Logo
Acrisure

Security Incident Response Engineer - EDR

Acrisure, Chicago, Illinois, United States, 60290

Save Job

Security Incident Response Engineer - EDR

Join to apply for the

Security Incident Response Engineer - EDR

role at

Acrisure Security Incident Response Engineer - EDR

Join to apply for the

Security Incident Response Engineer - EDR

role at

Acrisure About Acrisure

A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more. Job Description

About Acrisure

A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. Bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across a range of insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services – and more.

In the last eleven years, Acrisure has grown in revenue from $38 million to almost $5 billion and employs over 19,000 colleagues in more than 20 countries. Our culture is defined by our entrepreneurial spirit and all that comes with it: innovation, client centricity and an indomitable will to win.

Job Summary:

The Security Incident Response Engineer – EDR will support the organization’s security operations with a focus on endpoint detection and response (EDR) management and incident response activities. To succeed in this role, the candidate must be adept at coordinating and triaging security incidents, responding promptly and effectively to threats, and managing EDR toolsets at scale. The engineer will proactively monitor, analyze, and resolve security incidents involving endpoints, requiring high attention to detail and the ability to balance multiple urgent tasks. Key to this position is being a self-starter, consistently prioritizing critical tasks, and maintaining strong commitment to operational excellence.

Responsibilities:

Incident Response Detect, analyze, and respond to security incidents detected by EDR, SIEM, and Cloud Security tooling as well as MDR service providers. Lead or participate in investigation and containment efforts for both endpoint and identity related security threats. Develop and implement strategies to remove the root cause of the incident. Conduct forensic data acquisition, log analysis, and root cause determination for endpoint incidents. Develop and maintain incident response playbooks and runbooks specific to EDR technologies. Analyze security alerts and anomalies to determine if they represent actual security incidents. EDR Deployment and Configuration Oversee deployment, configuration, and ongoing management of EDR on endpoints for comprehensive coverage. Monitor and tune alerting rules/policies to reduce false positives and ensure accurate threat detection. Maintain compliance measures by enforcing configuration to organizational standards. Provide training on EDR usage to incident response teams and end-users. Review security alerts, correlate event data, and identify risks to endpoints. Maintain integration of EDR tools with SIEM and other security solutions. Regularly review and update endpoint security policies based on threat intelligence and incident learnings.

Requirements

Technical Skills Proficiency with leading Endpoint Detection and Response platforms (SentinelOne, Microsoft Defender, CrowdStrike, or other toolsets). Strong experience with incident response, digital forensics, and threat hunting on endpoints. Knowledge of endpoint operating systems (Windows, macOS, and Linux). Experience with scripting (PowerShell, Python, or Bash) for automation and log parsing. Professional Skills Excellent analytical and problem-solving skills; ability to work in high-pressure situations. Effective verbal and written communication abilities. Detail-oriented with strong organizational skills and the ability to handle multiple priorities. Ability to work independently and within a collaborative, team-oriented environment. Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related discipline (or equivalent experience). Minimum 3 years of progressive information security experience. At least 1-3 years focused on incident response, including hands-on EDR work. Expertise in Infrastructure Security: In-depth understanding of infrastructure security, including Windows, Active Directory, Unix/Linux, Mobile Security, and Privileged Access Management. Experience with Microsoft M365 security including Entra ID, Microsoft Defender for M365, and other toolsets is a plus. Relevant certifications (one or more preferred): GCFA, GCIH, CHFI, CySA+, or similar.

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

Benefits and Perks:

Competitive compensation Generous vacation policy, paid holidays, and paid sick time Medical Insurance, Dental Insurance, and Vision Insurance (employee-paid) Company-paid Short-Term and Long-Term Disability Insurance Company-paid Group Life insurance Company-paid Employee Assistance Program (EAP) and Calm App subscription Employee-paid Pet Insurance and optional supplemental insurance coverage Vested 401(k) with company match and financial wellness programs Flexible Spending Account (FSA), Health Savings Account (HSA) and commuter benefits options Paid maternity leave, paid paternity leave, and fertility benefits Career growth and learning opportunities …and so much more!

Please note: This list is not reflective of all benefits. Enrollment waiting periods or eligibility criteria may apply to certain benefits. Offerings may vary based on subsidiary entity or geographic location.

Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.

Welcome, your new opportunity awaits you.

Pay Details

Annual Salary: : $130,000 - $140,000

Pay Details:

The base compensation range for this position is $130,000 - $140,000. This range reflects Acrisure's good faith estimate at the time of this posting. Placement within the range will be based on a variety of factors, including but not limited to skills, experience, qualifications, location, and internal equity.

Acrisure is committed to employing a diverse workforce. All applicants will be considered foremploymentwithout attention to race, color, religion, age, sex, sexual orientation, gender identity, national origin, veteran, or disability status.

California

residents can learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy available at www.Acrisure.com/privacy/caapplicant.

To Executive Search Firms & Staffing Agencies: Acrisure does not accept unsolicited resumes from any agencies that have not signed a mutual service agreement. All unsolicited resumes will be considered Acrisure’s property, and Acrisure will not be obligated to pay a referral fee. This includes resumes submitted directly to Hiring Managers without contacting Acrisure’s Human Resources Talent Department. Seniority level

Seniority level Mid-Senior level Employment type

Employment type Full-time Job function

Job function Information Technology Industries Insurance Referrals increase your chances of interviewing at Acrisure by 2x Sign in to set job alerts for “Security Engineer” roles.

Chicago, IL $115,000.00-$138,000.00 1 month ago River Forest, IL $77,000.00-$85,666.00 2 weeks ago Chicago, IL $110,000.00-$115,000.00 1 year ago Greater Chicago Area $70,000.00-$80,000.00 5 days ago Chicago, IL $95,000.00-$115,000.00 3 days ago Software Engineer – Market and Reference Data

Chicago, IL $100,000.00-$150,000.00 2 days ago Chicago, IL $70,000.00-$80,000.00 1 day ago Chicago, IL $100,000.00-$150,000.00 1 week ago Chicago, IL $87,780.00-$119,680.00 2 weeks ago Chicago, IL $60,000.00-$72,000.00 1 day ago Chicago, IL $105,000.00-$145,000.00 1 week ago Oak Brook, IL $80,000.00-$95,000.00 1 week ago Chicago, IL $91,300.00-$110,000.00 3 days ago Network Security Engineer (NAC) - North Central (Remote in the U.S.)

Chicago, IL $77,000.00-$90,000.00 2 weeks ago Chicago, IL $77,900.00-$199,000.00 2 weeks ago Senior Engineer - Cybersecurity Operations & Engineering

Chicago, IL $114,665.00-$156,310.00 2 weeks ago Chicago, IL $74,000.00-$113,000.00 1 week ago Chicago, IL $110,775.00-$188,325.00 2 weeks ago Network Security Engineer (WAF) - North Central (Remote in the U.S.)

Chicago, IL $123,274.67-$167,301.34 1 week ago Deerfield, IL $98,600.00-$157,500.00 2 days ago Lisle, IL $58,400.00-$116,900.00 2 weeks ago Chicago, IL $110,000.00-$130,000.00 1 week ago Greater Chicago Area $190,000.00-$245,000.00 1 week ago Chicago, IL $85,000.00-$100,000.00 1 week ago Senior Identity Security Services Engineer

Chicago, IL $90,000.00-$132,000.00 5 days ago We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr