See all roles

Incident Response Engineer II (HYBRID) 4 Locations

Work from home Full-time role Hiring

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers. GEICO’s Cybersecurity Incident Response Team is looking for a highly motivated, confident, decisive, experienced Incident Response Engineer. As a member of CSIRT, you will be the front-line responder combating cybersecurity threats against GEICO and their customers by handling security events. You will be challenged with rapidly changing incidents where attackers use the latest cutting-edge technology in their attempt to compromise GEICO. You will conduct incident response activities and be involved in complex investigations (cloud response, malware analysis, threat actor analysis and attribution, root cause analysis), response, and remediation. Responsibilities:

  • Identify, detect, respond, and mitigate sophisticated threats to GEICO
  • Perform incident response functions including:
  • Responding to cloud-based incidents in AWS, Azure, and GCP
  • Host-based analysis of Windows, Linux and Mac operating systems
  • Examine data collected from a variety of tools and sources (e.g., IDS alerts, firewall logs, web logs, network traffic logs) to identify IOCs and/or malicious TTPs
  • Review/Comprehend log data and apply use case scenarios in effort to further develop threat detection and incident response capabilities
  • Analyze events that occur within their environments for the purposes of mitigating threats

Required Qualifications:

  • 4+ years of Incident Response experience
  • Knowledge of digital forensics and incident response best practices
  • Experience with responding to cloud-based incidents
  • Demonstrated experience performing root cause analysis of security events and incidents
  • Knowledgeable with security frameworks (E.g. – MITRE ATT&CK framework)
  • Ability to understand security control mechanisms for Windows, Linux, and Mac operating systems
  • Knowledge of computer networking concepts and protocols, and network security methodologies
  • Knowledge of common threat actor TTPs
  • Proficient in scripting languages such as Bash, Python, Perl, and PowerShell
  • Ability to apply strong critical thinking, logic, decision making, troubleshooting, and problem-solving skills
  • Strong written and oral communication skills
  • Ability to work independently and as a team member
  • Ability to handle advanced-level triage and troubleshooting
  • Ability to produce technical documentation, such as Visio flows and processes
  • Ability to understand complex problems while presenting them simplistically in a formal setting
  • Ability to learn and apply large amounts of technical and procedural information, and to follow published standards and processes.
  • Ability to follow complex instructions, resolve conflicts or facilitate conflict resolution, and have strong organization/priority setting skills.
  • Ability to analyze Windows systems for changes that occur during a specific timeframe.
  • Ability to analyze network packet captures
  • Knowledge of cloud computing technologies and concepts (SaaS, PaaS, IaaS, etc.)
  • Knowledge in cyber defense systems and mechanisms. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)

Desired certifications (at least one):

  • GIAC Cloud Security Essentials Certification (GCLD)
  • GIAC Cloud Forensics Responder (GCFR)
  • GIAC Certified Web Application Defender (GWEB)
  • GIAC Cloud Security Automation (GCSA)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Reverse Engineering Malware (GREM)
  • GIAC Defending Advanced Threats (GDAT)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Certified Information Systems Security Professional (CISSP)
  • Other equivalent industry-related certification

Annual Salary $80,000.00 - $160,000.00 The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations. GEICO will consider sponsoring a new qualified applicant for employment authorization for this position. The GEICO Pledge: Great Company: At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs. We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives. Great Careers: We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career – and your potential – in mind. You’ll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels. Great Culture: We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose. As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers. Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future.

  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being.
  • Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance.
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled. GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants. Apply tot his job Apply To this Job

You might like

Senior Incident Response & Cybersecurity Analyst

Work from home Full-time role

Cyber Security Operations Manager

Work from home Full-time role

Risk/ Security Controls Assessment and Remediation Manager Remote / Telecommute Jobs

Work from home Full-time role

Sr. Threat Intelligence Analyst; Remote, West Coast

Work from home Full-time role

Data Architect (Remote from anywhere in CO)

Work from home Full-time role

Emerging Risk Data Analyst

Work from home Full-time role

Enterprise Data Engineering Lead

Work from home Full-time role

Remote Data Entry Associate - Flexible Hours for Teens at blithequark

Work from home Full-time role

New Online Data Entry Jobs For Teens No Experience Full Time US

Work from home Full-time role

[Remote] Ataccama ONE Enablement & Data Governance Support Lead /Specialist consultant

Work from home Full-time role

Work From Home for 15 Year Olds: Flexible Teen ...

Work from home Full-time role

Experienced Full Stack Data Entry Professional – Aviation Industry Remote Work Opportunities

Work from home Full-time role

Experienced Full Time Remote Customer Service Representative – Delivering Exceptional Experiences for arenaflex Customers

Work from home Full-time role

ERP Business Analyst Sr (Full Remote)

Work from home Full-time role

Key Account Manger, Kyushu Area

Work from home Full-time role

Experienced Customer Service Specialist – Delivering Exceptional Experiences for arenaflex Customers

Work from home Full-time role

Assistant Manager - Lingerie & At Home - Westchester

Work from home Full-time role

Staff Software Engineer – Event-Driven Architecture

Work from home Full-time role

Expert Footwear Product Manager, Women's Lifestyle

Work from home Full-time role

Experienced Remote Customer Service Coordinator – Air Travel and Freight Support Specialist at Blithequark

Work from home Full-time role