Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Cybersecurity Engineer (Incident Response) image - Rise Careers
Job details

Senior Cybersecurity Engineer (Incident Response)

Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Headquartered in Virginia, we have more than 53,000 employees in approximately 80 countries across all 7 continents.

Amentum is seeking a Senior Cybersecurity Engineer with focus on Incident Response. This is a fully remote and hands-on role, responsible for ensuring Amentum assets are protected from cyber threats. This role provides technical expertise in multiple areas of cybersecurity to include Cloud Security and Endpoint Security. US Citizenship is required to apply. You may work remote-telework from anywhere within the United States.

Responsibilities:

  • Work closely with our MSSP to monitor and improve Incident Response services.
  • Design, develop and implement security controls to protect information systems, enterprise applications and data.
  • Participate in 2nd-level Security Operations Center (SOC) activities, e.g. respond to critical security incidents escalated by a MSSP.
  • Analyze, troubleshoot and investigate security-related IT system anomalies based on platform reporting, network traffic, log files and automated security alerts.
  • Optimize processes/tooling and automate recurring tasks.
  • Provide security oversight and coordination for changes to the IT landscape.
  • Provide off-hours support on an infrequent, but as needed basis.
  • Maintain and update relevant system and process documentation.
  • Perform other duties as assigned.

Knowledge, Skills and Abilities:

  • Self-starter with desire for professional excellence, able to work with minimal supervision.
  • Excellent communication skills, able to prioritize and adapt to dynamic changes in the environment.
  • Ability to travel up to 10%.

Minimum Requirements:

  • Must be a U.S. Citizen
  • Bachelor’s degree in Computer Science, Information Systems or related field plus five (5) years of relevant experience; three (3) years with a Master’s degree
  • Current Security+ or similar industry certification
  • Solid Microsoft Azure experience, including M365
  • Solid understanding of system and network security technologies and related concepts, e.g. boundary protection, network segmentation, firewalls, endpoint security, threat hunting, data protection
  • Effective time management and communication skills
  • Experience in Incident Management and Breach Investigations
  • Experience creating playbooks and detection automations
  • Experience in Threat Intelligence/Hunting using KQL
  • Experience in SIEM Management

Additional desired qualifications and experience:

  • Exposure to Microsoft Sentinel
  • Experience with NIST based controls or similar standard
  • Experience in forensics
  • Azure GCC-H exposure

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, religion, color, sex, gender, national origin, age, United States military veteran’s status, ancestry, sexual orientation, gender identity, marital status, family structure, medical condition including genetic characteristics or information, veteran status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal EEO laws and supplemental language at EEO including Disability/Protected Veterans and Labor Laws Posters.

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Cybersecurity Engineer (Incident Response), PAE

Amentum, a global leader in advanced engineering and innovative technology solutions, is on the lookout for a Senior Cybersecurity Engineer specializing in Incident Response. If you’re passionate about protecting assets from cyber threats and you thrive in a fully remote environment, this might be the right fit for you! In this hands-on role, you’ll collaborate closely with our Managed Security Service Provider to monitor and enhance Incident Response services. Your responsibilities will include designing, developing, and implementing security controls that protect critical information systems and enterprise applications. You will also respond to critical security incidents, analyze and troubleshoot IT system anomalies, and optimize processes and tools. A robust understanding of various cybersecurity aspects is a must, especially Cloud Security and Endpoint Security. Plus, with your strong communication skills and self-starter mentality, you’ll adapt smoothly to the dynamic nature of the cybersecurity landscape. While a bachelor’s degree and substantial experience are required, your drive for professional excellence will set you apart. Join our diverse team and contribute to addressing some of the most significant challenges in security and sustainability!

Frequently Asked Questions (FAQs) for Senior Cybersecurity Engineer (Incident Response) Role at PAE
What are the primary responsibilities of a Senior Cybersecurity Engineer (Incident Response) at Amentum?

As a Senior Cybersecurity Engineer (Incident Response) at Amentum, you'll be responsible for monitoring and improving incident response services in collaboration with our MSSP. You will design and implement security controls, participate in SOC activities, troubleshoot security incidents, and provide security oversight for IT changes. Your role is crucial in ensuring our assets are protected against evolving cyber threats.

Join Rise to see the full answer
What qualifications are required for the Senior Cybersecurity Engineer (Incident Response) position at Amentum?

To qualify for the Senior Cybersecurity Engineer (Incident Response) role at Amentum, you need a bachelor’s degree in Computer Science, Information Systems, or a related field. Additionally, you should have at least five years of relevant experience or three years with a Master’s degree. Current Security+ certification and significant expertise in Microsoft Azure are also essential.

Join Rise to see the full answer
What skills are crucial for a Senior Cybersecurity Engineer (Incident Response) at Amentum?

The key skills required for a Senior Cybersecurity Engineer (Incident Response) at Amentum include a solid understanding of system and network security technologies, exceptional communication skills, and experience in incident management and breach investigations. Familiarity with Microsoft Sentinel, NIST-based controls, and threat intelligence/hunting using KQL is also desirable.

Join Rise to see the full answer
Does Amentum allow remote work for the Senior Cybersecurity Engineer (Incident Response) role?

Yes, Amentum offers a fully remote work opportunity for the Senior Cybersecurity Engineer (Incident Response) position. While you can work from anywhere within the United States, you may be required to provide off-hours support occasionally as needed.

Join Rise to see the full answer
What is the company culture like at Amentum for a Senior Cybersecurity Engineer (Incident Response)?

Amentum prides itself on fostering a diverse and inclusive work environment. As a Senior Cybersecurity Engineer (Incident Response), you will find yourself in a culture that values professional excellence, encourages self-starters, and promotes collaboration. There’s a strong emphasis on addressing significant challenges in security, making it an exciting and rewarding place to work.

Join Rise to see the full answer
Common Interview Questions for Senior Cybersecurity Engineer (Incident Response)
Can you explain your experience with incident response and how it relates to this role?

When answering this question, highlight your previous roles that involved incident response efforts. Discuss specific incidents you managed, the process you followed, and any tools you utilized, such as SIEM. It's also effective to mention how your actions directly contributed to minimizing damage or enhancing security protocols within your previous workplace.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats and solutions?

Share your strategies for staying informed, such as following cybersecurity blogs, attending webinars, or participating in local meetups. Highlight any relevant certifications or continuous education pursuits that reinforce your commitment to remaining knowledgeable about current cyber threats and defense mechanisms.

Join Rise to see the full answer
What tools have you used for threat hunting and incident management?

Discuss specific tools you've utilized, such as Splunk or Microsoft Sentinel, and give examples of how you leveraged these tools in past roles. Explain your approach to threat hunting and incident management, mentioning any metrics you tracked to measure success.

Join Rise to see the full answer
Describe a time when you had to communicate a complex cybersecurity issue to a non-technical audience.

Use the STAR method to structure your response. Describe the Situation, Task, Action, and Result. Focus on how you simplified complex concepts and used analogies or visuals to ensure understanding, demonstrating your effective communication skills.

Join Rise to see the full answer
What measures would you implement to enhance our incident response capabilities?

Outline a structured approach where you assess current protocols, identify gaps, and propose specific measures such as improved training, updated playbooks, or advanced detection tools. Be prepared to defend your recommendations with possible outcomes based on industry best practices.

Join Rise to see the full answer
How would you approach incident investigation and documentation?

Discuss the importance of a thorough, methodical approach to incident investigation, emphasizing documentation. Mention your preference for tools that facilitate collaboration and systematic tracking, ensuring that you can provide insights for future improvements.

Join Rise to see the full answer
What experience do you have with cloud security, especially in environments like Microsoft Azure?

Share specific experiences and projects you’ve worked on within cloud environments, focusing on security measures you implemented on Azure. Emphasize your familiarity with Azure services and how you’ve integrated security practices into cloud architecture.

Join Rise to see the full answer
How do you prioritize your workload during a cyber incident?

Explain your approach to triaging incidents based on severity and potential impact. Describe methods you use to communicate with your team and stakeholders to ensure the most urgent tasks are handled promptly, while documenting findings concurrently.

Join Rise to see the full answer
Discuss your experience with automating security tasks.

Illustrate specific instances where you have successfully automated repeatable security tasks. Discuss the technologies used and the impacts of those automations on efficiency and accuracy within your prior organization.

Join Rise to see the full answer
What do you believe is the most critical skill for a Senior Cybersecurity Engineer focusing on incident response?

Express your viewpoint on crucial skills like analytical problem-solving, communication, or technical expertise, and explain why you believe they are vital in handling incidents effectively. Provide examples of how you've developed these skills throughout your career.

Join Rise to see the full answer
Similar Jobs
Posted 8 days ago

Join the DOJ as a Senior Training and Development Specialist to support the modernization of their inmate management system.

PAE Hybrid US-VA-Fort Belvoir
Posted 8 days ago

Amentum is hiring a Senior Operations Research Analyst to provide critical analytical support and strategic insight for the Agency's operations.

San Diego Foundation Remote No location specified
Posted 11 days ago

Join The San Diego Foundation as an IT Support Analyst to deliver crucial technical support in a hybrid work setting.

Photo of the Rise User
Posted 3 days ago

Become a key player at 700Apps as an Integration Team Lead specializing in WebMethods, steering projects towards efficiency and success.

Photo of the Rise User
Sedgwick Hybrid Atlanta, GA
Posted 12 hours ago

As the IT Director at Sedgwick, you will lead technology initiatives that enhance business operations and support a culture of caring and diversity.

Posted 13 days ago

Join our team as an FMIS Business Analyst, where you'll enhance financial systems and processes in a hybrid work environment.

Photo of the Rise User
Posted 2 days ago

As an Information Systems Security Officer at Agile Defense, you will ensure the implementation of essential security measures for IT systems while collaborating with elite professionals in a spirited culture.

Posted 10 days ago

Join SeaWorld as an IT Technician and support our mission of caring for animals while ensuring a smooth IT operation.

Photo of the Rise User
CGI Hybrid US, Virginia, Newport News, VA
Posted 9 days ago

Join CGI Federal as a Mid-Level Microsoft SQL Database Administrator to drive innovative technology solutions in Newport News, VA.

Photo of the Rise User
Baker Hughes Remote US-TX-HOUSTON-575 N. DAIRY ASHFORD RD, ENERGY CENTER II EC2
Posted 4 days ago

Lead the Oracle ERP Governance & Security Ops team at Baker Hughes, driving cybersecurity and compliance for a global organization.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!