Verified today
Engineer III Cyber Incident Response
About the role
The Engineer III, Cyber Incident Response is a senior technical role within Cencora's Security Operations Center (SOC) responsible for leading complex incident investigations and supporting the continuous improvement of detection and response capabilities. Day-to-day work includes investigating advanced threats, performing forensic analysis across endpoints, networks, and cloud environments, developing incident response playbooks, mentoring junior analysts, and collaborating with global cyber defense teams. This full-time position is based in Pune, India and is remote.
What you’ll do
- Lead the investigation and resolution of complex security incidents, including advanced persistent threats, ransomware, phishing campaigns, and insider activities
- Perform forensic analysis across endpoints, networks, and cloud environments to identify root causes and scope of compromise
- Develop and enhance incident response playbooks, runbooks, and detection use cases
- Collaborate with threat intelligence, vulnerability management, and countermeasures teams to strengthen defenses
- Escalate high-severity incidents to senior leadership and provide clear, actionable reporting
- Act as a technical escalation point for Engineer I/II analysts during incident investigations
- Contribute to red team and purple team exercises to validate and improve response capabilities
- Participate in after-action reviews and lessons-learned sessions to improve SOC processes
What you’ll bring
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience required
- 7+ years of progressive experience in cybersecurity, with at least 4 years in incident response or SOC operations
- 4+ years of experience in incident response, digital forensics, or advanced threat hunting
- Hands-on experience with SIEM, EDR, SOAR, and forensic tools such as Splunk, CrowdStrike, EnCase, and Wireshark
- Strong knowledge of incident response methodologies, digital forensics, and adversary tactics
- Familiarity with security frameworks such as NIST, MITRE ATT&CK, and ISO 27035
- Demonstrated success in mentoring junior analysts and improving SOC processes
- Strong written and verbal communication skills with the ability to document and present technical findings clearly
Nice to have
- Master's degree preferred
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Ethical Hacker (CEH)
- Certified Information Systems Security Professional (CISSP)
- Relevant industry certifications such as GCFA, GCIH, or CISSP preferred
Skills
Education
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent work experience; Master’s degree preferred.