Talent.com
Sr. Incident Response (IR) Detection Engineer

Sr. Incident Response (IR) Detection Engineer

PennyMacThousand Oaks, CA, United States
9 hours ago
Job type
  • Full-time
Job description

PENNYMAC

Pennymac (NYSE : PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market.

At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey.

A Typical Day

The Pennymac Information Security department is looking to bring on a Senior IR Detection Engineer to drive our Threat Detection and Response efforts. You will specialize in developing sophisticated signatures, queries, alerts, and dashboards to detect and neutralize cyber threats in a complex cloud environment while focusing on the SOC analyst experience.

The Senior IR Detection Engineer will :

Detection as Code : Design, develop, test, and deploy high-quality detection rules using version control systems (e.g., Git) and CI / CD pipelines.

Drive the overall detection engineering lifecycle including processes, improvements, and innovations.

Use inputs from Threat Intelligence (TI) and threat modeling exercises to identify critical detection gaps.

Maintain a comprehensive risk detection coverage mapping to communicate current coverage and show improvements.

Serve as the primary author and reviewer of new detectors, ensuring proper documentation and testing.

Continually observe the performance of existing detectors and tune them to reduce false positives and ensure they remain valuable.

Leverage AI / ML capabilities to enhance the detection engineering lifecycle and identify anomalies.

Partner with the Security Engineering team to configure, maintain, and optimize security monitoring tools to ensure maximum data ingestion quality and search performance.

Incident Response & Operations Support

L1 Support : Act as a tier-2 technical escalation point for the L1 SOC, providing expertise in triage, root cause analysis, and remediation planning for complex security alerts.

Perform in-depth host and network analysis across various environments with a primary focus on Windows, Cloud (AWS, Azure, GCP), and SaaS technologies.

Execute the full IR lifecycle and lead incident handling during major security events.

Serve as a technical escalation point for complex or novel security incidents.

Develop and review Standard Operating Procedures (SOPs), playbooks, and other documentation for the IR team.

Provide thought leadership on strategic objectives such as processes, technologies, and exercises.

Mentor and train junior and mid-level incident responders on advanced techniques, tools, and best practices.

What You’ll Bring

Deep understanding of hacking techniques and tools including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits.

Strong understanding of MITRE ATT&CK Framework.

Strong understanding of all phases of security incident handling and forensics including probing and attack methods, network / service discovery, system assessment, threat containment / eradication, and conducting retrospects to drive operational improvement.

Strong understanding of network technologies including TCP / IP, IDS / IPS, firewalls, LAN, WLAN, and WAN.

Expert understanding of AWS IaaS / PaaS, Linux, Windows Server, Windows Desktop, VMWare, Containers, and MacOS.

Experience operating and maintaining SIEM technology and providing feedback to engineering teams to continually improve technology capabilities.

Past experience in a Cyber Security Operations Center as a Security Analyst is desired.

Desired 2+ years of experience in Python and / or other scripting languages to automate common tasks and / or response actions.

Desired experience in Snowflake or similar Data Lake Technology.

Strong written and verbal communication.

Ability to self-start and spearhead initiatives with minimal direction and oversight.

Why You Should Join

As one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values : to be Accountable, Reliable and Ethical in all that we do. Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported.

Benefits That Bring It Home : Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include :

Comprehensive Medical, Dental, and Vision

Paid Time Off Programs including vacation, holidays, illness, and parental leave

Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)

Retirement benefits, life insurance, 401k match, and tuition reimbursement

Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorships

To learn more about our benefits visit :

For residents with state required benefit information, additional information can be found at :

Compensation : Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below :

Lower in range - Building skills and experience in the role

Mid-range - Experience and skills align with proficiency in the role

Higher in range - Experience and skills add value above typical requirements of the role

Some roles may be eligible for performance-based compensation and / or stock-based incentives awarded to employees based on company and individual performance.

Salary

$90,000 - $150,000

Work Model

REMOTE

Create a job alert for this search

Incident Response Engineer • Thousand Oaks, CA, United States

Related jobs
  • Promoted
Information System Security Officer (ISSO)

Information System Security Officer (ISSO)

DCS CorporationPoint Mugu, California, US
Permanent
Salary Range : $71,310 - $115,000 Provide on-site Information System Security Officer (ISSO) and / or Information Assurance Officer (IAO) support to our F-35 customer. Essential Job Functions : Ensure p...Show moreLast updated: 23 days ago
  • Promoted
EW Systems Engineer

EW Systems Engineer

DCS CorporationPoint Mugu, California, US
Full-time
Salary Range : $87,934 - $160,000 The EW Systems Engineer support a team of engineers with hardware and software electronic warfare solutions, performing analysis and coordinating products with mana...Show moreLast updated: 23 days ago
  • Promoted
Electrical Engineer (RF, HW / SW Design)

Electrical Engineer (RF, HW / SW Design)

