SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Incident Response Engineer

Archer Technologies - San Jose, CA, United States - In-office - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 144,000 - 180,000 / annual

Archer Technologies, headquartered in Silicon Valley, is a leader in advanced air mobility building an end-to-end platform delivering air taxis, unmanned aircraft systems (UAS), and AI-driven aviation solutions for commercial aerospace and defense sectors. We are seeking a Senior Incident Response Engineer to lead Archer's detection and remediation efforts. You will serve as the primary technical liaison to our Managed Security Service Provider (MSSP), translating security alerts into actionable responses while ensuring compliance with NIST SP 800-171 and CMMC Level 2 requirements. Key Responsibilities: - Serve as Archer's primary internal SIEM engineer, working with internal resources and MSSP for alert triage, validation, escalation threshold definition, and security tool tuning. - Lead technical response to validated security incidents including identification, containment, eradication, and recovery; coordinate cross-functional response teams during breaches, malware outbreaks, and insider threats. - Conduct deep-dive forensic investigations including memory analysis, disk imaging, timeline reconstruction, and evidence preservation; produce detailed incident reports for HR, legal, and regulatory stakeholders. - Execute proactive threat hunts using SIEM data to identify lateral movement, persistence mechanisms, and indicators of compromise (IOCs). - Develop, refine, and validate custom detection rules mapped to the MITRE ATT&CK framework, considering Archer-specific threats and compliance-driven use cases. - Design and maintain incident response playbooks and SOAR workflows to automate evidence collection, containment actions, and notification procedures. - Design log collection requirements and facilitate external compliance audits to ensure adherence to NIST SP 800-171 Audit and Accountability (AU) requirements, CMMC Level 2, and SOX ITGC expectations. - Manage endpoint and system detection policies, deploy sensors, and perform live response actions to contain active threats and collect forensic artifacts. - Identify and operationalize cyber threat intelligence (CTI) feeds, IOCs, and threat actor TTPs into detection logic. - Own IR documentation architecture: author, organize, and maintain incident response procedures, playbooks, and runbooks for consistency and audit-readiness. - Own and evolve Archer's IR program strategy, metrics, and roadmap; report progress and risk posture to the CISO and executive leadership. - Provide technical guidance and facilitate tabletop exercises to IT, application, and leadership teams on incident reporting, response protocols, and post-incident lessons learned. Requirements: - 5+ years in Incident Response or Security Operations (SOC), with proven experience managing MSSP relationships, alert triage, and SLA performance. - Hands-on experience investigating security incidents from detection through containment and eradication, including malware analysis, phishing attacks, ransomware, and insider threats. - Deep understanding of OS internals (Windows/Mac/Linux), network protocols, and proficiency in scripting (Python, PowerShell, Bash) for automation. - Working knowledge of SIEM platforms (Google SecOps/Chronicle, Splunk, Microsoft Sentinel) and query languages (YARA-L/GoogleSQL, SPL, KQL). - Hands-on experience with SOAR platforms (Google SecOps/Chronicle, Palo Alto Cortex XSOAR, Splunk Phantom SOAR). - Knowledge of Cyber Threat Intelligence standards and User Behavior Analytics (UEBA). - Strong technical writing skills with demonstrated experience authoring security documentation including playbooks, runbooks, and incident response procedures. - Demonstrated experience designing, leading, and facilitating tabletop exercises, purple team engagements, or incident simulations. - Demonstrated experience conducting proactive threat hunts using SIEM and EDR telemetry. - Broad security utility across the stack with working familiarity with firewalls, network security, cloud security (AWS/Azure/GCP), and application security (AppSec). - Excellent technical and executive writing and communication skills, with ability to translate complex threat data for both technical teams and executive leadership during high-pressure situations. Preferred Qualifications: - Advanced malware analysis skills (static/dynamic) using IDA Pro, Ghidra, or Cuckoo Sandbox. - Familiarity administering email security platforms (Material Security, ProofPoint, Check Point Harmony) and conducting phishing campaigns. - Strong understanding of NIST SP 800-171 and CMMC Level 2 requirements, specifically as they relate to Incident Response and Audit/Accountability. - Familiarity with aerospace and startup environments.

Similar roles