Talent.com
Sr. Incident Response (IR) Detection Engineer

Sr. Incident Response (IR) Detection Engineer

PennyMacWestlake Village, CA, United States
5 hours ago
Job type
  • Full-time
Job description

PENNYMAC

Pennymac (NYSE : PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market.

At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey.

A Typical Day

The Pennymac Information Security department is looking to bring on a Senior IR Detection Engineer to drive our Threat Detection and Response efforts. You will specialize in developing sophisticated signatures, queries, alerts, and dashboards to detect and neutralize cyber threats in a complex cloud environment while focusing on the SOC analyst experience.

The Senior IR Detection Engineer will :

  • Detection as Code : Design, develop, test, and deploy high-quality detection rules using version control systems (e.g., Git) and CI / CD pipelines.
  • Drive the overall detection engineering lifecycle including processes, improvements, and innovations.
  • Use inputs from Threat Intelligence (TI) and threat modeling exercises to identify critical detection gaps.
  • Maintain a comprehensive risk detection coverage mapping to communicate current coverage and show improvements.
  • Serve as the primary author and reviewer of new detectors, ensuring proper documentation and testing.
  • Continually observe the performance of existing detectors and tune them to reduce false positives and ensure they remain valuable.
  • Leverage AI / ML capabilities to enhance the detection engineering lifecycle and identify anomalies.
  • Partner with the Security Engineering team to configure, maintain, and optimize security monitoring tools to ensure maximum data ingestion quality and search performance.

Incident Response & Operations Support

  • L1 Support : Act as a tier-2 technical escalation point for the L1 SOC, providing expertise in triage, root cause analysis, and remediation planning for complex security alerts.
  • Perform in-depth host and network analysis across various environments with a primary focus on Windows, Cloud (AWS, Azure, GCP), and SaaS technologies.
  • Execute the full IR lifecycle and lead incident handling during major security events.
  • Serve as a technical escalation point for complex or novel security incidents.
  • Develop and review Standard Operating Procedures (SOPs), playbooks, and other documentation for the IR team.
  • Provide thought leadership on strategic objectives such as processes, technologies, and exercises.
  • Mentor and train junior and mid-level incident responders on advanced techniques, tools, and best practices.
  • What You'll Bring

  • Deep understanding of hacking techniques and tools including evasion techniques, reconnaissance, scanning, exploitation, evasion, lateral movement, persistence, and exploits.
  • Strong understanding of MITRE ATT&CK Framework.
  • Strong understanding of all phases of security incident handling and forensics including probing and attack methods, network / service discovery, system assessment, threat containment / eradication, and conducting retrospects to drive operational improvement.
  • Strong understanding of network technologies including TCP / IP, IDS / IPS, firewalls, LAN, WLAN, and WAN.
  • Expert understanding of AWS IaaS / PaaS, Linux, Windows Server, Windows Desktop, VMWare, Containers, and MacOS.
  • Experience operating and maintaining SIEM technology and providing feedback to engineering teams to continually improve technology capabilities.
  • Past experience in a Cyber Security Operations Center as a Security Analyst is desired.
  • Desired 2+ years of experience in Python and / or other scripting languages to automate common tasks and / or response actions.
  • Desired experience in Snowflake or similar Data Lake Technology.
  • Strong written and verbal communication.
  • Ability to self-start and spearhead initiatives with minimal direction and oversight.
  • Why You Should Join

    As one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values : to be Accountable, Reliable and Ethical in all that we do. Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported.

    Benefits That Bring It Home : Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include :

  • Comprehensive Medical, Dental, and Vision
  • Paid Time Off Programs including vacation, holidays, illness, and parental leave
  • Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)
  • Retirement benefits, life insurance, 401k match, and tuition reimbursement
  • Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorships
  • To learn more about our benefits visit :

    For residents with state required benefit information, additional information can be found at :

    Compensation : Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below :

  • Lower in range - Building skills and experience in the role
  • Mid-range - Experience and skills align with proficiency in the role
  • Higher in range - Experience and skills add value above typical requirements of the role
  • Some roles may be eligible for performance-based compensation and / or stock-based incentives awarded to employees based on company and individual performance.

    Salary

    $90,000 - $150,000

    Work Model

    REMOTE

    Create a job alert for this search

    Incident Response Engineer • Westlake Village, CA, United States

    Related jobs
    • Promoted
    Information System Security Officer (ISSO)

    Information System Security Officer (ISSO)

    DCS CorporationPoint Mugu, California, US
    Permanent
    Salary Range : $71,310 - $115,000 Provide on-site Information System Security Officer (ISSO) and / or Information Assurance Officer (IAO) support to our F-35 customer. Essential Job Functions : Ensure p...Show moreLast updated: 23 days ago
    • Promoted
    EW Systems Engineer

    EW Systems Engineer

    DCS CorporationPoint Mugu, California, US
    Full-time
    Salary Range : $87,934 - $160,000 The EW Systems Engineer support a team of engineers with hardware and software electronic warfare solutions, performing analysis and coordinating products with mana...Show moreLast updated: 23 days ago
    • Promoted
    Electrical Engineer (RF, HW / SW Design)

    Electrical Engineer (RF, HW / SW Design)

    DCS CorporationPoint Mugu, California, US
    Full-time
    Salary Range : $120,506 - $150,000 The Electrical Engineer (RF, HW / SW Design) will be tasked with designing, developing, troubleshooting, maintaining, testing, and upgrading electronic circuit cards...Show moreLast updated: 23 days ago
    • Promoted
    Enterprise Identity Architect

    Enterprise Identity Architect

    ClientWestlake Village, CA, US
    Temporary
    Duration : 5 months contract (potential to go PERM eventually).The Vice President Architect is responsible for providing strategic guidance, designs, and solution patterns to team members, and is th...Show moreLast updated: 30+ days ago
    • Promoted
    Software Engineer II

    Software Engineer II

    2kMoorpark, California, United States
    Full-time
    DELETE AS APPROPRIATE • • - please leave the relevant location tag for LinkedIn.K is headquartered in Novato, California and is a wholly owned label of Take-Two Interactive Software, Inc.Founded in 2...Show moreLast updated: 30+ days ago
    • Promoted
    Sr Incident Response Engineer

    Sr Incident Response Engineer

    The Trade DeskLos Angeles, CA, United States
    Full-time
    The Trade Desk is changing the way global brands and their agencies advertise to audiences around the world.How? With a media buying platform that helps brands deliver a more insightful and relevan...Show moreLast updated: 2 days ago
    • Promoted
    Lead Security & Safety Engineer

    Lead Security & Safety Engineer

    Genies, Inc.Los Angeles, CA, United States
    Full-time
    Genies is an avatar technology company powering the next era of interactive digital identity through AI companions.With the Avatar Framework and intuitive creation tools, Genies enables developers,...Show moreLast updated: 7 days ago
    • Promoted
    Security Analyst

    Security Analyst

    EY Studio+ NederlandLos Angeles, California, USA
    Full-time
    At EY were all in to shape your future with confidence.Well help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.Join EY and help to ...Show moreLast updated: 1 day ago
    • Promoted
    • New!
    Sr. Incident Response (IR) Detection Engineer

    Sr. Incident Response (IR) Detection Engineer

    PennyMacThousand Oaks, CA, United States
    Full-time
    Pennymac (NYSE : PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U. At Pennymac, our people are ...Show moreLast updated: 7 hours ago
    • Promoted
    Information Systems Security Officer (ISSO)

    Information Systems Security Officer (ISSO)

    Aviation Systems Engineering CompanyNaval Air Station Point Mugu, CA, United States
    Full-time
    Security Clearance Requirement : Top Secret.Telework Eligible? No - 100% On-Site.Information System Security Officer.The candidate will provide support for proposing, coordinating, implementing, and...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Aerospace Systems Safety Engineer (Experienced, Senior, or Lead)

    Aerospace Systems Safety Engineer (Experienced, Senior, or Lead)

    BoeingEl Segundo, CA, US
    Permanent +1
    At Boeing, we innovate and collaborate to make the world a better place.We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with g...Show moreLast updated: 6 hours ago
    • Promoted
    Sr. Associate, Quality Engineer

    Sr. Associate, Quality Engineer

    L3Harris TechnologiesENCINO, California, United States
    Full-time
    L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers’ mission and quest ...Show moreLast updated: 1 day ago
    • Promoted
    Cyber Warfare Technician

    Cyber Warfare Technician

    US NavyLong Beach, California, United States
    Part-time
    Languages are more than just communication-they're cultural codes that need to be analyzed and in some cases, broken.As a Cryptologic Technician Interpretive (CTI) you're more than a linguist-you'r...Show moreLast updated: 30+ days ago
    • Promoted
    Lead AI Security Engineer

    Lead AI Security Engineer

    Capital GroupLos Angeles, CA, United States
    Full-time
    I can succeed as a Lead AI Security Engineer at Capital Group".As aLeadAISecurity Engineer, you willbe responsible forsecuring Capital Group's enterprise AI Platforms. You'llcollaborate with platfor...Show moreLast updated: 13 days ago
    • Promoted
    Sr Specialist, Quality Engineer

    Sr Specialist, Quality Engineer

    L3Harris TechnologiesTARZANA, California, United States
    Full-time
    L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers’ mission and quest ...Show moreLast updated: 30+ days ago
    • Promoted
    Quality Engineer

    Quality Engineer

    Ensign-Bickford IndustriesMoorpark, CA, United States
    Full-time
    This opportunity is located within our.Ensign-Bickford Aerospace & Defense Company.This position provides organizational support for customer programs and supplier quality requirements.The candidat...Show moreLast updated: 30+ days ago
    • Promoted
    CMM Inspector

    CMM Inspector

    JobotSanta Clarita, CA, US
    Permanent
    We are an Aerospace manufacturing company looking for a CMM Programmer to join our growing team!.This Jobot Job is hosted by : Ryan Rubino. Are you a fit? Easy Apply now by clicking the "Apply Now" b...Show moreLast updated: 30+ days ago
    • Promoted
    Principal Security Infrastructure Engineer

    Principal Security Infrastructure Engineer

    VastLong Beach, California, United States
    Full-time +1
    At Vast, our mission is to contribute to a future where billions of people are living and thriving in space.We are building artificial gravity space stations, allowing long-term stays in space with...Show moreLast updated: 30+ days ago