Incident Response Engineer
alcor solutionsRaleigh (NC)
About the role
Alcor Solutions is seeking an experienced Incident Response Engineer to join our Security Operations and Incident Response team. The role will be responsible for detecting, investigating, containing, and responding to cybersecurity incidents across enterprise environments. The ideal candidate has hands-on experience investigating security incidents involving endpoints, networks, identity systems, cloud environments, email, and enterprise applications and is comfortable working in high-pressure situations involving potentially significant business impact.
Key Responsibilities:
Investigate and respond to security incidents involving malware, ransomware, phishing, credential compromise, data exfiltration, cloud threats, vulnerability exploitation, privilege escalation, and lateral movement.
Analyze security alerts and telemetry from SIEM, EDR/XDR, identity, network, cloud, and email security platforms.
Conduct threat hunting, root-cause analysis, and digital forensic investigations.
Develop and improve security detections, incident response playbooks, and investigation procedures.
Support containment, eradication, recovery, and post-incident activities.
Automate security investigation and response processes using PowerShell, Python, APIs, SOAR, or similar technologies.
Collaborate with SOC, Infrastructure, Cloud, Identity, Application, Vulnerability Management, and IT Operations teams during security incidents.
Document investigations and provide clear technical updates to security teams and leadership.
Apply frameworks such as MITRE ATT&CK and NIST Incident Response to investigations and response activities.
Required Qualifications3–7+ years of cybersecurity experience, with hands-on experience in incident response, security operations, threat hunting, digital forensics, or security engineering.
Strong understanding of Windows/Linux, networking, Active Directory, identity security, and common attack techniques.
Hands-on experience with SIEM and EDR/XDR platforms.
Strong analytical, troubleshooting, communication, and documentation skills.
Ability to work effectively under pressure during high-severity security incidents.
Preferred:
- Experience with Microsoft Sentinel, Defender XDR/Endpoint, Entra ID, Microsoft 365, CrowdStrike, Splunk, or Service
- Now Security Operations.
- Experience with Azure, AWS, or GCP security investigations.
- Experience with PowerShell, Python, REST APIs, SOAR, or security automation.
- Relevant certifications such as GCIH, GCFA, GCFE, CISSP, CySA+, Security+, CEH, or Microsoft Security certifications.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
