Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Xplor

$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3 to 6 years in security operations or incident response
  • Confidence in managing incident-handling lifecycle
  • Strong triage and root cause analysis skills
  • Log reading proficiency (HTTP, SMTP, network)
  • Hands-on experience with SIEM tools, preferably Microsoft Sentinel
  • Practical knowledge of EDR and advanced threat protection
  • Experience in threat hunting and detection automation
  • Understanding of attacker tools and techniques (TTPs)

Responsibilities

  • Own and manage security incidents from detection to eradication
  • Lead collaborative live incident response with the team
  • Conduct in-depth investigations into security events using various data sources
  • Perform forensics and malware triage to establish incident timelines
  • Coordinate incident responses with IT and broader security teams
  • Proactively hunt for threats and develop indicators of compromise
  • Automate incident response workflows for efficiency
  • Enhance detection coverage leveraging the MITRE ATT&CK framework
  • Feed insights from incidents back into security processes for improvement

Benefits

  • 12 weeks of Gender Neutral Paid Parental Leave
  • 3 additional days off to volunteer and give back
  • Unlimited access to LinkedIn Learning
  • Regular career and growth conversations
  • Commitment to Diversity & Inclusion initiatives
  • Access to free mental health support
  • Flexible working arrangements
  • Medical and life insurance
Full Job Description
Job Description

About the role

Our Cyber Threat Intelligence & Response (CTIR) engineers are the people we count on when something goes wrong, and the people who make sure it goes wrong far less often. This is a hands-on incident response role. You'll lead the response to security events across our platforms and applications: triage, investigate, contain, eradicate and recover, then make sure we come out of it stronger.

We're looking for someone who genuinely loves incident response. Someone who gets calmer and sharper when an incident kicks off, who is confident making decisions when the picture isn't complete, and who doesn't wait to be told what to look at. If you're a self-starter who takes ownership from the first alert to the final report, you'll fit right in.

Location: Remote

Reports to: VP of Cybersecurity / Cyber Threat Intelligence, Engineering & Response

What you'll do
  • Own incidents as part of the CTIR team: detect, triage, investigate, contain and eradicate, driving each one until the threat is under control.
  • Work live incidents alongside the team and be ready to step up and take the lead yourself when the situation calls for it.
  • Lead investigations across our systems, digging into logs, endpoints, email and network data to work out what happened, how far it reached, and how to resolve.
  • Perform host and network forensics, malware triage, and email analysis (including PDF and document analysis) to understand attacker activity and build a reliable timeline.
  • Coordinate with engineering, IT and the wider security team during a response, and communicate clearly to both technical teams and leadership.
  • Hunt proactively for threats across system logs, user behaviour and threat intelligence, turning what you find into new detections and indicators of compromise.
  • Build and automate incident response workflows and playbooks so routine response is fast and repeatable.
  • Strengthen our detection coverage using the MITRE ATT&CK framework, closing monitoring gaps, and tuning to reduce noise.
  • Feed what you learn from each incident back into how the team detects and responds, so an attack pattern we've seen once is caught faster next time.
  • Analyse threat intelligence, research emerging threats, and recommend practical mitigation.
  • Be ready to work incidents as they arise, including on-call and out-of-hours cover when needed.


Qualifications

What we're looking for

People who want to make a real difference in security, and who care about incident response in particular.
  • 3 to 6 years experience in security operations or incident response, with genuine passion for running incidents, not just watching a queue.
  • Confidence managing incidents through the full incident-handling lifecycle, and the judgement to make sound calls under pressure.
  • Strong triage and root cause analysis, with a solid understanding of different log sources and how to correlate events across them.
  • Comfortable reading logs (HTTP, SMTP, network), Windows and Active Directory, and common operating systems and servers.
  • Hands-on experience with a SIEM to investigate, hunt and build detections. Microsoft Sentinel and KQL preferred.
  • Practical experience across EDR, advanced threat protection, identity management and API security.
  • Threat-hunting experience across network flow, user behaviour and threat intelligence, plus the ability to design new ways to detect and contain attacks using scripting, analytics and automation.
  • Familiar with a broad range of attacker tools and techniques (TTPs), with the ability to map adversary activity across the Cyber Kill Chain to identify, assess, and communicate potential attack progression.
  • A self-starter who works independently, delivering projects without being chased, and keeps learning as the industry develops.
  • A critical thinker with strong problem-solving instincts and exceptional communication skills, capable of translating complex technical risks into clear, actionable insights for both the immediate team and cross-functional partners, including engineers, administrators, and leadership, through both verbal and written communication.
  • Good understanding of ITIL processes and standards such as ISO 27001 and PCI DSS, including change, incident and problem management.

Nice to have
  • Malware analysis experience.
  • Preferred certifications such as GCIH, GCFA, AZ-500 or SC-100.
  • Experience with Jupyter Notebooks for threat-hunting.
  • Python and PowerShell scripting.
  • Experience building and tuning SOAR automation for response.


Additional Information

Values and Life at Xplor

Our four core values - Make life simple, Build for people, Move with purpose and Create lasting communities - are key to who we are and guide us from how we hire to how we recognise our team members.

Our four core values guide us from how we hire and recognise our team members to how we interact with our customers day to day:

Make life simple
Build for people

Move with purpose
Create lasting communities.

If these values sound like you, and describe people you want to work with, you will thrive at Xplor.

As an Xplorer, you will be part of a global network of talented colleagues who will support your success. We look for commonalities and shared passions and give people the tools they need to deliver great work and grow at speed.

Some of our perks and benefits are: *include additional benefits provided in your region*
  • 12 weeks Gender Neutral Paid Parental Leave for both primary and secondary carer
  • #GiveBackDays/Commitment to social impact - 3 extra days off to volunteer and give back to your local community
  • Unlimited access to LinkedIn Learning, plus regular career and growth conversations with your leader, as part of Xplor GPS
  • Ongoing dedication to Diversity & Inclusion initiatives such as D&I Council, Global Mentorship Program
  • Access to free mental health support
  • Flexible working arrangements
  • Medical and life insurance

Ready to apply?

To start your application, please submit your resume and we will be in touch as soon as we can. Please include the word "moonshot" at the top of your message to the Hiring Manager so that we know you took the time to read our job ad.

#LI-remote

Similar Jobs

More Jobs at Xplor

More Information Technology Jobs

Find similar Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response jobs: