
Cyber Security Engineer, SOC & Incident Response
Overview
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.
What You'll Do8
- 1Monitor and analyze security alerts from SIEM and EDR tools to identify potential threats.
- 2Lead incident response efforts, containing and eradicating intrusions within 90 days of onboarding.
- 3Develop and refine detection rules and use cases for Splunk and CrowdStrike.
- 4Collaborate with network and system teams to harden firewall and Active Directory configurations.
- 5Document incident timelines, root cause analyses, and remediation steps for compliance.
- 6Conduct threat hunting across endpoints and cloud workloads using MITRE ATT&CK framework.
- 7Automate repetitive security tasks with Python scripts to reduce response times.
- 8Participate in on-call rotation for after-hours security escalations.
Requirements7
- 13+ years in cybersecurity operations, focusing on incident response and threat detection.
- 2Hands-on experience with Splunk and CrowdStrike or similar EDR tools.
- 3Strong knowledge of TCP/IP, DNS, HTTP, and common attack vectors.
- 4Familiarity with AWS security services like GuardDuty and CloudTrail.
- 5Proficiency in Python or PowerShell for automation and log analysis.
- 6Relevant certifications such as CompTIA Security+, GCIA, or GCIH.
- 7Onsite availability in Phoenix, AZ and ability to work on a 6-month contract.
Salary Insight
$135 - $146k per year
Similar open positions
Explore active roles that match your skills and interests.
MANTECH
VerifiedCyber Security Analyst, Incident Response & SOC
You will own security event correlation and incident triage across enterprise networks, detecting and responding to threats in real time. You will work within a 24x7 SOC team, analyzing alerts from Windows and Linux systems and coordinating remediation. You hold IAT Level II certification (Security+ or equivalent) and thrive in high-stakes environments. This role offers direct exposure to COTS security tools and a clear path to advanced cyber roles.
Distro
VerifiedCybersecurity Specialist - AZ On Site
Lead a critical cybersecurity function within a dynamic global organization serving over 95,000 businesses. Protect systems and data through proactive threat monitoring and incident response. Ensure compliance and drive continuous improvement in security posture.
Phoenix Cyber
VerifiedCybersecurity Analyst Remote Phoenix Cyber
Lead ownership of network traffic analysis and IDS monitoring for a remote team at Phoenix Cyber. Analyze security events and logs to prioritize threats. Develop SOPs and provide actionable insights. Collaborate with cross-functional teams to improve security architecture. Stay current with emerging threats and mitigation strategies. This role offers unique exposure to diverse security challenges across multiple clients.
Robert Half
VerifiedSecurity Analyst, Cloud Security Operations
You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.

System One
VerifiedMid-Level Cybersecurity Incident Response Analyst
Own security alert investigation and response at scale. Deliver actionable insights within 90 days. Differentiate through proactive threat hunting and cross-functional collaboration.