Alcor Solutions is seeking an experienced Incident Response Engineer to join our Security Operations and Incident Response team. The role will be responsible for detecting, investigating, containing, and responding to cybersecurity incidents across enterprise environments. The ideal candidate has hands-on experience investigating security incidents involving endpoints, networks, identity systems, cloud environments, email, and enterprise applications and is comfortable working in high-pressure situations involving potentially significant business impact.
Key Responsibilities: Investigate and respond to security incidents involving malware, ransomware, phishing, credential compromise, data exfiltration, cloud threats, vulnerability exploitation, privilege escalation, and lateral movement. Analyze security alerts and telemetry from SIEM, EDR/XDR, identity, network, cloud, and email security platforms. Conduct threat hunting, root-cause analysis, and digital forensic investigations. Develop and improve security detections, incident response playbooks, and investigation procedures. Support containment, eradication, recovery, and post-incident activities. Automate security investigation and response processes using PowerShell, Python, APIs, SOAR, or similar technologies. Collaborate with SOC, Infrastructure, Cloud, Identity, Application, Vulnerability Management, and IT Operations teams during security incidents. Document investigations and provide clear technical updates to security teams and leadership. Apply frameworks such as MITRE ATT&CK and NIST Incident Response to investigations and response activities. Required Qualifications3–7+ years of cybersecurity experience, with hands-on experience in incident response, security operations, threat hunting, digital forensics, or security engineering. Strong understanding of Windows/Linux, networking, Active Directory, identity security, and common attack techniques. Hands-on experience with SIEM and EDR/XDR platforms. Strong analytical, troubleshooting, communication, and documentation skills. Ability to work effectively under pressure during high-severity security incidents.
Preferred:
  • Experience with Microsoft Sentinel, Defender XDR/Endpoint, Entra ID, Microsoft 365, CrowdStrike, Splunk, or Service
  • Now Security Operations.
  • Experience with Azure, AWS, or GCP security investigations.
  • Experience with PowerShell, Python, REST APIs, SOAR, or security automation.
  • Relevant certifications such as GCIH, GCFA, GCFE, CISSP, CySA+, Security+, CEH, or Microsoft Security certifications.

Also on the board Same function, level within a rung

Level

Senior

Location

Raleigh, NC

Occupation

Information Security Engineers

Industry

Computer Systems Design Services

Posted

yesterday

Apply for this role →