamentals and other cloud security tooling like SIEM and CSPM.
  • Understanding of cloud security and AI security concepts.
  • Ability to communicate clearly with stakeholders at all levels during incidents and in reporting.
  • Must have at least one of the following certifications: GCIH, GCFA, GCFE, AWS Certified Solutions Architect, or CISSP.

More like this

Similar roles

Security Engineer, Incident Response

F5 Inc

Remote 28 days ago $132,000–$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Principal Security Engineer, Incident Response

F5 Inc

Remote 28 days ago $182,200–$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Cyber Defense Response Analyst II

CME Group

Chicago, IL 36 days ago $93,900–$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM