Tokio Marine HCC

The Tokio Marine HCC Group of Companies is an equal opportunity employer. Please visit www.tokiomarinehcc.com for more information about our companies.

DFIR Engineer

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000

Location

United States

Posted

13 days ago

Salary

Not specified

Power ShellBashPythonGoRustJenkinsGit Hub ActionsGit Lab CICircle CIDockerKubernetesTinesSplunkSwimlaneCortex XSOARREST APIDefenderSentinel OneCrowd StrikeSIEMIAMEDRIds/ipsVPNDLPVmwareHyper VAWSAzureMicrosoft 365Google Cloud PlatformLinuxWindowsDigital ForensicsMalware AnalysisThreat IntelligenceCISSPCISMGCFEGCFAGREMGBFAGCIHCFCECCE

Job Description

About Vector3 Vector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group (CPLG) . Vector3 specializes in responding to Business Email Compromise (BEC) and Ransomware incidents, helping insured organizations investigate, contain, and recover from cyber related incidents. Building on our success in incident response, we are launching a Managed Detection and Response (MDR) service designed to protect our DFIR clients from future incidents. The MDR program will deliver proactive monitoring, detection, and prevention solutions — powered by tools like Sophos EDR/NDR , Microsoft 365 , and Google Workspace .

Job Summary

Join us as a DFIR Engineer and take a role in shaping our digital forensics and incident response practice for TMHCC-CPLG insureds. In this position, you'll combine technical expertise to drive complex engineering initiatives that enhance the scale, speed, and precision of our investigations. You'll join a team of talented engineers through hands-on problem-solving, build scalable solutions for evolving threats, and help refine our consulting capabilities.

Key Responsibilities Intro

Relying on experience and knowledge, this role is responsible for accomplishing the following assignments. These assignments are varied in nature:

Leadership and Mentorship:
  • Assign tasks, delegate responsibilities, and provide mentorship to team members.
  • Support development and maintenance of operating procedures and best practices for engineering team.
  • Maintain positive, professional insured/carrier relationships.
  • Foster a culture of innovation, continuous learning, and skill development within the engineering team.

Client Management and Engagement:
  • Understand insured needs and tailor strategies to address specific business risks and compliance requirements.
  • Communicate complex engineering concepts internally and externally.

Incident Engineering Operations:
  • Develop and maintain engineering automation in support of incident response plans aligned with industry best practices.

Technical Experience:
  • Stay informed about emerging engineering technologies and industry best practices.
  • Understand and be aware of digital forensics methodologies for evidence collection, analysis, and reporting.
  • Provide expert technical guidance on engineering methodologies, automation techniques, software development and recovery techniques.
  • Occasionally, support complex digital forensic investigations, including analysis of system logs, network traffic, and endpoint data.

Competencies

Planning

• Follow work plans, established timelines, and predefined goals for assigned work.

• Meet commitments on deadlines.

Communication

• Communicate activities, results, and observations with employees and management as appropriate.

Cost Management

• Identify areas for improvement in existing business practices.

• Perform work thoroughly in a cost-efficient manner and at a high productivity level.

Business Controls and Policies

• Comply with all corporate policies and procedures.

• Report any breakdowns in controls to management.

• Conduct all activities in a safe manner.

People Management

• No people management responsibility

  • Education Requirements

Minimum 4 year / bachelor’s degree in cyber security, Computer Science, Information Technology related degree or relevant professional work experience

Certification, Licenses, and Designation s

2 years in leading active cybersecurity engagements, developing security automation and/or SOAR capabilities in support of security incident response, digital forensics, malware analysis or threat intelligence

Advanced degrees or certifications in security (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) or cloud engineering (AWS Certified Security, Azure Security Engineer, Google Professional Cloud Security Engineer, CCNA, MCSE) are a plus.

