Jobs and Careers
SA

Senior Incident Response Specialist

SAP
Newtown Square, PA, US, 19073, United Statesfull_timeVerifiedPosted 9 Jun 2025
💰 $227,500/yr($147,805/yr$227,500/yr)

About the role

Requisition ID: 429203
Work Area: Information Technology
Expected Travel: 0%
Career Status: Professional
Employment Type: Regular Full Time
Career Level: T3-2

Original Posting Date: 06/09/2025 

 

Job Title: Senior Incident Response Specialist 

Location: Newtown Square, PA 

Work Model: Hybrid work model 

 

Purpose and Objective:   

SAP America, Inc. seeks a Senior Incident Response Specialist at our Newtown Square, PA location to triage security alerts detected by Enterprise Detection and SIEM, analyzing all available data to determine if a cyber-attack is occurring, scoping the extent of a suspected attack, coordinating efforts to contain attacks, and providing guidance on remediation actions.  

 

Expectations and Tasks:  

Perform Incident Response Tier III duties as a part of a 24/7 cyber incident response team. Leverage SAP’s security tools to monitor, triage, and respond to security event alerts. Communicate updates to stakeholders both within and outside security. Perform forensic analysis and present evidence to stakeholders. Observe proper evidence custody and control procedures; document procedures and findings suitable for courtroom presentation. Partner with SAP groups to review monitoring requirements and create detection alerts. Develop automated workflows that will reduce response times. Develop and implement intrusion remediation and strategy. Perform additional analysis of escalations from junior Incident Response Analysts and conduct case review. Conduct proactive Cyber Hunting exercises based on threat intelligence from Response Analysts. Provide onboarding training and coaching to junior Incident Response Analysts. Collect intrusion artifacts and use discovered data to enable mitigation of potential cyber defense incidents within the enterprise. Conduct digital evidence analysis and gather evidence against network and host-based intrusions. Identify and document case relevant file-system artifacts, including browser histories, account usage, and USB histories. Ensure communication and escalation of security activities to leadership and senior-level team members. Provide guidance in developing incident handling processes, standard operating procedures, playbooks, and runbooks. Monitor and review incident response tools, procedures, and workflows, to develop strategy to increase efficiency and reduce response time.  

 

Education and Occupational Experience:  

Bachelor’s degree or foreign equivalent in Computer Science, Mathematics, Engineering, or a related field of study and six (6) years of progressive post-baccalaureate experience in the job offered or related occupation. Alternatively, a Master’s degree or foreign equivalent in Computer Science, Mathematics, Engineering, or a related field of study and four (4) years of experience in the job offered or related occupation. 

 

Qualifications/Skills and Competencies Experience:  

Experience must involve four (4) years in the following: 

  • RSA SA, Cellbrite, and Open source digital forensics; 

  • SNOW and RSA eCat; 

  • Network Security, Intrusion Detection and Prevention, Netwitness implementation and design, and forensics;  

  • Operate system installation, patching, and configuration in Windows, Linux and OSX; 

  • Security Management and Incident Response operations, including Analysis and Reverse engineering, and forensics;  

  • Automate full forensics capture and triage collection; and 

  • Programming languages including, C++, Assembly, Scripting, or Python. 

 

Travel: N/A 

 

This position is eligible for the Employee Referral Program subject to the eligibility criteria outlined in the

Company

SAP

View company profile →