
Cybersecurity Incident Response Engineer, Sr
ASM Research, An Accenture Federal Services Company, montgomery, al, United States
**Position Overview**
The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts for enterprise networks and mission‑critical systems, owning the technical direction and coordination of high‑impact events in a highly regulated environment. This role applies ITIL‑aligned incident management principles to structure major incident handling while maintaining deep technical focus on threat containment and eradication. It also drives proactive cybersecurity initiatives, including automation, custom scripting, and advanced defensive engineering, to strengthen the organization's ability to prevent, detect, and rapidly respond to sophisticated adversarial tactics.
The Senior Engineer develops and deploys scalable countermeasures, enhances SOC tooling and integrations, and implements advanced detection and response programs to defend against complex attacks. This role also mentors junior responders, shapes incident response governance, and influences broader security architecture and operations based on emerging threats and incident trends.
**Key Responsibilities**
+ Lead major incident bridges and war rooms, orchestrating technical teams, tracking actions, and making time‑critical decisions to restore service and mitigate business risk.
+ Integrate ITIL incident and major incident management practices with technical response workflows, ensuring disciplined prioritization, communication, and closure.
+ Design and optimize incident detection and response processes, including playbooks, escalation paths, and automation, to improve consistency, speed, and quality of response.
+ Build automation, orchestration, and custom scripting solutions to reduce manual workload, enhance triage and response, and streamline containment and eradication actions.
+ Perform advanced threat and forensic analysis of endpoint, network, identity, and cloud data to understand attacker objectives, lateral movement, and persistence mechanisms.
+ Partner with problem management and change management functions to translate incident findings into long‑term corrective actions, configuration changes, and risk‑reducing initiatives.
+ Define and track incident metrics such as MTTR, MTTD, incident volume, and recurrence, using data to identify systemic weaknesses and to brief leadership on operational risk.
+ Provide technical and procedural coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation quality, and stakeholder communication.
**Required Qualifications**
+ 8+ years of progressive IT and cybersecurity experience with significant responsibility for incident response and major incident leadership.
+ Bachelor's degree in IT, **Cybersecurity** , Computer Science, Business Administration, or a related field, or equivalent work experience.
+ Strong understanding of ITIL principles and incident management best practices, including experience with major incident processes.
+ Proficiency with incident management and service management tools integrated with security operations.
+ Excellent problem‑solving, analytical, communication, and interpersonal skills with demonstrated ability to manage multiple simultaneous incidents.
**Preferred Qualifications**
+ Demonstrated leadership of ITIL‑based major incident processes in large enterprises, including executive and customer‑facing communications.
+ Strong experience with enterprise incident management tools and service management platforms integrated with SOC and cyber defense functions.
+ Certifications such as ITIL Foundation plus advanced cybersecurity or incident response credentials evidencing both service management and deep technical capability.
+ At least one cybersecurity‑related professional certification - or the ability to obtain one within one year of hire - such as Security+, CySA+, GSEC, CEH, GCIA, GCIH, CISM or another industry‑recognized equivalent.
**Compensation Ranges**
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
**EEO Requirements**
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
**Disclaimer**
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$80,200 - 111,300
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.
The Cybersecurity Incident Response Engineer, Senior leads complex incident response efforts for enterprise networks and mission‑critical systems, owning the technical direction and coordination of high‑impact events in a highly regulated environment. This role applies ITIL‑aligned incident management principles to structure major incident handling while maintaining deep technical focus on threat containment and eradication. It also drives proactive cybersecurity initiatives, including automation, custom scripting, and advanced defensive engineering, to strengthen the organization's ability to prevent, detect, and rapidly respond to sophisticated adversarial tactics.
The Senior Engineer develops and deploys scalable countermeasures, enhances SOC tooling and integrations, and implements advanced detection and response programs to defend against complex attacks. This role also mentors junior responders, shapes incident response governance, and influences broader security architecture and operations based on emerging threats and incident trends.
**Key Responsibilities**
+ Lead major incident bridges and war rooms, orchestrating technical teams, tracking actions, and making time‑critical decisions to restore service and mitigate business risk.
+ Integrate ITIL incident and major incident management practices with technical response workflows, ensuring disciplined prioritization, communication, and closure.
+ Design and optimize incident detection and response processes, including playbooks, escalation paths, and automation, to improve consistency, speed, and quality of response.
+ Build automation, orchestration, and custom scripting solutions to reduce manual workload, enhance triage and response, and streamline containment and eradication actions.
+ Perform advanced threat and forensic analysis of endpoint, network, identity, and cloud data to understand attacker objectives, lateral movement, and persistence mechanisms.
+ Partner with problem management and change management functions to translate incident findings into long‑term corrective actions, configuration changes, and risk‑reducing initiatives.
+ Define and track incident metrics such as MTTR, MTTD, incident volume, and recurrence, using data to identify systemic weaknesses and to brief leadership on operational risk.
+ Provide technical and procedural coaching to incident handlers and SOC analysts, elevating investigative techniques, documentation quality, and stakeholder communication.
**Required Qualifications**
+ 8+ years of progressive IT and cybersecurity experience with significant responsibility for incident response and major incident leadership.
+ Bachelor's degree in IT, **Cybersecurity** , Computer Science, Business Administration, or a related field, or equivalent work experience.
+ Strong understanding of ITIL principles and incident management best practices, including experience with major incident processes.
+ Proficiency with incident management and service management tools integrated with security operations.
+ Excellent problem‑solving, analytical, communication, and interpersonal skills with demonstrated ability to manage multiple simultaneous incidents.
**Preferred Qualifications**
+ Demonstrated leadership of ITIL‑based major incident processes in large enterprises, including executive and customer‑facing communications.
+ Strong experience with enterprise incident management tools and service management platforms integrated with SOC and cyber defense functions.
+ Certifications such as ITIL Foundation plus advanced cybersecurity or incident response credentials evidencing both service management and deep technical capability.
+ At least one cybersecurity‑related professional certification - or the ability to obtain one within one year of hire - such as Security+, CySA+, GSEC, CEH, GCIA, GCIH, CISM or another industry‑recognized equivalent.
**Compensation Ranges**
Compensation ranges for ASM Research positions vary depending on multiple factors; including but not limited to, location, skill set, level of education, certifications, client requirements, contract-specific affordability, government clearance and investigation level, and years of experience. The compensation displayed for this role is a general guideline based on these factors and is unique to each role. Monetary compensation is one component of ASM's overall compensation and benefits package for employees.
**EEO Requirements**
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, disability, or age. All decisions on employment are made to abide by the principle of equal employment.
Physical Requirements
The physical requirements described in "Knowledge, Skills and Abilities" above are representative of those which must be met by an employee to successfully perform the primary functions of this job. (For example, "light office duties' or "lifting up to 50 pounds" or "some travel" required.) Reasonable accommodations may be made to enable individuals with qualifying disabilities, who are otherwise qualified, to perform the primary functions.
**Disclaimer**
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees assigned to this job.
$80,200 - 111,300
EEO Requirements
It is the policy of ASM that an individual's race, color, religion, sex, disability, age, gender identity, veteran status, sexual orientation or national origin are not and will not be considered in any personnel or management decisions. We affirm our commitment to these fundamental policies.
All recruiting, hiring, training, and promoting for all job classifications is done without regard to race, color, religion, sex, veteran status, disability, gender identity, or age. All decisions on employment are made to abide by the principle of equal employment.