Other

  • Proven track record of success in managing complex engineering initiatives.
  • Experience in conducting security investigations in Linux and Windows environments.
  • Understanding of cloud platforms and security considerations within AWS (Amazon Web Services), Azure, Microsoft 365, and GCP (Google Cloud Platform).
  • Proficient scripting/programming skills: PowerShell, Bash, Python, Go, Rust
  • Proficiency and experience with CI/CD: Jenkins, GitHub Actions, GitLab CI, Circle CI
  • Proficiency and experience with containerization: Docker, Kubernetes
  • Experience working with middleware or SOAR platforms: Tines, Splunk, Swimlane Cortex XSOAR
  • Experience working with RESTful APIs for security automation.
  • Experience with EDR solutions (Defender, SentinelOne, CrowdStrike)
  • Experience with threat intelligence platforms or open-source solutions.
  • Experience with malware analysis methodologies.
  • Experience administering various enterprise grade security tools and databases: SIEM, IAM, EDR, firewalls, IDS/IPS, VPN, data warehouses, DLP
  • Experience with data backup and recovery, data replication, and data archival technologies.
  • Experience with hypervisor technologies: VMWare, MS Hyper-V
  • Strong understanding of legal and regulatory frameworks related to cyber security such as PCI, NIST CSF, or other industry-specific regulations.
  • Excellent communication and presentation skills to clearly and concisely communicate complex technical findings to clients and stakeholders.
  • Strong leadership abilities to motivate and mentor team members.
  • Superior organizational and analytical skills; demonstrated ability to manage multiple tasks simultaneously.
  • Knowledgeable of industry changes, legal updates, and technical developments related to applicable area of the Company’s business to proactively respond to changing business environment.
  • Advanced proficiency and experience using Microsoft Office package (Excel, Access, PowerPoint, Word).

Additional Working Conditions and Physical Conditions

  • Overtime hours may be required to fulfill job responsibilities
  • May be required to remain stationary for extended periods of time
  • May be required to move up to 10 pounds
  • Must be able to operate a computer and other devices
  • Close vision and ability to adjust focus, such as required to read a computer screen
  • Regular travel (up to 50% of time)

Related Categories

Related Job Pages

More Security Engineer Jobs

Information Processing Clerk

The Shella Foundation

The Shella Foundation is a nonprofit organization dedicated to enhancing the lives of seniors, children, veterans, and individuals with disabilities. Through strategic grants, community partnerships, and fundraising initiatives, we empower individuals to live independently in their homes. Our work also inspires families to advocate for accessible, high-quality care and supportive services, ensuring that those in need receive the respect and assistance they deserve.

Security Engineer13 days ago
Full TimeRemoteTeam 2-10

We are seeking a detail-oriented and reliable Remote Information Processing Clerk to join our team. In this role, you will be responsible for entering, updating, organizing, and maintaining information in company systems. This is a fully remote position that requires strong atten...

United States

Senior Manager of Offensive Security

Twilio

Build the future of communications.

Security Engineer13 days ago
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to r...

United States

Senior Application Development Engineer

Titan Technologies

Titan Technologies, LLC and our wholly owned subsidiaries, TelaForce, LLC, Titan Facilities, Inc. and Zen Strategics, design, build, integrate, and manage innovative solutions and software applications. Our remarkable people, working collaboratively under a shared vision, have earned a reputation with our customers for delivering results with maximum impact. Sound intriguing? Consider Titan Technologies for the next step in your career journey and be part of an impactful team! Titan is proud to be a Service-Disabled Veteran Owned Business.

Security Engineer13 days ago
Full TimeRemoteTeam 501-1,000

Zen Strategics, a Titan Technologies company, is seeking a Senior Application Development Engineer to support cybersecurity efforts for DHS USCIS systems. The Engineer will design and implement enterprise cybersecurity solutions, support threat modeling, automate security process...

United States
$150K - $165K / year

Principal Incident Response Engineer

Autodesk

How the world gets designed and made. #MakeAnything

Security Engineer13 days ago
Full TimeRemoteTeam 10,001+Since 1982H1B No Sponsor

Principal Incident Response Engineer conducting investigations and threat analysis for Autodesk

AWSAzureCloudGoogle Cloud PlatformSplunk
Oregon
$134K - $239.6K / year