Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

03 Sep 2026
New Hampshire, Auckland 00000 Auckland USA

Senior Cybersecurity Engineer | Cyber Threat Intelligence & Response

About the roleOur Cyber Threat Intelligence & Response (CTIR) engineers are the people we count on when something goes wrong, and the people who make sure it goes wrong far less often. This is a hands-on incident response role. You'll lead the response to security events across our platforms and applications: triage, investigate, contain, eradicate and recover, then make sure we come out of it stronger.We're looking for someone who genuinely loves incident response. Someone who gets calmer and sharper when an incident kicks off, who is confident making decisions when the picture isn't complete, and who doesn't wait to be told what to look at. If you're a self-starter who takes ownership from the first alert to the final report, you'll fit right in.Location:  RemoteReports to:  VP of Cybersecurity | Cyber Threat Intelligence, Engineering & ResponseWhat you'll doOwn incidents as part of the CTIR team: detect, triage, investigate, contain and eradicate, driving each one until the threat is under control.Work live incidents alongside the team and be ready to step up and take the lead yourself when the situation calls for it.Lead investigations across our systems, digging into logs, endpoints, email and network data to work out what happened, how far it reached, and how to resolve.Perform host and network forensics, malware triage, and email analysis (including PDF and document analysis) to understand attacker activity and build a reliable timeline.Coordinate with engineering, IT and the wider security team during a response, and communicate clearly to both technical teams and leadership.Hunt proactively for threats across system logs, user behaviour and threat intelligence, turning what you find into new detections and indicators of compromise.Build and automate incident response workflows and playbooks so routine response is fast and repeatable.Strengthen our detection coverage using the MITRE ATT&CK framework, closing monitoring gaps, and tuning to reduce noise.Feed what you learn from each incident back into how the team detects and responds, so an attack pattern we've seen once is caught faster next time.Analyse threat intelligence, research emerging threats, and recommend practical mitigation.Be ready to work incidents as they arise, including on-call and out-of-hours cover when needed.

Related jobs

Job Details

Jocancy Online Job Portal by jobSearchi.