Remote Incident Response Engineer Jobs
Remote Incident Response Engineer jobs are in active demand at remote-first companies and large distributed teams, including employers like Abacus, Airbnb, and Abacus.Ai, from junior to senior. Scan the live roles below and apply to whichever ones fit.
Find JobsOverview
Showing 5 of 9+ Remote Incident Response Engineer jobs











If you’re looking for a special place to build or grow your career, you’ve found it. Whether you’re an experienced professional, a recent college graduate or somewhere in between, IDEX is a place where you can apply your existing skills and learn new ones in an environment where you can make an impact.
With interesting opportunities in engineering, marketing, sales, supply chain, operations, HR, finance, and more across more than 40 diverse businesses around the globe, chances are, we have something special for you.
The Senior Manager, Cybersecurity Incident Response & Security Operations serves as a operational leader within the IDEX Cybersecurity function, responsible for coordinating and advancing enterprise-wide incident detection and response capabilities.
This role oversees the execution and continuous improvement of incident response processes and security operations (SOC) functions across multiple internal and external providers, ensuring consistent, high-quality monitoring, escalation, and response.
This role is responsible for defining how cybersecurity incidents are assessed, escalated, and managed across the enterprise, and for ensuring IDEX Cybersecurity leads the response to significant security events. This role will partner with the IT and infrastructure teams that operate specific environments (e.g., data center SOC services).
The role partners closely with IT, infrastructure, and external SOC providers to align on detection capabilities and operational processes, while supporting Cybersecurity leadership in coordinating high-impact incidents and driving continuous improvement in response effectiveness.
Position Responsibilities
Incident Response:
- Support enterprise incident response activities across detection, triage, containment, eradication, and recovery
- Coordinate the execution of high-impact cybersecurity incidents, in support of Cybersecurity leadership
- Serve as an operational escalation point for incident response, ensuring issues are appropriately routed and addressed
- Develop and maintain incident response playbooks, procedures, and standards
- Support coordination with legal, compliance, IT, and external response partners under the direction of Cybersecurity leadership
- Lead post-incident reviews with relevant stakeholders to identify improvements and strengthen organizational readiness
Security Operations:
- Lead security operations activities focused on SOC services, including security monitoring, alert management, and incident response execution
- Oversee internal teams and external service providers (e.g., MSSPs) to ensure consistent, high-quality security operations coverage
- Establish and enforce operational standards for alert triage, escalation, and incident handling
- Drive scalability and efficiency through automation, orchestration, and process optimization
- Ensure effective monitoring coverage across Microsoft 365 Commercial and Government Community Cloud High (GCCH) environments
Security Operations Program & Technology Management:
- Own and evolve security operations technologies, including security information & event monitoring (SIEM) and detection and response platforms
- Define and govern how multiple SOCs (internal and external) operate together, ensuring clear roles, responsibilities, and coordination models
- Establish IDEX Cybersecurity as the lead authority for major incident response, with external SOCs supporting detection and escalation
- Manage relationships with external SOC providers, including performance oversight, metrics, and participation in QBRs
- Improve detection fidelity through alert tuning, use case development, and false positive reduction
- Drive enhancements in detection coverage, response speed (MTTR), and overall operational effectiveness
- Partner with cybersecurity leadership to define operational roadmap, priorities, and maturity targets
Operational Coordination & Service Delivery:
- Coordinate cybersecurity requests and activities across teams, ensuring work is properly triaged, prioritized, and completed
- Manage ticketing and escalation processes, ensuring issues are routed, tracked, and resolved in a timely manner
- Track and communicate the status of incidents, initiatives, and key activities across teams
- Partner with IT and project management office (PMO) teams to ensure cybersecurity requirements are built into projects and services from the start
- Promote consistent, security-first practices across IT operations and service delivery
Metrics, Reporting & Continuous Improvement:
- Own security operations performance metrics and reporting, including MTTR, detection effectiveness, alert quality, and service level agreements (SLAs)
- Develop and enhance operational metrics and dashboards to support enterprise reporting and risk visibility
- Use data-driven insights to identify gaps, inefficiencies, and improvement opportunities
- Drive continuous improvement initiatives to enhance operational maturity, scalability, and consistency
Training, Exercises & Readiness:
- Support coordination of cybersecurity readiness efforts, including tabletop exercises and crisis simulations
- Mentor and develop team members and stakeholders in incident response practices
- Support knowledge transfer and training initiatives to improve enterprise-wide response capabilities
- Contribute to development and maintenance of operational documentation and standards
Position Qualifications, Skills, and Experience
- Bachelor’s degree in Information Systems, Computer Science, Information Security, or equivalent experience
- 10+ years of experience in cybersecurity with a focus on security operations, incident response, or SOC leadership
- Demonstrated experience leading enterprise incident response and security operations programs
- Strong expertise in SIEM platforms, detection engineering concepts, and monitoring operations
- Experience in complex enterprise or regulated environments
- Proven ability to lead cross-functional initiatives in matrixed organizations
- Strong communication skills with the ability to engage both technical and executive stakeholders
- Experience supporting Microsoft 365 GCC High (GCCH) environments
- Experience managing MSSPs or external SOC/forensic partners
- Familiarity with NIST CSF, NIST 800-53, and NIST 800-171
- Relevant certifications preferred (e.g., CISSP, GCIH, GCFA, CISM)
- Experience implementing automation, orchestration, and AI-enabled security operations capabilities
Are you ready to join a different kind of company where our people, our culture, and our commitments are centered around providing trusted solutions that improve lives around the world?
Total Rewards
The compensation range for this position is $141,800.00 - $212,800.00, depending on experience. This position may be eligible for performance based bonus plan.Benefits Package
Our comprehensive U.S. benefit offerings include: Health benefits, 401(k) retirement savings program with company match, PTO, and more. More information on our benefits and rewards can be found on our career page: https://www.idexcorp.com/careers/our-benefits-and-rewards/
IDEX is an Equal Opportunity Employer. IDEX gives consideration for employment to qualified applicants without regard to race, color, religion, creed, genetic information, sex, sexual orientation, gender identity or expression, marital status, age, national origin, disability, protected veteran status, or any other consideration or protected category made unlawful by federal, state or local laws.
Attention Applicants: If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, please let us know. Likewise, if you are limited in the ability to access or use this online application process and need an alternative method for applying, we will determine an alternate way for you to apply. Please contact our Talent Acquisition Team at lfcareers@idexcorp.com for assistance with an accommodation. These contact tools may be used only by individuals with a disability for accommodation requests. Do not inquire as to the status of an application.
This posting is for an existing vacancy.
Artificial intelligence is not used to screen, assess or select applicants.See All 9 Remote Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Incident Response Engineer Job Market
Who's Hiring
- Abacus1
- Airbnb1

