Philadelphia Indemnity Insurance Company

Senior Incident Response/Operations Engineer

Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in cybersecurity operations
  • 3+ years of incident response experience
  • Skilled in creating incident reports for leadership
  • Proficient in threat hunting using intelligence data
  • Strong network and host security event analysis
  • System administration expertise in Windows or Linux
  • Coding proficiency in languages like Python or Perl

Responsibilities

  • Lead security incident investigations and resolutions
  • Monitor and ensure optimal security system performance
  • Manage security tools to detect and mitigate threats
  • Maintain security data integrity and robust feeds
  • Collaborate with team on proactive threat detection
  • Create threat detection rules and SOAR playbooks
  • Refine key performance metrics for security operations
  • Identify process automation opportunities to improve efficiency
  • Act as a subject matter expert in security operations
  • Clearly communicate technical information to various audiences
  • Build relationships to enhance team impact
  • Influence team strategy and vision

Benefits

  • Comprehensive benefits package
  • Bonus eligibility based on performance
  • Opportunities for professional development
  • Collaborative work environment
  • Supportive team culture
Full Job Description
Job Summary:

As the Senior Incident Response/Operations Engineer under the Global Fusion Center US Operations, you will handle day-to-day maintenance of security infrastructure in addition to proactive threat hunting and incident response. Your role will be key in the development, installation, configuration, and continuous improvement of the global security operations service and be critical in the response to external and internal threats. This position will require a blend of technical expertise, analytical skills, and effective communication abilities to ensure swift and efficient handling of security events. You will also be expected to identify opportunities to automate and improve effectiveness of operations.

Essential Job Functions:
  • Conduct security investigations and lead security incident response in a cross-functional environment and drive incident resolution
  • Monitor security systems and infrastructure to support best performance and reliability
  • Implement and manage security tools and processes, to detect and mitigate threats
  • Maintain robust security feeds and ensure data integrity
  • Proactively look for threats working with level one analysts, affected teams and security vendors
  • Author threat detection rules and subsequent SOAR playbooks
  • Refine operational metrics, key performance indicators, and service level objectives to measure Security Operations and Incident Response services
  • Identify and implement security process automation, continuously improving processes and tools
  • Be a technical subject matter expert for Security Operations and incident Response services
  • Provide expertise to partnered security teams in mitigation of those threats
  • Communicate complex technical information clearly and concisely to both technical and non-technical audiences
  • Collaborate with partner security teams to offer guidance and bolster support of the organization's security infrastructure
  • Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work
  • Influence and align the team's vision and strategy


Qualifications:
  • 8 or more years of experience in an operational cybersecurity role
  • 3 or more years of hands-on incident response experience
  • Experience developing and delivering on incident and program status for leadership
  • Experience in threat hunting including leveraging intelligence data to proactively find and iteratively investigate suspicious behavior across networks and systems
  • Experience analyzing network and host-based security events
  • Proficient System Administration with either Microsoft Windows or Linux
  • Proficient with CLI shells such as PowerShell or bash
  • Proficient with Security Log infrastructure configuration such as Windows Event Forwarding (WEF) or syslog
  • Proficient in an interpreted language such as Python, Perl, or Ruby
  • Familiarity with regular expressions
  • Familiarity with Large Language Models tools such as Ollama
  • Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux
  • Knowledge of networking technologies, specifically TCP/IP and the related protocols
  • Understanding of networks, operating systems, and architecture and how they affect the security posture of a company
  • Strong problem-solving aptitude
  • Demonstrated ownership of projects or tasks
  • Strong verbal and written communication skills
  • Demonstrated professionalism and a calm demeanor while dealing with complex or high-urgency situations


Salary range $119,000 to $165,000. Ultimate salary offered will be based on factors such as applicant experience and geographic location. Our company offers a competitive benefits package and bonus eligibility on top of base.

About Philadelphia Indemnity Insurance Company

Philadelphia Indemnity Insurance Company is a subsidiary of Tokio Marine Group, a global insurance company. They offer a range of commercial insurance products, including property, liability, and automobile coverage. They work with a network of independent agents and brokers to provide customized insurance solutions to businesses of all sizes. They are committed to providing exceptional customer service and have received numerous awards for their claims handling and underwriting expertise.
Learn more about Philadelphia Indemnity Insurance Company
Size
1,000 employees
Industry
Founded
1980

Similar Jobs

More Jobs at Philadelphia Indemnity Insurance Company

More Information Technology Jobs

Find similar Senior Incident Response/Operations Engineer jobs: