Acrisure

Security Incident Response Engineer

Acrisure$95K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or equivalent experience.
  • Minimum 3 years of progressive information security experience.
  • Strong understanding of incident response methodologies and attack lifecycle.
  • Experience with EDR platforms like Microsoft Defender, CrowdStrike, or similar.
  • Experience with SIEM technologies including Microsoft Sentinel, Splunk, or equivalent.
  • Knowledge of cloud security concepts and Microsoft 365.
  • Familiarity with Windows, Linux, and macOS operating systems.

Responsibilities

  • Investigate and respond to cybersecurity incidents across various platforms.
  • Perform incident triage, classification, and recovery activities.
  • Execute incident response procedures per the Cyber Incident Response Plan (CIRP).
  • Coordinate response efforts across multiple business and technical teams.
  • Maintain detailed records of incidents, timelines, and lessons learned.
  • Analyze alerts from EDR, SIEM, and other security platforms to validate incidents.
  • Conduct proactive threat hunting to identify potential security threats.

Benefits

  • Collaborative work environment fostering cross-functional partnerships.
  • Opportunities for continuous professional development and training.
  • Involvement in a critical role impacting global cybersecurity efforts.
  • Participation in after-hours incident response and on-call rotations.
  • Engagement in innovative security engineering projects.
Full Job Description


Job Summary:

The Security Incident Response Engineer is responsible for detecting, investigating, containing, eradicating, and recovering from cybersecurity incidents across Acrisure's global environment. This role serves as a key member of the Security Operations team and works closely with Infrastructure, Cloud, Identity, Workplace Technology, Legal, Privacy, Human Resources, and business stakeholders to rapidly respond to security threats and reduce organizational risk.

The engineer leverages enterprise security technologies including EDR, SIEM, cloud security platforms, email security solutions, threat intelligence, and security automation tooling to identify and respond to attacks impacting endpoints, identities, cloud environments, applications, and data. This position combines hands-on incident response, threat hunting, detection tuning, forensic investigation, and continuous improvement activities.

Success in this role means rapidly detecting and containing threats before they become business-impacting events, continuously improving the organization's ability to respond to attacks, and driving measurable reductions in response times, incident severity, and operational risk.

Responsibilities:

Incident Response Operations

  • Investigate and respond to cybersecurity incidents involving endpoints, identities, cloud platforms, email systems, applications, data, and network infrastructure.
  • Perform incident triage, severity classification, impact analysis, containment, eradication, and recovery activities.
  • Execute cyber incident response procedures and escalation processesin accordance withthe Cyber Incident Response Plan (CIRP).
  • Coordinate response efforts across Security, Infrastructure, Cloud, IAM, Workplace Technology, Legal, Privacy, Human Resources, and business teams.
  • Support major incident management activities and provide technical leadership during active security events.
  • Maintain detailed incident records, timelines, evidence, findings, and lessons learned.

Threat Detection and Investigation

  • Analyze alerts generated by EDR, SIEM, MDR, email security, cloud security, deception, and threat intelligence platforms.
  • Validate suspicious activity to distinguish true security incidents from false positives.
  • Perform root cause analysis toidentifyattack vectors, affected assets, compromised accounts, and attacker activities.
  • Conduct proactive threat hunting toidentifyindicators of compromise, adversary behaviors, and emerging threats.
  • Leverage MITRE ATT&CK techniques to improve detection and investigative effectiveness.

Digital Forensics and Evidence Collection

  • Collect, preserve, and analyze system, endpoint, cloud, email, and identity-related evidence.
  • Perform log analysis, forensic triage, malware investigation, and timeline reconstruction.
  • Support legal, regulatory, audit, and compliance investigations asrequired.
  • Maintainevidencehandling and chain-of-custody procedures where applicable.

Security Engineering and Continuous Improvement

  • Develop andmaintainincident response playbooks, investigation procedures, and operational runbooks.
  • Recommend detection improvements, new use cases, automations, and response capabilities.
  • Tune security alerts and detection logic to improve fidelity and reduce false positives.
  • Assistin the implementation and improvement of SOAR workflows and automated response capabilities.
  • Participate in tabletop exercises, incident simulations, and purple team activities.

Metrics and Reporting

  • Track and report operational metrics including:
  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Incident volume
  • Severity trends
  • Containment effectiveness
  • Detection fidelity
  • Produce incident reports, executive summaries, and post-incident reviews.
  • Identifyrecurring trends and recommend corrective actions.

Collaboration and Enablement

  • Partner with Security Engineering teams to improve telemetry, monitoring, and investigative capabilities.
  • Work with Vulnerability Management and Exposure Management teams on remediation activities resulting from incidents.
  • Provide guidance and mentorship to analysts and junior responders.
  • Participate in after-hoursincident response and on-call rotations asrequired.

Education and Experience:

  • Bachelors degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience).
  • Minimum 3 years of progressive information security experience.
  • Strong understanding of incident response methodologies, attack lifecycle, and containment strategies.
  • Experience with one or more EDR platforms such as Microsoft Defender for Endpoint,SentinelOne, CrowdStrike, or equivalent.
  • Experience with SIEM technologies such as Microsoft Sentinel, Google SecOps, Splunk,QRadar, or similar platforms.
  • Knowledge of Microsoft 365, Entra ID, Active Directory, and cloud security concepts.
  • Understanding ofMITRE ATT&CK, threat intelligence, and threat hunting methodologies.
  • Familiarity with Windows, Linux, and macOS operating systems.
  • Ability to analyze logs, indicators of compromise (IOCs), and attacker techniques.
  • Experience with PowerShell, Python, KQL, or other scripting/query languages.

#LI-CH1

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

About Acrisure

Acrisure is an insurance brokerage firm that provides a range of insurance products and services to businesses and individuals. The company was founded in 2005 and is headquartered in Caledonia, Michigan. Acrisure offers a wide range of insurance products, including property and casualty, employee benefits, and personal lines insurance. The company has grown rapidly through a series of acquisitions, and now has over 500 offices in the United States and around the world. Acrisure has been recognized as one of the fastest-growing companies in the United States, and has won numerous awards for its innovative insurance products and services.
Learn more about Acrisure
Size
7,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Acrisure

More Information Technology Jobs

Find similar Security Incident Response Engineer jobs: