Senior Incident Response Security Engineer, Escalations

Intuit

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Charlotte, NC
Posted
2 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $183k
$127k most similar roles pay here $231k

This listing doesn't post a salary. Most similar roles pay $153,675–$212,000.

Based on 240 similar postings.

Employer

About Intuit

Intuit is a financial software company known for products like TurboTax, QuickBooks, Mint, and Credit Karma, helping consumers and small businesses manage their finances and taxes. Industry: Financial Software & Technology

Intuit currently has 189 open roles on FindRole.

Listed pay typically runs $202,500–$274,000 across 165 roles with salary data.

Most-posted roles

View all roles at Intuit

At a glance

TL;DR · Senior Incident Response Security Engineer, Escalations

The Senior Incident Response Security Engineer - Escalations joins the Escalations team within the Security Operations Center to defend against modern cyber-attacks. This role involves overseeing escalated security events, conducting root cause investigations, and managing incident communications for critical issues. The engineer will build and improve response playbooks, provide training to junior responders, and collaborate with legal and risk teams to ensure regulatory compliance. Key responsibilities include investigating risks specific to AI/LLM-based tools, such as prompt injection and data leakage. Required skills include proficiency in EDR and CSPM tools like CrowdStrike Falcon and Wiz, SIEM platforms like Splunk or LogScale, and cloud security across AWS, Azure, and GCP. The candidate must navigate frameworks including MITRE ATT&CK, NIST, and OWASP while utilizing frontier AI platforms to accelerate triage and documentation within the security lifecycle.

What you'll do

  • Oversee and respond to escalated security events while activating incident response plans as required.
  • Provide on-call support for critical issues and manage communications with stakeholders regarding incident status.
  • Lead investigations to determine the root cause, scope, and impact of security incidents.
  • Utilize frontier AI platforms and tools to accelerate triage, investigation, and documentation processes.
  • Investigate and respond to specific threats involving AI/LLM-based tools and agentic platforms.
  • Develop and maintain incident response plans, procedures, and playbooks for swift action and compliance.
  • Provide guidance and training on security best practices and incident handling to internal partners.
  • Mentor junior responders on forensic analysis, cloud security forensics, and technical best practices.

What we're looking for

  • 3-5 years of experience in a dedicated cybersecurity role with an emphasis on digital forensics and incident response.
  • 1-3 years of experience writing scripts or code to automate security work using AI coding assistants and platforms.
  • Working knowledge of AI/LLM security risks, including OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • Experience performing analysis and detection engineering using EDR or CSPM tools like CrowdStrike Falcon and Wiz.
  • Deep understanding of SIEM solutions such as Splunk or LogScale.
  • Experience securing and managing public cloud services (AWS, Azure, GCP) including IAM, CI/CD pipelines, and network security.
  • Comprehensive understanding of cybersecurity, networking/cloud fundamentals, and frameworks like OWASP, MITRE ATT&CK, NIST, and CIS.
  • A Bachelor's degree or higher in technology, computer science, cybersecurity, or a related field (preferred).
  • Industry-recognized professional certifications such as AWS Security Specialty, GIAC, ISC2, or AI security credentials (preferred).

More like this

Similar roles

Principal Security Engineer, Incident Response

F5 Inc

Remote 13 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Security Engineer, Incident Response

F5 Inc

Remote 13 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Draper, UT 29 days ago $136,200$214,005
Incident Response SIEM SOAR EDR XDR Python PowerShell Bash MITRE ATT&CK Threat Hunting Threat Modeling AWS Microsoft Azure Google Cloud Platform Digital Forensics AI DLP STRIDE
8+ yrs exp

Security Incident Response Engineer

Stripe

Remote (Chicago, IL) +3 7 days ago $144,300$216,500
Python SQL Log Analysis Network Security Digital Forensics Incident Response Databricks Jupyter Trino PySpark Pandas Sci-kit Learn osquery Splunk LogScale UEBA SIEM SOAR DLP
3+ yrs exp Remote

Staff Technical Support Engineer, FortiSIEM

Fortinet

Sunnyvale, CA 27 days ago $110,000$134,000
Linux Windows Server FortiSIEM TCP/IP Firewalls VPN Elasticsearch Clickhouse VMware KVM Proxmox Nutanix AWS Azure GCP Python Bash PowerShell JavaScript C++ Java
6+ yrs exp