Incident Response Engineer Jobs
Incident Response Engineer jobs are open across financial services, healthcare, technology, government contracting, and managed security services, from entry-level analyst roles to senior and principal positions, with specializations in digital forensics, threat hunting, and malware analysis. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote incident response engineer jobs →Overview
Showing 5 of 127+ Incident Response Engineer jobs











DESCRIPTION
About Us:
Twitch is the world’s biggest live streaming service, with global communities built around gaming, entertainment, music, sports, cooking, and more. It is where thousands of communities come together for whatever, every day.
We’re about community, inside and out. You’ll find coworkers who are eager to team up, collaborate, and smash (or elegantly solve) problems together. We’re on a quest to empower live communities, so if this sounds good to you, see what we’re up to on LinkedIn and X, and discover the projects we’re solving on our Blog. Be sure to explore our Interviewing Guide to learn how to ace our interview process.
About the Role
Twitch is looking for a Security Incident Response Engineer to join our SIRT. Reporting to the SIRT Manager, you'll be at the heart of our mission to find, handle, and learn from security incidents across our global platform. We're looking for engineers who thrive coordinating response to emerging issues in information security who are ready to level up our defense. If you're passionate about protecting the Twitch community and solving complex security puzzles, we want to hear from you!
You can work from San Francisco, CA; Irvine, CA; or Seattle, WA.
You Will
- Participate in an on-call rotation that includes your peers on the Security Incident Response Team
- Qualify reports or alerts of activity as security incidents using clear guidelines that establish what a security incident is
- Evaluate the potential and realized impact of security incidents to Twitch
- Analyze threat actor tactics, techniques, and procedures
- Participate or create information sharing groups; communicate securely and responsibly
- Write and follow clear procedures so that our work can be accountable, repeated, measured, and improved
- Communicate with peers and leadership about timeline of a security related event with what potential and realized impact, how we discovered it, and how we're handling it
- Coordinate security incident response activities with affected teams to do the right thing for our customers and our organization
- Investigate, document, and implement agentic detection, enrichment, triage, response, and communication automations in every day processes
- Lead lessons learned discussions and help teams effect change across the business that reduces incident recurrence
Perks
- Medical, Dental, Vision & Disability Insurance
- 401(k)
- Maternity & Parental Leave
- Flexible PTO
- Amazon Employee Discount
BASIC QUALIFICATIONS
- 3+ years of information security and compliance experience, or Bachelor's degree in computer science, engineering, analytics, mathematics, statistics, IT or equivalent
- Automation experience using scripting or programming languages (Go, Python, Ruby, Shell, or Perl)
- Ability to securely design and implement AI/ML-driven playbooks to automate common security operations
- Experience coordinating responses to security incidents
- Knowledge of security issues and threat landscape
- Background in cloud, host, network, and application security
- Familiarity with common Incident Response frameworks or lifecycle models like NIST-800-61, ISO/IEC 27035, etc.
PREFERRED QUALIFICATIONS
- B.S. or M.S. in Computer Science, Computer Engineering, Software Security, or a related technical discipline
- Experience and familiarity with streaming and content creation
- Experience handling security incidents in hybrid cloud environment (AWS, GCP) and conducting log dives on cloud telemetry like CloudTrail
- Passion and excitement for Twitch
Twitch is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, IRVINE - 159,300.00 - 202,400.00 USD annually
USA, CA, SAN FRANCISCO - 166,600.00 - 212,800.00 USD annually
USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually
Incident Response Engineer Jobs by Experience Level
See All 127+ Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsIncident Response Engineer Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Consulting & Professional Services
- Retail
- Science & Research
- Investment & Asset Management
What Employers Look For
The qualifications that appear most often in incident response engineer jobs.
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Proficiency in digital forensics and malware analysis using tools like Volatility, FTK, or EnCase
- Knowledge of network traffic analysis and packet inspection with Wireshark or similar tools
- Relevant certification such as GCIH, GCFE, Security+, or CySA+
- Familiarity with endpoint detection and response platforms including CrowdStrike, SentinelOne, or Carbon Black
- Bachelor's degree in cybersecurity, computer science, information systems, or equivalent practical experience
Tips for Your Incident Response Engineer Job Search
Tailor your resume to the incident lifecycle
Hiring managers scan for evidence you've worked through the full cycle: detection, containment, eradication, and recovery. List specific incidents you've handled, the tools you used at each stage, and the measurable outcome, even if the numbers are approximate.
Certify strategically before you apply
GCIH and GCFE carry the most weight with security teams hiring for incident response specifically. If you already hold Security+ or CySA+, lead with those while you pursue the GIAC certs, since many postings list both tiers.
Apply early to roles that fit
Migrate Mate lists incident response engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by your clearance level
A large share of incident response roles, especially in government contracting and defense, require an active Secret or TS/SCI clearance. Filter by clearance requirement before applying so you don't spend time on roles your current status can't support.
Prepare a hands-on technical portfolio
Interviewers routinely ask candidates to walk through a real investigation. Document two or three sanitized case studies showing your triage methodology, tools used, and how you communicated findings to stakeholders, even from lab or CTF environments.
Negotiate scope, not just compensation
During offer conversations, ask specifically about your on-call rotation structure, escalation authority, and tooling budget. Incident response roles vary dramatically in how much autonomy you actually have, and clarifying these upfront prevents surprises after you start.
Incident Response Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most incident response engineers?
The companies hiring the most incident response engineers right now include Amazon, Allied Universal, and Google, with the largest share of openings in Virginia, California, and Texas, based on current listings on Migrate Mate as of September 2026. Managed security service providers and large financial institutions consistently post the highest volume of openings year-round.
How many incident response engineer jobs are remote?
About 87% of incident response engineer openings are fully remote or hybrid as of September 2026, though on-site requirements are more common in roles tied to government, critical infrastructure, and classified environments. Threat intelligence and digital forensics sub-specializations tend to have the highest concentration of fully remote positions among all incident response roles.
How do you become an incident response engineer?
Start by building a foundation in networking, operating systems, and security fundamentals, then pursue a certification like Security+ or CySA+ to validate core knowledge. Gain hands-on experience through a SOC analyst or IT security role, and work toward GIAC certifications such as GCIH. Practice in lab environments, participate in capture-the-flag competitions, and document real investigations to demonstrate your methodology to employers.
Can you get hired as an incident response engineer with little experience?
Yes, entry-level incident response engineer roles exist, though most expect some prior exposure to security operations or IT support. Building a home lab, earning your first certification, and contributing to open-source threat analysis projects can substitute for direct professional experience. Positions at managed security service providers often serve as structured entry points because they handle high incident volume and train analysts on the job.
What does the incident response engineer interview process look like?
Most processes start with a recruiter screen focused on your experience and certifications, followed by a technical interview where you walk through how you'd triage a specific incident scenario. Later rounds typically include a hands-on exercise, such as analyzing a memory dump or reviewing a log sample, and a behavioral interview assessing how you communicate under pressure. Final rounds often involve a meeting with the security team lead.
Where can I find and apply to incident response engineer jobs?
You can find and apply to incident response engineer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience level, specialization, and location preference, then apply directly to each listing without leaving the platform.
See All 127+ Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs