6d ago
New

Lead/ Senior Security Engineer- Incident Response - CSIRT - Cloud Security

United StatesUnited States·Work From HomeRemotesenior
EngineeringSecurity Engineer
1 views0 saves0 applied

Quick Summary

Key Responsibilities

detection, triage, containment, eradication, recovery, and post-incident review. Build and maintain IR plans, playbooks, and runbooks for consistent, repeatable response.

Requirements Summary

//www.fico.com/en/privacy-policy

Technical Tools
EngineeringSecurity Engineer

As a Senior/Lead Incident Response Engineer at FICO, you will lead our defensive security operations with a strong focus on people, preparedness, and cross-team readiness. You will own how FICO detects, contains, and recovers from security incidents, and build the organizational readiness that makes that possible.  You will be responsible for designing and running tabletop exercises that bring stakeholders from across the business together and keep them engaged from planning through execution. If you love building trust across teams and shaping how FICO prepares for security incidents, this role is for you.

  • Design and facilitate incident response tabletop exercises across security, IT, engineering, legal, and business teams, testing preparedness and surfacing gaps.

  • Own the full incident lifecycle: detection, triage, containment, eradication, recovery, and post-incident review.

  • Build and maintain IR plans, playbooks, and runbooks for consistent, repeatable response.

  • Partner with threat intelligence, SOC, and engineering to turn IR and exercise findings into stronger detection and controls.

  • Communicate clearly with stakeholders at all levels, during incidents and in reporting.

  • Support digital forensics investigations, apply the PICERL and NIST frameworks, and lead IR activities in cloud environments using SIEM, CSPM, and other cloud security tooling.

  • Bring an IR perspective to FICO’s cloud and AI security programs and use AI and automation in IR and tabletop exercise workflows.

  • In-depth experience designing and facilitating IR tabletop exercises or similar simulations, including engaging cross-functional participants and turning results into real improvements.

  • Strong interpersonal skills: calm under pressure, a skilled facilitator, a trusted relationship-builder across teams, and an effective coach and mentor.

  • Experience in enterprise incident response across the full IR lifecycle.Good working knowledge of forensics tools (such as Magnet Axiom, Velociraptor, Volatility, FTK, Autopsy) and AWS cloud security fundamentals.

  • Good understanding of cloud security and AI security concepts.

  • Must have at least one of the following certifications, or similar: GCIH, GCFA, GCFE, AWS Certified Solutions Architect, or CISSP 

  • An inclusive culture strongly reflecting our core values:  Act Like an Owner, Delight Our Customers and Earn the Respect of Others.

  • The opportunity to make an impact and develop professionally by leveraging your unique strengths and participating in valuable learning experiences.

  • Highly competitive compensation, benefits and rewards programs that encourage you to bring your best every day and be recognized for doing so.

  • An engaging, people-first work environment offering work/life balance, employee resource groups, and social events to promote interaction and camaraderie.

  • The targeted base pay range for this role is: $136,500 to $214,500 with this range reflecting differences in candidate knowledge, skills and experience.
     

#LI-RR1

#LI-remote

 

At FICO, you can develop your career with a leading organization in one of the fastest-growing fields in technology today – Big Data analytics.  You’ll play a part in our commitment to help businesses use data to improve every choice they make, using advances in artificial intelligence, machine learning, optimization, and much more.


FICO makes a real difference in the way businesses operate worldwide:

•    Credit Scoring — FICO® Scores are used by 90 of the top 100 US lenders.

•    Fraud Detection and Security — 4 billion payment cards globally are protected by FICO fraud systems.

•    Lending — 3/4 of US mortgages are approved using the FICO Score.

Global trends toward digital transformation have created tremendous demand for FICO’s solutions, placing us among the world’s top 100 software companies by revenue. We help many of the world’s largest banks, insurers, retailers, telecommunications providers and other firms reach a new level of success. Our success is dependent on really talented people – just like you – who thrive on the collaboration and innovation that’s nurtured by a diverse and inclusive environment. We’ll provide the support you need, while ensuring you have the freedom to develop your skills and grow your career.  Join FICO and help change the way business thinks!

Learn more about how you can fulfil your potential at www.fico.com/Careers

FICO promotes a culture of inclusion and seeks to attract a diverse set of candidates for each job opportunity. We are an equal employment opportunity employer and we’re proud to offer employment and advancement opportunities to all candidates without regard to race, color, ancestry, religion, sex, national origin, pregnancy, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Research has shown that women and candidates from underrepresented communities may not apply for an opportunity if they don’t meet all stated qualifications. While our qualifications are clearly related to role success, each candidate’s profile is unique and strengths in certain skill and/or experience areas can be equally effective. If you believe you have many, but not necessarily all, of the stated qualifications we encourage you to apply.

Information submitted with your application is subject to the FICO Privacy policy at https://www.fico.com/en/privacy-policy

Location & Eligibility

Where is the job
Work From Home, United States
Remote within one country
Who can apply
Open to applicants worldwide

Listing Details

Posted
September 26, 2026
First seen
October 2, 2026
Last seen
October 2, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
37%
Scored at
October 2, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Lead/ Senior Security Engineer- Incident Response - CSIRT - Cloud Security