Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Agent
Ai Security
Cloud Platforms
Cyber Forensics
Data Security
Digital Incident Response
Forensics
Identity and Access Management
Incident Response
Information Security
InfoSec
Security Automation
Security Compliance
Security Engineer
Security Investigation
Security Investigations
Security Operations
Threat Hunting
Job Description
Intuit’s Digital Forensics and Incident Response (DFIR) team within the Security Operations Center (SOC) is hiring a Senior Security Engineer to drive investigations, detection improvements, and emerging AI/agentic risk response.
Responsibilities
- Oversee and promptly respond to escalated security events or investigations; activate the Security Incident Response Plan when required.
- Provide on-call support for critical severity issues, coordinate communications, and report incident status to the appropriate stakeholders.
- Lead forensic analysis to determine root cause, scope, and impact of security incidents.
- Investigate and respond to incidents involving AI/LLM-based tools and agentic platforms, including data leakage, insecure output handling, and unauthorized model access.
- Extend incident response playbooks to cover generative AI and AI SOC platform risks.
- Develop, maintain, and improve incident response plans, procedures, and playbooks to enable swift action and support regulatory compliance.
- Use AI SOC platforms and frontier AI tools to accelerate triage, detection tuning, investigation, and documentation, and evaluate new AI capabilities during onboarding.
- Provide guidance and training on security best practices and incident response to organizational partners, aligned with business objectives and compliance requirements.
- Mentor and train incident responders on incident handling, forensic analysis, and cloud security forensics best practices.
- Collaborate with Compliance, Legal, and Risk teams to integrate incident response operations with business and regulatory needs.
- Assess vulnerabilities, propose remediation strategies, and stay current on emerging security trends, threats, and countermeasures.
Requirements
- 3-5 years of experience in a dedicated cybersecurity role with strong emphasis on digital forensics and incident response.
- Bachelor’s degree or higher in Technology, Computer Science, Cybersecurity, or related field, or equivalent hands-on experience (preferred).
- 1-3 years writing scripts or code in Bash, PowerShell, or Python to automate security work.
- Comfort using AI coding assistants and AI SOC platforms to build faster, with awareness of risks introduced by AI-generated code.
- Working knowledge of AI/LLM security risks and mitigations, including data exfiltration, insecure output handling, model and data supply chain risk, and shadow AI usage.
- Familiarity with frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
- Experience performing analysis and detection engineering using Endpoint Detection and Response or Cloud Security Posture Management tools such as CrowdStrike Falcon and Wiz.
- Proven threat hunting experience using hypothesis-driven hunts across endpoint, cloud, and network telemetry to uncover threats that evade existing detections.
- Comprehensive understanding of cybersecurity, networking, and cloud fundamentals, including frameworks such as OWASP, MITRE ATT&CK, NIST, and CIS.
- Experience using and defending public cloud services: AWS, Azure, and GCP (IAM, CI/CD Pipelines, Network Security, DLP).
- Deep understanding of SIEM solutions such as Splunk and LogScale.
- Strong analytical and problem-solving skills focused on root cause identification and assessing risk exposure.
- Exceptional communication skills (verbal and written) to explain technical details to non-technical audiences and support stakeholder relationships.
- Self-motivated and able to work autonomously, managing tasks effectively and seeking assistance when necessary.
- Ability to work under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.
- Proficiency in digital forensics technologies and methodologies, and expertise in the Security Incident Response Lifecycle based on frameworks like NIST or SANS.
- Adaptable and proactive approach with willingness to take on varied responsibilities and continuously learn.
- Industry-recognized certifications (advantageous), such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials.
Technologies
- Bash
- PowerShell
- Python
- AWS Security Specialty
- GCIH
- GCFA
- GFCE
- CISSP
- AWS
- Azure
- GCP
- IAM
- CI/CD Pipelines
- Network Security
- DLP
- CrowdStrike Falcon
- Wiz
- Splunk
- LogScale
- Security Information and Event Management (SIEM)
- Endpoint Detection and Response
- Cloud Security Posture Management
- OWASP Top 10 for LLM Applications
- MITRE ATLAS
- NIST AI RMF
- OWASP
- MITRE ATT&CK
- NIST
- CIS
- SANS
- AI coding assistants
- AI SOC platforms
- frontier AI tools
Location
- Frisco, TX (onsite)
Compensation and Benefits
- May be eligible for a cash bonus, equity rewards, and benefits in accordance with applicable plans and programs.