More jobs:
Senior Security Incident Response Engineer
Job in
Atlanta, Fulton County, Georgia, 30383, USA
Listed on 2025-12-18
Listing for:
Acrisure, LLC
Full Time
position Listed on 2025-12-18
Job specializations:
-
IT/Tech
Cybersecurity, Network Security
Job Description & How to Apply Below
1170 Peachtree St Ste 1200 - ATLANTA, GA:
AUSTIN, TX:
GRAND RAPIDS, MItime type:
Full time posted on:
Posted Todayjob requisition :
JR110503##
** About Acrisure
** A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and the last eleven years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries.
Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win.
*
* Job Summary:
** The Senior Incident Response Engineer will lead advanced security incident response efforts, focusing on Microsoft E5 security capabilities and Data Loss Prevention (DLP). This role combines technical expertise with leadership responsibilities, ensuring robust detection, containment, and remediation of threats while driving proactive security measures across the enterprise.
** Responsibilities:
**** Incident Response:
*** Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers.
* Lead post-incident reviews and drive process improvements.
* Perform advanced threat hunting using Microsoft Defender and related tools.
* Integrate threat intelligence and adapt detection strategies based on real world threats observed by the organization.
* Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents.
* Develop and maintain incident response playbooks and runbooks across the security operations toolset.
* Collaborate with analysts and other IR engineers to identify opportunities for improvement and tuning of detection rules.
* Collaborate with IT, legal, HR, communications, and other business units
** Microsoft Security & Policy Design:
*** Collaborate on the design, implementation, and maintenance of security policies for Microsoft security components, including: + Defender for Endpoint + Defender for Cloud Apps + Microsoft Purview DLP + Intune + Conditional Access & Information Protection
* Regularly review and update policies based on evolving threats and lessons learned.
* Collaborate with compliance and IT teams to enforce security standards and regulatory requirements.
** Requirements:
*** Proficiency with Microsoft 365 Security Suite as well as other security tooling such as Sentinel One, Google Sec Ops, Abnormal Security, and others.
* Strong experience with incident response, digital forensics, and threat hunting across a hybrid environment.
* Knowledge of endpoint operating systems (Windows, macOS, and Linux).
* Experience with cloud environments such as Azure, AWS, and GCP.
* Experience with scripting (Power Shell, Python, or Bash) for automation and log parsing desired.
* Embrace a metric-driven approach to continuous improvement.
* Excellent analytical and critical thinking skills; ability to work in high-pressure situations.
* Effective verbal and written communication abilities.
* Meticulous with strong organizational skills and the ability to handle multiple priorities.
* Ability to work independently and within a collaborative, team-oriented environment.
*
* Education and Experience:
*** Minimum 5 years of progressive information security experience.
* At least 4 years focused on incident response, including investigations across different security domains (endpoint, application, DLP, and more).
* Expertise in Infrastructure Security:
In-depth understanding of infrastructure security, including Windows, Active Directory, Unix/Linux, Mobile Security, and Privileged Access Management.
* Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, MS SC-200, MS SC-400 or similar.#LI-CH1
** Candidates should be comfortable with an on-site presence to support…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×