Senior Security Engineer/Incident Response
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Security Management & Operations
Senior Security Engineer / Incident Response
Lead Stack Inc. is an award-winning, one of the nation's fastest-growing, certified minority-owned (MBE) staffing services provider of contingent workforce. As a recognized industry leader in contingent workforce solutions and Certified as a Great Place to Work, we're proud to partner with some of the most admired Fortune 500 brands in the world.
Duration: 12+ Months (Contract to Hire)
Location:
Blue Ash, OH – Onsite Pay Rate: $70-80/hr on w2
Job Description:
To Vendors
This is a 12+ month contract to hire opportunity, supporting Corporate Information Security.
Candidates will be required to be on-site 5 days/week.
This is a senior-level individual contributor role with no direct reports.
Candidates should have directly relevant Security Operations and investigation experience. Lack of relevant hands-on experience will be a disqualifier.
Pre-screen consists of 5 unique questions specific to the role
Job Description
The Senior Security Engineer will support day-to-day Security Operations, with a focus on investigating security events and responding to complex security incidents. This person will lead containment, eradication, and recovery efforts across endpoint, cloud, and identity-related incidents and serve as an escalation point for more complex security events. This is a senior-level individual contributor role requiring strong Security Operations experience, critical thinking, attention to detail, and the ability to communicate effectively in high-pressure situations.
The ideal candidate will be able to break down complex technical information and communicate clearly with both technical and non-technical stakeholders.
Requirements
· Strong experience in Security Operations, security investigations, and incident response
· Hands-on experience investigating and responding to security events and incidents
· Experience supporting containment, eradication, and recovery activities
· Experience with security alerts and detections
· Experience developing or maintaining security playbooks and/or runbooks
· Understanding of Security Operations tooling such as SIEM/SOAR, EDR, email security gateways, and firewalls
· Strong critical-thinking and problem-solving skills
· Ability to break down complex technical topics and communicate them clearly to technical and non-technical audiences
· Strong written and verbal communication skills
· Demonstrated leadership within an individual contributor role
· Experience mentoring junior team members
Nice-to-Haves
· Experience with detection engineering
· Experience with rule or alert tuning
· Familiarity with the MITRE ATT&CK framework, including mapping security activity or detections to relevant tactics and techniques
· Experience with cloud environments such as Azure, GCP, or AWS
· Familiarity with Google Security Operations
· Experience contributing to tabletop exercises or security audits
Key Responsibilities
· Lead containment, eradication, and recovery efforts for endpoint, cloud, identity, and other security incidents
· Serve as an escalation point for complex security events and incidents
· Investigate security events and determine appropriate response actions
· Contribute to the development and improvement of security playbooks and runbooks
· Provide feedback to the Detection team to improve the quality of detections, enrichment, and automated response
· Collaborate with cross-functional teams to improve logging visibility and response readiness
· Contribute to operational maturity through playbooks, mentoring, tabletop exercises, detections, and audits
· Mentor junior team members and help build their Security Operations capabilities
· Communicate technical information effectively to both technical and non-technical stakeholders
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).