Acrisure Logo

Acrisure

Senior Security Incident Response Engineer

Reposted 13 Hours Ago
Be an Early Applicant
In-Office
3 Locations
Senior level
In-Office
3 Locations
Senior level
Lead advanced security incident response efforts focusing on Microsoft E5 security capabilities, handling incident detection, analysis, and remediation while promoting proactive security measures across the enterprise.
The summary above was generated by AI

About Acrisure

A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more.

In the last eleven years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win.

Job Summary:

The Senior Incident Response Engineer will lead advanced security incident response efforts, focusing on Microsoft E5 security capabilities and Data Loss Prevention (DLP). This role combines technical expertise with leadership responsibilities, ensuring robust detection, containment, and remediation of threats while driving proactive security measures across the enterprise.

Responsibilities:

Incident Response:

  • Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers.
  • Lead post-incident reviews and drive process improvements.
  • Perform advanced threat hunting using Microsoft Defender and related tools.
  • Integrate threat intelligence and adapt detection strategies based on real world threats observed by the organization.
  • Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents.
  • Develop and maintain incident response playbooks and runbooks across the security operations toolset.
  • Collaborate with analysts and other IR engineers to identify opportunities for improvement and tuning of detection rules.
  • Collaborate with IT, legal, HR, communications, and other business units

Microsoft Security & Policy Design:

  • Collaborate on the design, implementation, and maintenance of security policies for Microsoft security components, including:
    • Defender for Endpoint
    • Defender for Cloud Apps
    • Microsoft Purview DLP
    • Intune
    • Conditional Access & Information Protection
  • Regularly review and update policies based on evolving threats and lessons learned.
  • Collaborate with compliance and IT teams to enforce security standards and regulatory requirements.

Requirements:

  • Proficiency with Microsoft 365 Security Suite as well as other security tooling such as SentinelOne, Google SecOps, Abnormal Security, and others.
  • Strong experience with incident response, digital forensics, and threat hunting across a hybrid environment.
  • Knowledge of endpoint operating systems (Windows, macOS, and Linux).
  • Experience with cloud environments such as Azure, AWS, and GCP.
  • Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing desired.
  • Embrace a metric-driven approach to continuous improvement.
  • Excellent analytical and critical thinking skills; ability to work in high-pressure situations.
  • Effective verbal and written communication abilities.
  • Meticulous with strong organizational skills and the ability to handle multiple priorities.
  • Ability to work independently and within a collaborative, team-oriented environment.

Education and Experience:

  • Minimum 5 years of progressive information security experience.
  • At least 4 years focused on incident response, including investigations across different security domains (endpoint, application, DLP, and more).
  • Expertise in Infrastructure Security: In-depth understanding of infrastructure security, including Windows, Active Directory, Unix/Linux, Mobile Security, and Privileged Access Management. 
  • Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, MS SC-200, MS SC-400 or similar.

#LI-CH1

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.


Why Join Us:

At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.

Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.


Employee Benefits

We also offer our employees a comprehensive suite of benefits and perks, including:

  • Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.

  • Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.

  • Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.

  • Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.

  • … and so much more!

This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.


Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting [email protected].


California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.


Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.


Welcome, your new opportunity awaits you.

Top Skills

AWS
Azure
Bash
GCP
Google Secops
Microsoft 365 Security Suite
Powershell
Python
Sentinelone

Similar Jobs

18 Hours Ago
Remote or Hybrid
8 Locations
100K-165K Annually
Senior level
100K-165K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Senior Platform Consultant will plan, deploy, and provide operational support for CrowdStrike Falcon Cloud Security, engaging with customers and integrating security solutions while mentoring team members.
Top Skills: AWSAzureBashCi/CdCloud SecurityCloudFormationDockerGCPKubernetesLinuxmacOSPowershellPythonTerraformWindows
18 Hours Ago
Remote or Hybrid
2 Locations
125K-180K Annually
Expert/Leader
125K-180K Annually
Expert/Leader
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design and build scalable data integration frameworks and pipelines, ensuring data accuracy and collaborating with stakeholders to improve data management.
Top Skills: AirflowDbtGitGitlab Ci/CdJenkinsPythonRedshiftSnowflakeSQL
18 Hours Ago
Remote or Hybrid
2 Locations
95K-140K Annually
Junior
95K-140K Annually
Junior
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
This role involves supporting customers in operationalizing the Falcon platform for security, conducting onboarding meetings, and ensuring customer satisfaction and project success through effective communication and expertise in endpoint security.
Top Skills: Active DirectoryAWSAzureCitrixDockerFalcon PlatformGCPKubernetesMS OfficeSccm

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account