All jobs

Cybersecurity Engineer - Incident Response & Threat Detection

100% Remote Full-time Open now

This a Full Remote job, the offer is available from: United States

Job Description

Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team. Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and security is critical to its success. We are seeking a professional who is passionate about protecting the organization, capable of leading response efforts during security incidents, and eager to mature enterprise-wide incident detection, investigation, and response capabilities. You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in detecting, investigating, containing, and remediating cyber incidents, while helping to strengthen Fragomen’s overall security posture. How Will You Make a Difference at Fragomen? As a Security Engineer focused on Incident Response, you will:

  • Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
  • Monitor, investigate, and correlate security alerts using SIEM, EDR, and forensic tools.
  • Perform digital forensic investigations across endpoints, servers, cloud, and network environments.
  • Triage and escalate security events in accordance with established incident response procedures.
  • Develop, maintain, and continuously improve incident response playbooks, SOPs, and workflows.
  • Improve alert quality and response effectiveness through root cause analysis and post-incident reviews.
  • Partner with IT, Legal, Compliance, Privacy, and Risk teams during security incidents.
  • Support regulatory, legal, and client-driven incident response and reporting requirements.
  • Participate in and facilitate incident response tabletop exercises and simulations.
  • Contribute to the design and enhancement of detection, logging, and monitoring capabilities.
  • Provide technical guidance and mentorship to junior analysts and security team members.

Required Qualifications

  • 1+ years of experience in cybersecurity, incident response, or security operations.
  • Hands-on experience responding to security incidents in enterprise environments.
  • Strong ability to analyze security events and perform technical investigations.
  • Working knowledge of:
  • TCP/IP, DNS, HTTP/S, VPNs, firewalls, and proxy technologies
  • Windows and Linux operating systems
  • Identity and access systems and authentication mechanisms
  • Experience using SIEM and security platforms such as:
  • Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar
  • Ability to identify and respond to:
  • Phishing and business email compromise
  • Malware and ransomware
  • Credential compromise
  • Lateral movement and persistence mechanisms
  • Brute-force and privilege escalation attacks
  • Strong written and verbal communication skills, especially during high-pressure incidents.
  • Demonstrated ability to follow structured processes while continuously improving them.

Preferred Qualifications

  • Experience with EDR, SOAR, and forensic tooling (e.g., CrowdStrike, Defender, Carbon Black, EnCase, Velociraptor, etc.).
  • Experience supporting investigations involving legal, compliance, or regulatory stakeholders.
  • Knowledge of MITRE ATT&CK and modern adversary tactics.
  • Experience with cloud and SaaS incident response (Azure, M365, AWS, etc.).
  • Relevant certifications, including:
  • GIAC (GCIH, GCFA, GCIA)
  • Offensive Security (OSCP, OSCE, OSEE)
  • Vendor certifications (Splunk, Sentinel, CrowdStrike, etc.)

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations. This offer from "Fragomen" has been enriched by Jobgether.com and got a 72% flex score. Apply tot his job Apply To this Job

You might also like

Senior Incident Response Engineer (Purple Team)

100% Remote Full-time

Cybersecurity Analyst III

100% Remote Full-time

Clinical Project Manager (Research & IT) – Home...

100% Remote Full-time

Solutions Architect 4 (Data Architect) -Remote

100% Remote Full-time

Manager, Data Analyst (Applicants must be legally authorized to work in the United States. The company does not provide visa sponsorship for this position)

100% Remote Full-time

AI Data Engineering Manager

100% Remote Full-time

Sr. Data Governance Analyst & Steward

100% Remote Full-time

IT Business/Data Analyst (Data Governance & Stewardship)

100% Remote Full-time

Data Center Production Operations Engineer

100% Remote Full-time

Master Data Management Analyst - Remote

100% Remote Full-time

[Remote] Collector/Resolution Specialist

100% Remote Full-time

Experienced Customer Service Representative – Work from Home, PA, TN, FL – arenaflex in Warrendale, Pennsylvania

100% Remote Full-time

Mortgage Processing Assistant

100% Remote Full-time

Remote Part‑Time Data Entry Clerk – Entry‑Level Typing Specialist with Flexible Shifts at arenaflex

100% Remote Full-time

Senior Programmatic Manager (Remote Mexico)

100% Remote Full-time

Experienced Remote Data Entry Specialist – Part-Time Administrative Support Opportunity with Flexible Hours at arenaflex

100% Remote Full-time

Licensed Sales Professional (LSP) - Remote - MT

100% Remote Full-time

Amazon Remote jobs - Hiring Now Part-time jobs

100% Remote Full-time

Junior Financial Analyst

100% Remote Full-time

Channel Marketing Manager

100% Remote Full-time