Senior Lead Cyber Security Incident Response Engineer

FICO

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Remote
Salary
$136,500–$214,500 / yr
Posted
28 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $175k
This role $176k
$121k most similar roles pay here $224k

This role pays more than 51% of similar roles. Most pay $151,475–$197,775 — the shaded band above. At the midpoint, this role pays about $176k versus about $175k for comparable roles.

Based on 240 similar postings.

Employer

About FICO

FICO (Fair Isaac Corporation) is a data analytics company best known for the FICO credit score, and provides analytics software and tools for fraud detection, credit scoring, and decision management. Industry: Data Analytics & Financial Technology

FICO currently has 9 open roles on FindRole.

Listed pay typically runs $132,300–$207,900 across 9 roles with salary data.

Most-posted roles

View all roles at FICO

At a glance

TL;DR · Senior Lead Cyber Security Incident Response Engineer

As a Senior/Lead Cyber Security - Incident Response Engineer, you will lead defensive security operations with a focus on people, preparedness, and cross-team readiness. You will own the full incident lifecycle—including detection, triage, containment, eradication, recovery, and post-incident review—while designing and facilitating tabletop exercises for stakeholders across security, IT, engineering, legal, and business teams. You will build and maintain IR plans, playbooks, and runbooks to ensure consistent responses. The role involves supporting digital forensics investigations using tools like Magnet Axiom, Velociraptor, Volatility, FTK, and Autopsy. You will work within the PICERL and NIST frameworks while managing cloud environments using SIEM and CSPM tools. Additionally, you will integrate AI and automation into incident response workflows to strengthen detection and controls across cloud and AI security programs.

What you'll do

  • Design and facilitate incident response tabletop exercises for cross-functional teams to test preparedness and identify gaps.
  • Manage the full incident lifecycle including detection, triage, containment, eradication, recovery, and post-incident reviews.
  • Develop and maintain incident response plans, playbooks, and runbooks to ensure consistent and repeatable responses.
  • Partner with threat intelligence and engineering teams to translate exercise findings into improved detections and controls.
  • Conduct digital forensics investigations using industry-standard tools and frameworks like PICERL and NIST.
  • Manage incident response activities within cloud environments using SIEM, CSPM, and other security tooling.
  • Integrate AI and automation into incident response workflows and tabletop exercise processes.
  • Communicate clearly with stakeholders at all levels during active incidents and in formal reporting.

What we're looking for

  • Experience in enterprise incident response across the full lifecycle including detection, triage, containment, eradication, and recovery.
  • In-depth experience designing and facilitating incident response tabletop exercises for cross-functional teams.
  • Good working knowledge of forensics tools such as Magnet Axiom, Velociraptor, Volatility, FTK, or Autopsy.
  • Knowledge of AWS cloud security fundamentals and other cloud security tooling like SIEM and CSPM.
  • Understanding of cloud security and AI security concepts.
  • Ability to communicate clearly with stakeholders at all levels during incidents and in reporting.
  • Must have at least one of the following certifications: GCIH, GCFA, GCFE, AWS Certified Solutions Architect, or CISSP.

More like this

Similar roles

Principal Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Staff Cyber Incident Response Engineer

Adobe

San Jose, CA +2 91 days ago $214,100$310,100
Incident Response Forensics Malware Triage Kubernetes Docker EDR Linux MacOS Windows AWS Azure GCP SIEM Bash Python Ruby Log Analysis Threat Hunting
7+ yrs exp

Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Draper, UT 23 days ago $136,200$214,005
Incident Response SIEM SOAR EDR XDR Python PowerShell Bash MITRE ATT&CK Threat Hunting Threat Modeling AWS Microsoft Azure Google Cloud Platform Digital Forensics AI DLP STRIDE
8+ yrs exp

Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Cyber Defense Response Analyst II

CME Group

Chicago, IL 15 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM