The Role
The Incident Response Engineer leads investigations into severe threats, performs forensics, automates response actions, monitors alerts, and documents findings.
Summary Generated by Built In
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
Job Responsibilities
- Incident Investigation: Lead investigations into high-severity threats, identifying root causes to prevent recurrence.
- Threat Containment & Remediation: Take immediate, hands-on action to stop attacks and restore systems to normal operations.
- Digital Forensics: Perform host, memory, and network forensics to uncover indicators of compromise (IOCs).
- Automation & Tooling: Write scripts (Python, Bash, PowerShell) and build SOAR playbooks to automate response actions.
- Monitoring & Hunting: Proactively monitor security alerts and conduct threat hunting to detect malicious activity.
- Documentation & Reporting: Create detailed post-mortem reports and update runbooks
Job Qualifications
- Experience: Generally 3–5+ years in cybersecurity, SOC analysis, or system engineering.
- Technical Skills: Proficiency in network protocols (TCP/IP, DNS), operating systems (Windows, Linux), and cloud platforms (AWS, Azure, GCP).
- Tools: Experience with SIEM, EDR, and SOAR tools.
- Frameworks: Familiarity with the MITRE ATT&CK framework and NIST IR Lifecycle.
- Education: Bachelor’s degree in Computer Science, Cyber Security, or equivalent experience.
- Certifications: Preferred certifications include: GIAC, GCIH, CISSP or CEH
We’re actively searching for talented and expereinced professionals who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:
- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
True Zero Technologies is a Professional Services firm and authorized product reseller. Made up of passionate technologists, TZT delivers services for both the public and private sector, creating unique and scalable solutions based on business context driven requirements. TZT is rapidly expanding it's team to meet demand, we have many opportunities including long-term, multi-year contracts supporting Splunk instances large and small with ample opportunity to help shape large operational and security programs. Apply today! https://truezerotech.applicantpro.com/jobs/