- Abacus.Ai1

- ClickHouse1

- Fireblocks1

Top Industries Hiring
- Technology & Software5
- Hospitality & Tourism2
- Law & Legal Services1
What Employers Look For
The qualifications that appear most often in remote incident response engineer jobs.
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Proficiency in digital forensics and malware analysis using tools like Volatility, FTK, or EnCase
- Knowledge of network traffic analysis and packet inspection with Wireshark or similar tools
- Relevant certification such as GCIH, GCFE, Security+, or CySA+
- Familiarity with endpoint detection and response platforms including CrowdStrike, SentinelOne, or Carbon Black
- Bachelor's degree in cybersecurity, computer science, information systems, or equivalent practical experience
Tips for Your Remote Incident Response Engineer Job Search
Tailor your resume to the incident lifecycle
Hiring managers scan for evidence you've worked through the full cycle: detection, containment, eradication, and recovery. List specific incidents you've handled, the tools you used at each stage, and the measurable outcome, even if the numbers are approximate.
Certify strategically before you apply
GCIH and GCFE carry the most weight with security teams hiring for incident response specifically. If you already hold Security+ or CySA+, lead with those while you pursue the GIAC certs, since many postings list both tiers.
Apply early to roles that fit
Migrate Mate lists incident response engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by your clearance level
A large share of incident response roles, especially in government contracting and defense, require an active Secret or TS/SCI clearance. Filter by clearance requirement before applying so you don't spend time on roles your current status can't support.
Prepare a hands-on technical portfolio
Interviewers routinely ask candidates to walk through a real investigation. Document two or three sanitized case studies showing your triage methodology, tools used, and how you communicated findings to stakeholders, even from lab or CTF environments.
Negotiate scope, not just compensation
During offer conversations, ask specifically about your on-call rotation structure, escalation authority, and tooling budget. Incident response roles vary dramatically in how much autonomy you actually have, and clarifying these upfront prevents surprises after you start.
Remote Incident Response Engineer Jobs: Frequently Asked Questions
How do I get a remote incident response engineer job?
Target companies that already run distributed teams, since they hire remotely by default and know how to onboard someone they never meet in person. Remote incident response engineer employers screen hard for self-direction and clear written communication on top of the core skills, so show evidence you can own work without someone over your shoulder. Apply to the openings above that match your experience.
Which companies hire remote incident response engineers?
Employers currently hiring remote incident response engineers include Abacus, Airbnb, and Abacus.Ai, per current remote listings on Migrate Mate as of June 2026. Remote-first firms and large companies running distributed teams post the most remote incident response engineer roles.
Can you get a remote incident response engineer job with no experience?
Yes, but it is harder than an on-site role, because remote work expects you to operate independently from the start. Entry-level remote incident response engineer openings do exist, especially at remote-first companies, and a portfolio of real work helps more than a long resume. Applying broadly to the roles that fit improves your odds.
Do you need a degree for remote incident response engineer jobs?
Not always. Many employers hire remote incident response engineers on demonstrated skills and prior work rather than a specific degree, though some larger companies still prefer one. Showing relevant results matters more than a credential for most remote incident response engineer roles.
Which industries hire the most remote incident response engineers?
The sectors hiring the most remote incident response engineers are Technology & Software, Hospitality & Tourism, and Law & Legal Services, based on current remote listings on Migrate Mate as of June 2026. These sectors run distributed teams and hire incident response engineers remotely most consistently.
See All 9 Remote Incident Response Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs