Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
GEICO

CSIRT Engineer

GEICO

Incident Response Engineer at GEICO combating cybersecurity threats and handling security events. Involving in incident response activities and complex investigations for threat mitigation.

Posted 6/14/2026full-timeBethesda • California, Maryland, Texas, Washington • 🇺🇸 United StatesMid-LevelSenior💰 $60,000 - $150,000 per yearWebsite

Tech Stack

Tools & technologies
AWSAzureCloudGoogle Cloud PlatformLinuxPerlPython

About the role

Key responsibilities & impact
  • Identify, detect, respond, and mitigate sophisticated threats to GEICO
  • Perform incident response functions including: Responding to cloud-based incidents in AWS, Azure, and GCP
  • Host-based analysis of Windows, Linux and Mac operating systems
  • Examine data collected from a variety of tools and sources (e.g., IDS alerts, firewall logs, web logs, network traffic logs) to identify IOCs and/or malicious TTPs
  • Review/Comprehend log data and apply use case scenarios in effort to further develop threat detection and incident response capabilities
  • Analyze events that occur within their environments for the purposes of mitigating threats

Requirements

What you’ll need
  • 4+ years of Incident Response experience
  • Knowledge of digital forensics and incident response best practices
  • Experience with responding to cloud-based incidents
  • Demonstrated experience performing root cause analysis of security events and incidents
  • Knowledgeable with security frameworks (E.g. – MITRE ATT&CK framework)
  • Ability to understand security control mechanisms for Windows, Linux, and Mac operating systems
  • Knowledge of computer networking concepts and protocols, and network security methodologies
  • Knowledge of common threat actor TTPs
  • Proficient in scripting languages such as Bash, Python, Perl, and PowerShell
  • Ability to apply strong critical thinking, logic, decision making, troubleshooting, and problem-solving skills
  • Strong written and oral communication skills
  • Ability to work independently and as a team member
  • Ability to handle advanced-level triage and troubleshooting
  • Ability to produce technical documentation, such as Visio flows and processes
  • Ability to understand complex problems while presenting them simplistically in a formal setting
  • Ability to learn and apply large amounts of technical and procedural information, and to follow published standards and processes
  • Ability to follow complex instructions, resolve conflicts or facilitate conflict resolution, and have strong organization/priority setting skills
  • Ability to analyze Windows systems for changes that occur during a specific timeframe
  • Ability to analyze network packet captures
  • Knowledge of cloud computing technologies and concepts (SaaS, PaaS, IaaS, etc.)
  • Knowledge in cyber defense systems and mechanisms. (e.g., NIPS, anti-malware, restrict/prevent external devices, spam filters)

Benefits

Comp & perks
  • Competitive pay
  • Benefits
  • Flexibility to support your well-being and future
  • Personalized development programs
  • Mentorship
  • Certification assistance

ATS Keywords

✓ Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
Incident ResponseDigital ForensicsRoot Cause AnalysisThreat DetectionScripting LanguagesBashPythonPerlPowerShellNetwork Packet Analysis
Soft Skills
Critical ThinkingProblem SolvingDecision MakingTroubleshootingWritten CommunicationOral CommunicationTeamworkIndependenceOrganizationConflict Resolution