Senior Security Engineer, Digital Forensics and Incident Response (DFIR)

Intuit

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Frisco, TX
Posted
2 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $182k
$122k most similar roles pay here $224k

This listing doesn't post a salary. Most similar roles pay $151,475–$212,250.

Based on 240 similar postings.

Employer

About Intuit

Intuit is a financial software company known for products like TurboTax, QuickBooks, Mint, and Credit Karma, helping consumers and small businesses manage their finances and taxes. Industry: Financial Software & Technology

Intuit currently has 198 open roles on FindRole.

Listed pay typically runs $202,500–$274,000 across 173 roles with salary data.

Most-posted roles

View all roles at Intuit

At a glance

TL;DR · Senior Security Engineer, Digital Forensics and Incident Response (DFIR)

Senior Security Engineer - Digital Forensics and Incident Response (DFIR) joins the Security Operations Center team to defend against cyber-attacks and manage incident response processes. This role involves responding to escalated security events, performing forensic investigations to determine root causes, and developing playbooks for emerging AI and agentic system risks like data leakage or unauthorized model access. The engineer will build threat hunting capabilities, tune detections, and provide training on cloud security forensics. Key technical requirements include proficiency in Bash, PowerShell, and Python for automation, alongside experience with CrowdStrike Falcon, Wiz, Splunk, and LogScale. Candidates must navigate complex environments involving AWS, Azure, and GCP while applying frameworks like MITRE ATT&CK, NIST, and OWASP. The role addresses critical security challenges by integrating incident response operations with compliance requirements to protect organizational assets from sophisticated threats.

What does a Security Engineer earn?

Median $185000 from 85 postings across 39 companies.

See salary data

What you'll do

  • Respond to escalated security events and activate the Security Incident Response Plan as required.
  • Provide on-call support for critical issues while managing stakeholder communications and incident reporting.
  • Lead forensic investigations to determine the root cause, scope, and impact of security incidents.
  • Investigate and mitigate risks specific to AI/LLM tools, including data leakage and unauthorized model access.
  • Develop and maintain incident response plans, procedures, and playbooks for regulatory compliance.
  • Utilize AI SOC platforms and frontier tools to accelerate triage, detection tuning, and documentation.
  • Mentor team members on incident handling techniques, forensic analysis, and cloud security best practices.
  • Execute hypothesis-driven threat hunting across endpoint, cloud, and network telemetry to uncover hidden threats.

What we're looking for

  • 3-5 years of experience in a dedicated cybersecurity role with an emphasis on digital forensics and incident response.
  • 1-3 years of experience writing scripts or code in Bash, PowerShell, or Python to automate security work.
  • Proficiency in performing analysis and detection engineering using EDR or CSPM tools such as CrowdStrike Falcon and Wiz.
  • Experience defending public cloud services including AWS, Azure, and GCP across IAM, CI/CD pipelines, and network security.
  • Deep understanding of SIEM solutions like Splunk and LogScale.
  • Knowledge of AI/LLM security risks and frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • A Bachelor's degree or higher in Technology, Computer Science, Cybersecurity, or a related field (preferred).
  • Industry-recognized certifications such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials (preferred).

More like this

Similar roles

Security Engineer, Incident Response

F5 Inc

Remote 15 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Draper, UT 30 days ago $136,200$214,005
Incident Response SIEM SOAR EDR XDR Python PowerShell Bash MITRE ATT&CK Threat Hunting Threat Modeling AWS Microsoft Azure Google Cloud Platform Digital Forensics AI DLP STRIDE
8+ yrs exp

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 94 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 94 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Firewalls
5+ yrs exp Hybrid

Senior Security Engineer

Green Dot Corp

Los Angeles, CA 94 days ago $113,400$162,000
Azure Network Security Penetration Testing CI/CD DevSecOps Identity and Access Management (IAM) NIST CIS Benchmarks OWASP SSDLC Azure Firewall Network Security Groups Key Vault Defender Firewalls
5+ yrs exp Hybrid