Senior Security Engineer - Digital Forensics and Incident Response (DFIR)
Agent
Ai Security
Cloud Platforms
Cyber Forensics
Data Security
Digital Incident Response
Engineer
Forensics
Identity and Access Management
Incident Response
Information Security
InfoSec
Security Automation
Security Compliance
Security Engineer
Security Investigation
Security Investigations
Security Operations
Threat Hunting
Job Description
Intuit is hiring a Senior Security Engineer to join its Digital Forensics and Incident Response (DFIR) team within the broader Security Operations Center (SOC). In this role, you will support the organization’s response to cyber-attacks by leading incident investigations, identifying root causes, and expanding detections and playbooks, including coverage for emerging AI and agentic system risks.
This onsite position is based in Frisco, TX. The role is intended for experienced security engineers with strong DFIR fundamentals, incident handling expertise, and the ability to improve how the SOC triages and investigates threats across endpoint, cloud, and network telemetry.
Key Responsibilities
- Oversee and promptly respond to escalated security events or investigations, activating the Security Incident Response Plan when required.
- Provide on-call support for critical severity issues, manage communications, and report incident status to the appropriate stakeholders.
- Lead forensic analysis to determine root cause, scope, and impact of security incidents.
- Investigate and respond to incidents involving AI/LLM-based tools and agentic platforms, including data leakage, insecure output handling, and unauthorized model access, and extend IR playbooks to cover generative AI and AI SOC platform risks.
- Develop, maintain, and improve incident response plans, procedures, and playbooks to support swift action and regulatory compliance.
- Use AI SOC platforms and frontier AI tools to accelerate triage, detection tuning, investigation, and documentation, and evaluate new AI capabilities as they are onboarded.
- Deliver guidance and training on security best practices and incident response to organizational partners, ensuring alignment with business objectives and compliance requirements.
- Mentor and train incident responders on incident handling, forensic analysis, and cloud security forensics and best practices.
- Collaborate with Compliance, Legal, and Risk teams to integrate incident response operations with business and regulatory needs.
- Assess vulnerabilities, propose remediation strategies, and stay current on emerging security trends, threats, and countermeasures.
Requirements
- Bachelor’s degree or higher in Technology, Computer Science, Cybersecurity, or a related field (or equivalent hands-on experience) is preferred.
- Industry-recognized professional certifications such as AWS Security Specialty, GCIH, GCFA, GFCE, CISSP, or emerging AI security credentials are advantageous.
- 3-5 years of experience in a dedicated cybersecurity role, with strong emphasis on digital forensics and incident response.
- 1-3 years writing scripts or code (Bash, PowerShell, Python); comfortable using AI coding assistants and AI SOC platforms to build faster, with awareness of risks from AI-generated code.
- Working knowledge of AI/LLM security risks and mitigations, including data exfiltration, insecure output handling, model and data supply chain risk, and shadow AI usage; familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF.
- Experience conducting analysis and detection engineering using Endpoint Detection and Response or Cloud Security Posture Management tools such as CrowdStrike Falcon and Wiz.
- Proven threat hunting experience, with hypothesis-driven hunts across endpoint, cloud, and network telemetry to uncover threats that evade existing detections.
- Comprehensive understanding of cybersecurity, networking, and cloud fundamentals and frameworks such as OWASP, MITRE ATT&CK, NIST, and CIS.
- Experience using and defending Public Cloud services such as AWS, Azure, and GCP (IAM, CI/CD Pipelines, Network Security, DLP).
- Deep understanding of SIEM solutions such as Splunk and LogScale.
- Strong analytical and problem-solving abilities, focused on identifying root causes and assessing risk exposure.
- Exceptional communication skills, capable of explaining technical details to non-technical audiences and building strong stakeholder relationships.
- Self-motivated, able to work autonomously, managing tasks effectively and seeking assistance when necessary.
- Ability to work under pressure in a dynamic environment, prioritizing tasks to meet tight deadlines while maintaining procedural discipline.
- Profound knowledge of digital forensics technologies and methodologies, plus expertise in the Security Incident Response Lifecycle according to frameworks like NIST or SANS.
- Adaptable and proactive, willing to take on various responsibilities and continuously learn and upgrade skills.
Technologies
- Bash, PowerShell, Python
- AWS Security Specialty, GCIH, GCFA, GFCE, CISSP
- AWS, Azure, GCP, IAM, CI/CD Pipelines, Network Security, DLP
- CrowdStrike Falcon, Wiz
- Splunk, LogScale (SIEM), Endpoint Detection and Response, Cloud Security Posture Management
- OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, OWASP, MITRE ATT&CK, NIST, CIS, SANS
- AI coding assistants, AI SOC platforms, frontier AI tools
Compensation and Benefits
- This position may be eligible for a cash bonus, equity rewards, and benefits in accordance with applicable plans and programs.