SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Incident Responder

DocuSign - North Sydney, NSW, Australia - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

DocuSign is seeking a Senior Incident Responder to join its CSIRT (Computer Security Incident Response Team) in North Sydney. This is an individual contributor role reporting to the CSIRT Senior Manager, focused on the "Detect & Respond" function within the security operations center. Key responsibilities include leveraging AI and machine learning tools to enhance log analysis, alert triage, and threat hunting. You will monitor for and investigate security incidents involving AI/ML models, including adversarial attacks, prompt injection, and model evasion. The role requires performing initial triage and in-depth analysis of security alerts from SIEM and other monitoring tools, correlating events across log sources to identify potential incidents, and determining scope, severity, and impact of detected threats. You will conduct technical investigations into cybersecurity incidents including malware analysis, phishing attacks, web application compromises, and insider threats. Digital forensics techniques will be used to gather evidence and understand incident timelines. You'll support incident containment, eradication, and recovery efforts, document findings and lessons learned, and participate in proactive threat hunting to uncover hidden threats. The role involves optimizing SIEM and SOAR platforms for alert processing and incident workflows, identifying automation opportunities, and collaborating with other security teams, IT, and business units. You'll provide clear updates on incident status and post-incident analysis to leadership. Required qualifications include 8+ years of hands-on cybersecurity experience with focus on SOC and/or incident response, solid understanding of incident response lifecycles and security best practices, and experience with SIEM tools (Splunk, QRadar, Sentinel). You need strong familiarity with EDR solutions, digital forensics principles, scripting languages (Python, PowerShell, Bash), and the MITRE ATT&CK framework. Understanding of AI-driven security threats and ability to leverage AI/ML tools for incident response is essential. Preferred qualifications include a Bachelor's or Master's degree in Computer Science or Information Security, advanced certifications (GCFA, GCED, GCIH, GCIA, CISSP, CISM), experience designing enterprise IR/DFIR programs, SOAR platform expertise, cloud security background, and experience with AI security frameworks like MITRE ATLAS or OWASP Top 10 for LLMs. The position is hybrid with a minimum 2 days per week in-office requirement in North Sydney.

Similar roles