Fragomen Logo

Fragomen

Cybersecurity Engineer - Incident Response & Threat Detection

Posted 5 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in Corporal, CA, USA
Junior
Remote
Hiring Remotely in Corporal, CA, USA
Junior
As a Cybersecurity Engineer, lead incident response activities, conduct digital forensics, monitor security alerts, and improve detection capabilities while collaborating with various teams.
The summary above was generated by AI

Job Description

Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team.

Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and security is critical to its success. We are seeking a professional who is passionate about protecting the organization, capable of leading response efforts during security incidents, and eager to mature enterprise-wide incident detection, investigation, and response capabilities.

You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in detecting, investigating, containing, and remediating cyber incidents, while helping to strengthen Fragomen’s overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Incident Response, you will:

  • Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
  • Monitor, investigate, and correlate security alerts using SIEM, EDR, and forensic tools.
  • Perform digital forensic investigations across endpoints, servers, cloud, and network environments.
  • Triage and escalate security events in accordance with established incident response procedures.
  • Develop, maintain, and continuously improve incident response playbooks, SOPs, and workflows.
  • Improve alert quality and response effectiveness through root cause analysis and post-incident reviews.
  • Partner with IT, Legal, Compliance, Privacy, and Risk teams during security incidents.
  • Support regulatory, legal, and client-driven incident response and reporting requirements.
  • Participate in and facilitate incident response tabletop exercises and simulations.
  • Contribute to the design and enhancement of detection, logging, and monitoring capabilities.
  • Provide technical guidance and mentorship to junior analysts and security team members.

Required Qualifications

  • 1+ years of experience in cybersecurity, incident response, or security operations.
  • Hands-on experience responding to security incidents in enterprise environments.
  • Strong ability to analyze security events and perform technical investigations.
  • Working knowledge of:
    • TCP/IP, DNS, HTTP/S, VPNs, firewalls, and proxy technologies
    • Windows and Linux operating systems
    • Identity and access systems and authentication mechanisms
  • Experience using SIEM and security platforms such as:
    • Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar
  • Ability to identify and respond to:
    • Phishing and business email compromise
    • Malware and ransomware
    • Credential compromise
    • Lateral movement and persistence mechanisms
    • Brute-force and privilege escalation attacks
  • Strong written and verbal communication skills, especially during high-pressure incidents.
  • Demonstrated ability to follow structured processes while continuously improving them.
     

Preferred Qualifications

  • Experience with EDR, SOAR, and forensic tooling (e.g., CrowdStrike, Defender, Carbon Black, EnCase, Velociraptor, etc.).
  • Experience supporting investigations involving legal, compliance, or regulatory stakeholders.
  • Knowledge of MITRE ATT&CK and modern adversary tactics.
  • Experience with cloud and SaaS incident response (Azure, M365, AWS, etc.).
  • Relevant certifications, including:
    • GIAC (GCIH, GCFA, GCIA)
    • Offensive Security (OSCP, OSCE, OSEE)
  • Vendor certifications (Splunk, Sentinel, CrowdStrike, etc.)

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations.

Top Skills

Arcsight
AWS
Azure
Carbon Black
Crowdstrike
Defender
Dns
Edr
Elk
Encase
Firewalls
Forensic Tools
Http/S
Linux
M365
Microsoft Sentinel
Proxy Technologies
Qradar
SIEM
Splunk
Tcp/Ip
Velociraptor
Vpns
Windows

Similar Jobs

58 Minutes Ago
Remote or Hybrid
United States
166K-210K Annually
Senior level
166K-210K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
The Director of Marketing AI Transformation will lead AI initiatives in Marketing, focusing on strategy, enablement, governance, and optimization to drive impact and efficiency.
Top Skills: AIAnalytics ToolsContent Generation ToolsCRMMapsMarketing Operations
An Hour Ago
Easy Apply
Remote
USA
Easy Apply
207K-244K Annually
Senior level
207K-244K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
The Senior Product Manager will lead Trading Growth strategy for the Base App, focusing on user acquisition, engagement, and retention through various optimization strategies and cross-functional collaboration.
Top Skills: Data-Driven DevelopmentFintechGrowth StrategiesMachine Learning ToolsOnchain ProtocolsTrading Systems
An Hour Ago
Easy Apply
Remote
USA
Easy Apply
180K-212K Annually
Senior level
180K-212K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
The Senior Data Scientist will analyze business challenges, conduct experiments, develop metrics, and collaborate with teams to drive data-driven decisions and user growth.
Top Skills: PythonSQL

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account