Philadelphia Indemnity Insurance Company

Senior Incident Response/Operations Engineer - Hybrid, New York, NY

Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in operational cybersecurity roles
  • 3+ years of hands-on incident response experience
  • Experience reporting incident statuses to leadership
  • Proficient in threat hunting with intelligence data
  • Strong skills in analyzing network and host-based security events
  • Knowledgeable in Windows or Linux System Administration
  • Familiarity with security log configuration and CLI shells

Responsibilities

  • Lead security investigations and manage incident response efforts
  • Monitor and maintain security systems for optimal performance
  • Implement tools to detect and mitigate potential threats
  • Maintain security data integrity and manage robust feeds
  • Proactively collaborate with analysts to identify and address threats
  • Develop detection rules and SOAR playbooks for security events
  • Enhance operational metrics to gauge Security Operations effectiveness

Benefits

  • Comprehensive benefits package
  • Bonus eligibility based on performance
  • Employee development and training opportunities
  • Positive work environment with team collaboration
  • Flexible working conditions to support work-life balance
Full Job Description
Job Summary:

As the Senior Incident Response/Operations Engineer under the Global Fusion Center US Operations, you will handle day-to-day maintenance of security infrastructure in addition to proactive threat hunting and incident response. Your role will be key in the development, installation, configuration, and continuous improvement of the global security operations service and be critical in the response to external and internal threats. This position will require a blend of technical expertise, analytical skills, and effective communication abilities to ensure swift and efficient handling of security events. You will also be expected to identify opportunities to automate and improve effectiveness of operations.

Essential Job Functions:
  • Conduct security investigations and lead security incident response in a cross-functional environment and drive incident resolution
  • Monitor security systems and infrastructure to support best performance and reliability
  • Implement and manage security tools and processes, to detect and mitigate threats
  • Maintain robust security feeds and ensure data integrity
  • Proactively look for threats working with level one analysts, affected teams and security vendors
  • Author threat detection rules and subsequent SOAR playbooks
  • Refine operational metrics, key performance indicators, and service level objectives to measure Security Operations and Incident Response services
  • Identify and implement security process automation, continuously improving processes and tools
  • Be a technical subject matter expert for Security Operations and incident Response services
  • Provide expertise to partnered security teams in mitigation of those threats
  • Communicate complex technical information clearly and concisely to both technical and non-technical audiences
  • Collaborate with partner security teams to offer guidance and bolster support of the organization's security infrastructure
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work
  • Influence and align the team's vision and strategy


Qualifications:
  • 8 or more years of experience in an operational cybersecurity role
  • 3 or more years of hands-on incident response experience
  • Experience developing and delivering on incident and program status for leadership
  • Experience in threat hunting including leveraging intelligence data to proactively find and iteratively investigate suspicious behavior across networks and systems
  • Experience analyzing network and host-based security events
  • Proficient System Administration with either Microsoft Windows or Linux
  • Proficient with CLI shells such as PowerShell or bash
  • Proficient with Security Log infrastructure configuration such as Windows Event Forwarding (WEF) or syslog
  • Proficient in an interpreted language such as Python, Perl, or Ruby
  • Familiarity with regular expressions
  • Familiarity with Large Language Models tools such as Ollama
  • Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux
  • Knowledge of networking technologies, specifically TCP/IP and the related protocols
  • Understanding of networks, operating systems, and architecture and how they affect the security posture of a company
  • Strong problem-solving aptitude
  • Demonstrated ownership of projects or tasks
  • Strong verbal and written communication skills
  • Demonstrated professionalism and a calm demeanor while dealing with complex or high-urgency situations


Salary range $119,000 to $165,000. Ultimate salary offered will be based on factors such as applicant experience and geographic location. Our company offers a competitive benefits package and bonus eligibility on top of base.

About Philadelphia Indemnity Insurance Company

Philadelphia Indemnity Insurance Company is a subsidiary of Tokio Marine Group, a global insurance company. They offer a range of commercial insurance products, including property, liability, and automobile coverage. They work with a network of independent agents and brokers to provide customized insurance solutions to businesses of all sizes. They are committed to providing exceptional customer service and have received numerous awards for their claims handling and underwriting expertise.
Learn more about Philadelphia Indemnity Insurance Company
Size
1,000 employees
Industry
Founded
1980

Similar Jobs

More Jobs at Philadelphia Indemnity Insurance Company

More Information Technology Jobs

Find similar Senior Incident Response/Operations Engineer - Hybrid, New York, NY jobs: