Summary
Bentley Systems provides software that helps infrastructure professionals design, build, and operate resilient infrastructure. The Incident Responder I will monitor and investigate security alerts, validate automated verdicts, contain incidents, and improve detections, playbooks, tooling, and security automation within a 24/7 Security Operations Center.
Responsibilities
- Monitor and respond to alerts and cases from the SIEM, SOAR, endpoint, and cloud security platforms, including the output of automated investigation agents
- Review automated verdicts — malicious, not malicious, inconclusive — and act on them: confirm and close, escalate, or contain within the approved autonomy tier (isolate a host, revoke a session, block an indicator)
- Own the inconclusive queue: investigate what automation could not resolve and document the outcome so the same class of case can be automated next time
- Hand off and receive incidents cleanly across shifts with complete, structured notes; escalate to senior responders and management per the incident response procedure
- Sample automated verdicts for accuracy (false positives and false negatives) and report findings; your sampling doubles as audit evidence for our compliance program
- Tune existing detections and playbooks based on what your shift observed; keep runbooks current
- Watch the health of the tooling the SOC depends on — sensor coverage, connector status, log sources — and raise gaps before they become blind spots
- Contribute to detection-as-code: propose new detections and playbook steps, version them, and test them with a senior engineer
- Learn the behavioral baselines of AI agents operating in our environment and flag abnormal agent activity — a new class of alert this SOC owns
- Take part in post-incident reviews and turn lessons into automation requests for the engineering team
Skills
- 1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration
- Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS)
- A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference
- Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why
- Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system
- Availability for a shift rotation as part of a 24×7 operation
- Requires sitting or standing at will while performing work on a computer
- Applicants must be authorized to work in the U.S. without current or future employer sponsorship
- Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL
- Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM
- Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications
Qualifications
Must Haves
- 1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration
- Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS)
- A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference
- Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why
- Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system
- Availability for a shift rotation as part of a 24×7 operation
- Requires sitting or standing at will while performing work on a computer
- Applicants must be authorized to work in the U.S. without current or future employer sponsorship
Nice to Haves
- Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL
- Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM
- Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications
Benefits
- Hybrid preferred; remote considered
- We fund training and certifications
- Defined career path into detection engineering, security engineering, architecture, or governance