Principal Incident Response Engineer, Remote

Autodesk Autodesk · Enterprise · Portland, OR +1

This role focuses on incident response and security analysis within an enterprise environment, utilizing Splunk for data analysis and threat detection. It involves advanced investigations, threat hunting, and mentoring junior analysts, with experience in cloud environments (Azure, AWS, GCP).

What you'd actually do

  1. Conduct detailed investigations on high-complexity incidents, correlating data across diverse sources using Splunk to pinpoint IOCs and determine root causes
  2. Work directly with the Incident Response Manager and cross-functional teams to coordinate incident mitigation efforts and continuously refine response protocols
  3. Develop and maintain technical playbooks, enhance detection capabilities, and contribute to the evolution of Autodesk’s incident response strategy
  4. Provide technical guidance and mentorship to junior analysts, fostering an environment of continuous learning and improvement
  5. Operate seamlessly within a cloud agnostic framework, with exposure to Azure, AWS, and GCP infrastructures

Skills

Required

  • 5+ years of hands-on experience in incident response or security operations
  • Exceptional proficiency with Splunk; capable of writing and optimizing multi-source queries, and incident dashboards to detect or display advanced threats
  • Demonstrated ability to independently conduct sophisticated threat analyses and forensic investigations
  • Strong analytical, problem-solving, and communication skills
  • Proven ability to mentor peers
  • Experience or familiarity with managing security operations in cloud environments including Azure, AWS, and GCP

What the JD emphasized

  • Exceptional proficiency with Splunk