DCS CorporationPoint Mugu, California, US
Full-time
Salary Range : $120,506 - $150,000 The Electrical Engineer (RF, HW / SW Design) will be tasked with designing, developing, troubleshooting, maintaining, testing, and upgrading electronic circuit cards...Show moreLast updated: 23 days ago
  • Promoted
Project Engineer I

Project Engineer I

SanbellVentura, CA, US
Full-time
Built by merging 5 strong firms with similar foundational and cultural values, our team of engineers, planners, landscape architects, surveyors, and designers is now stronger.We are 200 + team memb...Show moreLast updated: 30+ days ago
  • Promoted
Enterprise Identity Architect

Enterprise Identity Architect

ClientWestlake Village, CA, US
Temporary
Duration : 5 months contract (potential to go PERM eventually).The Vice President Architect is responsible for providing strategic guidance, designs, and solution patterns to team members, and is th...Show moreLast updated: 30+ days ago
  • Promoted
Software Engineer II

Software Engineer II

2kMoorpark, California, United States
Full-time
DELETE AS APPROPRIATE • • - please leave the relevant location tag for LinkedIn.K is headquartered in Novato, California and is a wholly owned label of Take-Two Interactive Software, Inc.Founded in 2...Show moreLast updated: 30+ days ago
  • Promoted
Identity & Access Management (IAM) Engineer

Identity & Access Management (IAM) Engineer

MedtronicNorthridge, California, USA
Full-time
We anticipate the application window for this opening will close on - 5 Dec 2025.At Medtronic you can begin a life-long career of exploration and innovation while helping champion healthcare access...Show moreLast updated: 3 days ago
  • Promoted
Travel RN - Level III NICU - $2,497 per week

Travel RN - Level III NICU - $2,497 per week

American TravelerLake Sherwood, CA, US
Full-time
American Traveler is seeking a travel nurse RN NICU - Neonatal Intensive Care for a travel nursing job in Thousand Oaks, California. Job Description & Requirements Specialty : NICU - Neonatal Intensi...Show moreLast updated: 9 days ago
  • Promoted
Director of Security Operations (Aerospace)

Director of Security Operations (Aerospace)

Allied UniversalVentura, CA, US
Full-time
Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and co...Show moreLast updated: 17 days ago
  • Promoted
Traffic Control Technician II

Traffic Control Technician II

Roadsafe Traffic SystemsVentura, California, US
Full-time
Title : Traffic Control Technician II Classification : Non-Exempt About the Organization RoadSafe Traffic Systems is the largest national provider of traffic safety products and services in the Unite...Show moreLast updated: 7 days ago
  • Promoted
Staff Applied Scientist, Recommender Systems

Staff Applied Scientist, Recommender Systems

The Trade DeskVentura, CA, United States
Full-time
The Trade Desk is a global technology company with a mission to create a better, more open internet for everyone through principled, intelligent advertising. We have also built something even strong...Show moreLast updated: 3 days ago
  • Promoted
Business Intelligence Analyst II

Business Intelligence Analyst II

The Trade DeskVentura, CA, United States
Full-time
The Trade Desk is changing the way global brands and their agencies advertise to audiences around the world.How? With a media buying platform that helps brands deliver a more insightful and relevan...Show moreLast updated: 30+ days ago
  • Promoted
Information Systems Security Officer (ISSO)

Information Systems Security Officer (ISSO)

Aviation Systems Engineering CompanyNaval Air Station Point Mugu, CA, United States
Full-time
Security Clearance Requirement : Top Secret.Telework Eligible? No - 100% On-Site.Information System Security Officer.The candidate will provide support for proposing, coordinating, implementing, and...Show moreLast updated: 30+ days ago
  • Promoted
Sr. Associate, Quality Engineer

Sr. Associate, Quality Engineer

L3Harris TechnologiesENCINO, California, United States
Full-time
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers’ mission and quest ...Show moreLast updated: 1 day ago
  • Promoted
Sr Specialist, Quality Engineer

Sr Specialist, Quality Engineer

L3Harris TechnologiesTARZANA, California, United States
Full-time
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers’ mission and quest ...Show moreLast updated: 30+ days ago
  • Promoted
Quality Engineer

Quality Engineer

Ensign-Bickford IndustriesMoorpark, CA, United States
Full-time
This opportunity is located within our.Ensign-Bickford Aerospace & Defense Company.This position provides organizational support for customer programs and supplier quality requirements.The candidat...Show moreLast updated: 30+ days ago
  • Promoted
CMM Inspector

CMM Inspector

JobotSanta Clarita, CA, US
Permanent
We are an Aerospace manufacturing company looking for a CMM Programmer to join our growing team!.This Jobot Job is hosted by : Ryan Rubino. Are you a fit? Easy Apply now by clicking the "Apply Now" b...Show moreLast updated: 30+ days ago
  • Promoted
Senior Software Engineer - Geo Targeting

Senior Software Engineer - Geo Targeting

The Trade DeskVentura, CA, United States
Full-time
The Trade Desk is a global technology company with a mission to create a better, more open internet for everyone through principled, intelligent advertising. Handling over 1 trillion queries per day...Show moreLast updated: 30+ days ago