Jobs and Careers
CD

Principal Incident Response and Automation Developer

CDW
Virtual - Illinois, United States, United StatesRemotefull_timeVerifiedPosted 6 Feb 2025
💰 $233,400/yr($143,000/yr$233,400/yr)

About the role

Bring your IT career and talents to CDW, where you can have a greater impact, be inspired by our mission and excited about your career and future. A Fortune 200 leader, we’re the driven professionals and technology experts companies turn to most to solve their IT challenges.

Join CDW and help protect delivery of full stack technology solutions and global services for 250K+ customers—including corporate enterprise, government, education, and healthcare industries. You will be on a team dedicated to collaborative delivery of a new global information\ security strategy, operating model, and objectives to accelerate CDW’s business goals in a secure way.

What you will do: Your role at CDW is of the utmost importance to the company’s mission, objectives, and reputation. As a Principal of Incident Response and Automation Development, you will play a pivotal role in identifying and analyzing cyber threat tactics, techniques, and procedures—ensuring proactive detection capabilities by leveraging automation to aid the global threat detection and response mission. Your responsibilities include four parts:

Key Areas of Responsibilities

Threat Detection and Response

  • Develop incident response methodologies to triage cybersecurity events and incidents for other members of a growing team
  • Collaborate with other coworkers and teams to develop and deploy cybersecurity countermeasures during cybersecurity events and incidents.
  • Perform post event and incident analysis to prevent re-occurrence.
  • Perform after action analysis to identify areas and opportunities of improvement to reduce the chance or impact of future events and incidents.
  • Build/Define and standardize procedures and processes for triage methods.

Automation Development

  • Lead the integration of current technologies with SIEM and SOAR platforms.
  • Design and implement the architecture and analysis efforts related to incident response automation.
  • Develop automation playbooks using out-of-the-box or custom integrations and functions.
  • Develop custom integrations and automation using scripting languages such as Python and/or PowerShell.
  • Lead automation use case/playbook design sessions.
  • Troubleshoot issues related to automation processes or tools.
  • Develop documentation related to automation processes and procedures.

Proactive Threat Detection Engineering

  • Develop threat detection rules and use cases based on the latest threat intelligence and operational changes within CDW’s global technology ecosystem.
  • Collaborate with cybersecurity coworkers to develop and implement effective defensive strategies against current and emerging threats.
  • Provide technical guidance and mentorship to junior team members.
  • Drive and guide purple team exercises to help test and improve detection capabilities.
  • Develop and monitor metrics and key performance indicators to measure the effectiveness of the threat detection program.

Threat Hunting

  • Build and execute regular threat hunting campaigns focused on current, emerging, and obscure tactics, techniques, and procedures.
  • Proactively search for, identify, and analyze new and existing techniques to detect advanced and targeted threats.
  • Utilize advanced threat hunting techniques to detect anomalies and suspicious activities that may indicate a compromise.
  • Develop and maintain threat hunting playbooks, procedures, and best practices to enhance the efficiency and effectiveness of the threat hunting program.
  • Collaborate with other cybersecurity professionals, including CDW’s Cybersecurity Services team to scale threat hunting outcomes and insights.

What we expect of you:

Who you are:

  • You thrive on making an impact—for your team, your company, and the industry.
  • You are extremely hands-on with a passion for technology.
  • You do not accept the status-quo, and always strive to improve.
  • You are eager to learn and seek professional development continuously.
  • You are resourceful, open-minded, analytical and enjoy solving complex problems.
  • You are diligent and self-motivated.

What we are looking for:

  • Bachelor’s Degree and 10 years of experience within Information Security, or 14 years of experience within Information Security.
  • Strong understanding of advanced threat hunting techniques, including the use of EDR tools, network traffic analysis, and other techniques.
  • Experience developing cybersecurity platforms using CI/CD tools and practices.
  • Experience with threat intelligence platforms, SIEM, and other cybersecurity tools and technologies such as the following:

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CDW

View company profile →