Acrisure

Security Incident Response Engineer

Acrisure$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in information security with a focus on incident response
  • Strong expertise in leading EDR platforms (e.g., SentinelOne, CrowdStrike)
  • Proficient in scripting for automation (PowerShell, Python, or Bash)
  • Experience with endpoint operating systems (Windows, macOS, Linux)
  • Relevant industry certifications (GCFA, GCIH, CHFI, CySA+) preferred
  • Strong analytical, problem-solving, and communication skills
  • Detail-oriented with effective organization skills

Responsibilities

  • Detect and analyze security incidents using EDR and other tools
  • Lead investigations and containment efforts for endpoint security threats
  • Develop remedial strategies to eliminate root causes of incidents
  • Conduct forensic data acquisition and log analysis for endpoints
  • Create and maintain incident response playbooks for EDR technologies
  • Monitor and tune alerting rules to enhance threat detection
  • Train teams and end-users on effective EDR usage

Benefits

  • Comprehensive medical, dental, and vision insurance
  • Generous paid time off and holidays along with EAP access
  • 401(k) plan with immediate vesting and HSA/FSA options
  • Paid maternity and paternity leave for all parents
  • Pet insurance and legal plan coverage available
Full Job Description

Job Summary:

Acrisure is seeking a Security Incident Response Engineer to join our growing team. The Security Incident Response Engineer – EDR will support the organization’s security operations with a focus on endpoint detection and response (EDR) management and incident response activities. To succeed in this role, the candidate must be adept at coordinating and triaging security incidents, responding promptly and effectively to threats, and managing EDR toolsets at scale. The engineer will proactively monitor, analyze, and resolve security incidents involving endpoints, requiring high attention to detail and the ability to balance multiple urgent tasks. Key to this position is being a self-starter, consistently prioritizing critical tasks, and maintaining strong commitment to operational excellence. 

Responsibilities:

Incident Response

  • Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers. 
  • Lead or participate in investigation and containment efforts for both endpoint and identity related security threats. 
  • Develop and implement strategies to remove the root cause of the incident. 
  • Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents. 
  • Develop and maintain incident response playbooks and runbooks specific to EDR technologies. 
  • Analyze security alerts and anomalies to determine if they represent actual security incidents.  

EDR Deployment and Configuration 

  • Oversee deployment, configuration, and ongoing management of EDR on endpoints for comprehensive coverage. 
  • Monitor and tune alerting rules/policies to reduce false positives and ensure accurate threat detection. 
  • Maintain compliance measures by enforcing configuration to organizational standards. 
  • Provide training on EDR usage to incident response teams and end-users.  
  • Review security alerts, correlate event data, and identify risks to endpoints.
  • Maintain integration of EDR tools with SIEM and other security solutions. 
  • Regularly review and update endpoint security policies based on threat intelligence and incident learnings. 

Requirements

  • Proficiency with leading Endpoint Detection and Response platforms (SentinelOne, Microsoft Defender, CrowdStrike, or other toolsets). 
  • Strong experience with incident response, digital forensics, and threat hunting on endpoints. 
  • Knowledge of endpoint operating systems (Windows, macOS, and Linux). 
  • Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing. 
  • Excellent analytical and problem-solving skills; ability to work in high-pressure situations. 
  • Effective verbal and written communication abilities. 
  • Detail-oriented with strong organizational skills and the ability to handle multiple priorities. 
  • Ability to work independently and within a collaborative, team-oriented environment. 

Education and Experience:

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience). 
  • Minimum 3 years of progressive information security experience. 
  • At least 1-3 years focused on incident response, including hands-on EDR work. 
  • Expertise in Infrastructure Security: In-depth understanding of infrastructure security, including Windows, Active Directory, Unix/Linux, Mobile Security, and Privileged Access Management.  
  • Experience with Microsoft M365 security including Entra ID, Microsoft Defender for M365, and other toolsets is a plus. 
  • Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, or similar. 

#LI-CH1

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

Why Join Us:

At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.

Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.

 

Employee Benefits

We also offer our employees a comprehensive suite of benefits and perks, including:

  • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.

  • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.

  • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.

  • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.

  • … and so much more!

This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.

 

About Acrisure

Acrisure is an insurance brokerage firm that provides a range of insurance products and services to businesses and individuals. The company was founded in 2005 and is headquartered in Caledonia, Michigan. Acrisure offers a wide range of insurance products, including property and casualty, employee benefits, and personal lines insurance. The company has grown rapidly through a series of acquisitions, and now has over 500 offices in the United States and around the world. Acrisure has been recognized as one of the fastest-growing companies in the United States, and has won numerous awards for its innovative insurance products and services.
Learn more about Acrisure
Size
7,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Acrisure

More Information Technology Jobs

Find similar Security Incident Response Engineer jobs: