Security Incident Response

March 10

Apply Now
Logo of Lincoln Financial

Lincoln Financial

Lincoln Financial is an organization dedicated to protecting the privacy and security of its job applicants. It actively informs candidates about potential recruitment scams and outlines its robust hiring procedures, making clear that they do not request sensitive personal information during the application process. The company offers a diverse range of career opportunities across various fields including actuarial, finance, legal, and customer service, and is committed to maintaining equal employment opportunities.

Retirement Solutions • Life and Annuities • Group Protection

10,000+ employees

Founded 1905

💸 Finance

👥 HR Tech

📋 Description

• This position continuously monitors the alert queue; investigates security alerts; monitors health of security sensors and endpoints; collects data and context necessary to initiate IR response. • Responsible for correlation and initial triage of security events and indicators generated by security monitoring tools to determining scope, urgency and potential impact. • Document incidents from initial detection through final resolution. • Perform incident response functions including but not limited to - host-based analysis functions through investigating Windows, Linux, and Mac OS X systems to identify suspicious and malicious activities. • Maintain expertise in Operating Systems (Windows/Linux) operations and artifacts to assist in investigations. • Ability to analyze different data types from various sources within the enterprise and draw conclusions regarding past and potential current security incidents. • Provide after-hours (on-call/weekend rotational) support as required to address critical incidents and maintain continuous coverage. • Perform threat hunting exercises to proactively and iteratively discover current or historical threats that evade existing security mechanisms and use that information to improve cyber resilience. • Create and modify SIEM dashboards to clearly identify scope of findings or monitor activity. • Tune and maintain security tool policies (EDR, IPS, Content Filter, etc.) to reduce false positives and improve tool detection capabilities.

🎯 Requirements

• 3 - 5+ Years Experience with one or more of the following technologies: Endpoint Detection and Response (EDR/XDR) and/or DFIR opensource tools (Ex. Kape, Plaso Log2Timeline, Autopsy, etc.) • 3 - 5+ Years Information Security related experience, in areas such as: security operations, incident analysis, incident handling, and vulnerability management or testing, system patching, log analysis, intrusion detection, or firewall administration. • 4 Year/Bachelor's degree or equivalent work experience

🏖️ Benefits

• A clearly defined career framework to help you successfully manage your career • Leadership development and virtual training opportunities • PTO/parental leave • Competitive 401K and employee benefits • Free financial counseling, health coaching and employee assistance program • Tuition assistance program • A leadership team that prioritizes your health and well-being; offering a remote work environment and flexible work hybrid situations • Effective productivity/technology tools and training

Apply Now

March 8

Join Axonius as a Security Operations Engineer to enhance our cybersecurity team’s operational maturity and address security threats.

March 7

Binary Defense is looking for a Cybersecurity Incident Response Analyst to manage client incidents and forensic analysis.

Discover 100,000+ Remote Jobs!

Join now to unlock all jobs

Discover hidden jobs

We scan the internet everyday and find jobs not posted on LinkedIn or other job boards.

Head start against the competition

We find jobs within 24 hours of being posted, so you can apply before everyone else.

Be the first to know

Daily emails with new job openings straight to your inbox.

Choose your membership

Cancel anytime

Loved by 10,000+ remote workers

Wall of Love

Frequently asked questions

We use powerful scraping tech to scan the internet for thousands of remote jobs daily. It operates 24/7 and costs us to operate, so we charge for access to keep the site running.

Of course! You can cancel your subscription at any time with no hidden fees or penalties. Once canceled, you’ll still have access until the end of your current billing period.

Other job boards only have jobs from companies that pay to post. This means that you miss out on jobs from companies that don't want to pay. On the other hand, Remote Rocketship scrapes the internet for jobs and doesn't accept payments from companies. This means we have thousands more jobs!

New jobs are constantly being posted. We check each company website every day to ensure we have the most up-to-date job listings.

Yes! We’re always looking to expand our listings and appreciate any suggestions from our community. Just send an email to Lior@remoterocketship.com. I read every request.

Remote Rocketship is a solo project by me, Lior Neu-ner. I built this website for my wife when she was looking for a job! She was having a hard time finding remote jobs, so I decided to build her a tool that would search the internet for her.

Why I created Remote Rocketship

Choose your membership

Cancel anytime

Loved by 10,000+ remote workers
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com