Cybersecurity Engineer - Incident Response & Threat Detection

Sorry, this job was removed at 06:07 p.m. (CST) on Thursday, Apr 02, 2026
Hiring Remotely in Corporal, CA, USA
Remote
Legal Tech
The Role

Job Description

Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is seeking a Cyber Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team.

Our industry-leading, immigration-specific technology and infrastructure is undergoing significant transformation, and security is critical to its success. We are seeking a professional who is passionate about protecting the organization, capable of leading response efforts during security incidents, and eager to mature enterprise-wide incident detection, investigation, and response capabilities.

You will join a team of security engineers who make security a differentiator in our technology offerings. The successful candidate will play a key role in detecting, investigating, containing, and remediating cyber incidents, while helping to strengthen Fragomen’s overall security posture.

How Will You Make a Difference at Fragomen?

As a Security Engineer focused on Incident Response, you will:

  • Lead and support end-to-end incident response activities, including detection, analysis, containment, eradication, and recovery.
  • Monitor, investigate, and correlate security alerts using SIEM, EDR, and forensic tools.
  • Perform digital forensic investigations across endpoints, servers, cloud, and network environments.
  • Triage and escalate security events in accordance with established incident response procedures.
  • Develop, maintain, and continuously improve incident response playbooks, SOPs, and workflows.
  • Improve alert quality and response effectiveness through root cause analysis and post-incident reviews.
  • Partner with IT, Legal, Compliance, Privacy, and Risk teams during security incidents.
  • Support regulatory, legal, and client-driven incident response and reporting requirements.
  • Participate in and facilitate incident response tabletop exercises and simulations.
  • Contribute to the design and enhancement of detection, logging, and monitoring capabilities.
  • Provide technical guidance and mentorship to junior analysts and security team members.

Required Qualifications

  • 1+ years of experience in cybersecurity, incident response, or security operations.
  • Hands-on experience responding to security incidents in enterprise environments.
  • Strong ability to analyze security events and perform technical investigations.
  • Working knowledge of:
    • TCP/IP, DNS, HTTP/S, VPNs, firewalls, and proxy technologies
    • Windows and Linux operating systems
    • Identity and access systems and authentication mechanisms
  • Experience using SIEM and security platforms such as:
    • Splunk, Microsoft Sentinel, QRadar, ArcSight, ELK, or similar
  • Ability to identify and respond to:
    • Phishing and business email compromise
    • Malware and ransomware
    • Credential compromise
    • Lateral movement and persistence mechanisms
    • Brute-force and privilege escalation attacks
  • Strong written and verbal communication skills, especially during high-pressure incidents.
  • Demonstrated ability to follow structured processes while continuously improving them.
     

Preferred Qualifications

  • Experience with EDR, SOAR, and forensic tooling (e.g., CrowdStrike, Defender, Carbon Black, EnCase, Velociraptor, etc.).
  • Experience supporting investigations involving legal, compliance, or regulatory stakeholders.
  • Knowledge of MITRE ATT&CK and modern adversary tactics.
  • Experience with cloud and SaaS incident response (Azure, M365, AWS, etc.).
  • Relevant certifications, including:
    • GIAC (GCIH, GCFA, GCIA)
    • Offensive Security (OSCP, OSCE, OSEE)
  • Vendor certifications (Splunk, Sentinel, CrowdStrike, etc.)

All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position's location, and conducting a comprehensive background check, where permitted by local regulations.

Similar Jobs

Remote or Hybrid
9 Locations
205000 Employees
35K-67K Hourly

NBCUniversal Logo NBCUniversal

Staff Devops Engineer

AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Remote or Hybrid
Los Angeles, CA, USA
68000 Employees
130K-160K Annually

MetLife Logo MetLife

Disability Customer Advocate II - 6/1/26

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
54K-80K Annually

Cox Enterprises Logo Cox Enterprises

Supervisor, Client Service Quality - CAI Inventory Solutions

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
61K-92K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
5,000 Employees
Year Founded: 1951

What We Do

Fragomen is a leading firm dedicated exclusively to immigration services worldwide. Founded in 1951, Fragomen represents a broad range of companies, organizations and individuals to help facilitate the transfer of employees worldwide. We provide immigration support in more than 170 countries. An Am Law 100 and Global 100 firm, Fragomen’s professionals are respected thought leaders in the immigration field, as recognized by Chambers, Best Lawyers and Who’s Who. The firm employs more than 4,400 immigration professionals and support staff located in over 50 offices across the Americas, Asia Pacific and EMEA. Our services go beyond processing visa and work permit applications. We provide strategic consultative services and support to meet the full spectrum of business immigration needs. This includes government strategies and compliance, planning for mergers and acquisitions, and consular and document support. From our Immigration Technology Innovation Lab, we focus on using automation and artificial intelligence to pioneer sophisticated technology solutions to revolutionize the immigration experience for our clients. All services are designed to improve your speed-to-ground and help you mobilize your employee population so you can remain a cutting-edge player in your industry and competitive wherever you operate. We are committed to fostering a dynamic, diverse workplace. Year after year, Fragomen is recognized for our diversity by The American Lawyer, Law360 and the National Law Journal. Find out more at www.fragomen.com.

Similar Companies Hiring

CertifID Thumbnail
Software • Security • Real Estate • PropTech • Legal Tech • Cybersecurity
Austin , TX
130 Employees
Eve Thumbnail
Legal Tech • Software • Generative AI
San Mateo, CA
180 Employees
GC AI Thumbnail
Legal Tech • Artificial Intelligence
San Francisco, California
46 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account