EngineerJobs.io
← Back to all jobs

Job Description

Intuit’s Digital Forensics and Incident Response (DFIR) team within the Security Operations Center (SOC) is hiring a Senior Security Engineer to drive investigations, detection improvements, and emerging AI/agentic risk response.

Responsibilities

  • Oversee and promptly respond to escalated security events or investigations; activate the Security Incident Response Plan when required.
  • Provide on-call support for critical severity issues, coordinate communications, and report incident status to the appropriate stakeholders.
  • Lead forensic analysis to determine root cause, scope, and impact of security incidents.
  • Investigate and respond to incidents involving AI/LLM-based tools and agentic platforms, including data leakage, insecure output handling, and unauthorized model access.
  • Extend incident response playbooks to cover generative AI and AI SOC platform risks.
  • Develop, maintain, and improve incident response plans, procedures, and playbooks to enable swift action and support regulatory compliance.
  • Use AI SOC platforms and frontier AI tools to accelerate triage, detection tuning, investigation, and documentation, and evaluate new AI capabilities during onboarding.
  • Provide guidance and training on security best practices and incident response to organizational partners, aligned with business objectives and compliance requirements.
  • Mentor and train incident responders on incident handling, forensic analysis, and cloud security forensics best practices.
  • Collaborate with Compliance, Legal, and Risk teams to integrate incident response operations with business and regulatory needs.
  • Assess vulnerabilities, propose remediation strategies, and stay current on emerging security trends, threats, and countermeasures.

Requirements

  • 3-5 years of experience in a dedicated cybersecurity role with strong emphasis on digital forensics and incident response.
  • Bachelor’s degree or higher in Technology, Computer Science, Cybersecurity, or related field, or equivalent hands-on experience (preferred).
  • 1-3 years writing scripts or code in Bash, PowerShell, or Python to automate security work.
  • Comfort using AI coding assistants and AI SOC platforms to build faster, with awareness of risks introduced by AI-generated code.
  • Working knowledge of AI/LLM security risks and mitigations, including data exfiltration, insecure output handling, model and data supply chain risk, and shadow AI usage.
  • Familiarity with frameworks such as OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
  • Experience performing analysis and detection engineering using Endpoint Detection and Response or Cloud Security Posture Management tools such as CrowdStrike Falcon and Wiz.
  • Proven threat hunting experience using hypothesis-driven hunts across endpoint, cloud, and network telemetry to uncover threats that evade existing detections.
  • Comprehensive understanding of cybersecurity, networking, and cloud fundamentals, including frameworks such as OWASP, MITRE ATT&CK, NIST, and CIS.
  • Experience using and defending public cloud services: AWS, Azure, and GCP (IAM, CI/CD Pipelines, Network Security, DLP).
  • Deep understanding of SIEM solutions such as Splunk and LogScale.
  • Strong analytical and problem-solving skills focused on root cause identification and assessing risk exposure.
  • Exceptional communication skills (verbal and written) to explain technical details to non-technical audiences and support stakeholder relationships.
  • Self-motivated and able to work autonomously, managing tasks effectively and seeking assistance when necessary.
  • Ability to work under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.
  • Proficiency in digital forensics technologies and methodologies, and expertise in the Security Incident Response Lifecycle based on frameworks like NIST or SANS.
  • Adaptable and proactive approach with willingness to take on varied responsibilities and continuously learn.
  • Industry-recognized certifications (advantageous), such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials.

Technologies

  • Bash
  • PowerShell
  • Python
  • AWS Security Specialty
  • GCIH
  • GCFA
  • GFCE
  • CISSP
  • AWS
  • Azure
  • GCP
  • IAM
  • CI/CD Pipelines
  • Network Security
  • DLP
  • CrowdStrike Falcon
  • Wiz
  • Splunk
  • LogScale
  • Security Information and Event Management (SIEM)
  • Endpoint Detection and Response
  • Cloud Security Posture Management
  • OWASP Top 10 for LLM Applications
  • MITRE ATLAS
  • NIST AI RMF
  • OWASP
  • MITRE ATT&CK
  • NIST
  • CIS
  • SANS
  • AI coding assistants
  • AI SOC platforms
  • frontier AI tools

Location

  • Frisco, TX (onsite)

Compensation and Benefits

  • May be eligible for a cash bonus, equity rewards, and benefits in accordance with applicable plans and programs.

Similar Jobs