Summary
Rate is a retail mortgage lender providing technology-driven mortgage and homeownership services. The Senior Cyber Security Incident Responder will support the Risk Operations Center by leading incident response, threat hunting, detection engineering, threat intelligence, and fraud investigations. The role focuses on investigating incidents, improving security tooling and response processes, and strengthening organizational readiness.
Responsibilities
- Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned
- Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps
- Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes
- Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents
- Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time
- Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively
- Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness
- Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization
- Collaborate with engineering teams to continuously strengthen detection and response capabilities
Skills
- 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role
- Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures)
- Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms
- Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies
- Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews
- Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS
- Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership
- Bachelor's degree in cybersecurity, information technology, or equivalent experience
- Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Certified Information Security Manager (CISM)
Qualifications
Must Haves
- 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role
- Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures)
- Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms
- Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies
- Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews
- Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS
- Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership
- Bachelor's degree in cybersecurity, information technology, or equivalent experience
Nice to Haves
- Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Certified Information Security Manager (CISM)
Benefits
- Annual pay plus bonus and/or commissions
- Remote work arrangement
- Eligibility to participate in a company-sponsored 401(k)
- Vacation benefits
- Eligibility for medical, dental, vision, and prescription drug benefits
- Flexible benefits, including healthcare and/or dependent day care flexible spending accounts
- Life insurance and death benefits
- Critical care insurance
- Personal accidental insurance
- Commuter benefits
- Pet insurance
- Certain time off and leave of absence benefits
- Well-being benefits, including an employee assistance program
- Legal planning assistance
- Identity theft protection
- Wellness resources