- Company Name
- Rockstar Games
- Job Title
- Security Engineer, DFIR
- Job Description
-
**Job Title**
Security Engineer, DFIR
**Role Summary**
Lead incident response and digital forensics across a global organization, prioritizing complex security events, preserving evidence, and advising stakeholders to safeguard information systems and intellectual property.
**Expectations**
- 3+ years in incident response, digital forensics, or penetration testing across systems, networks, and cloud services.
- Full incident‑response lifecycle ownership, with proven analytical and containment skills.
- Ability to process large data sets, script in a modern language, and adapt rapidly to shifting priorities.
- Strong written and verbal communication; cross‑functional collaboration with technical and business teams.
**Key Responsibilities**
- Detect and respond to emerging threats; investigate, preserve, and analyze digital evidence.
- Conduct threat hunting for anomalies and indicators of compromise.
- Support incident readiness, response, and post‑incident recovery.
- Leverage large‑scale data platforms (Splunk, Elastic, Databricks, etc.) to support operations.
- Utilize EDR solutions to detect and mitigate endpoint threats.
- Advise business units and stakeholders on security recommendations.
- Track industry trends, evolving threat landscapes, and refine response playbooks.
**Required Skills**
- Incident response, digital forensics, or penetration testing experience across networking, applications, OS, and virtualization.
- Proficient in log analysis, anomaly detection, threat containment, and response prioritization.
- Experience with endpoint detection & response platforms.
- Familiarity with data analytics platforms (Splunk, Elastic, Databricks, etc.).
- Cloud platform knowledge: AWS, Azure, or GCP.
- Coding/scripting in Python, Java, Go, Rust, or similar.
- Excellent written and verbal communication; ability to manage rapid priority shifts.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
- Preferred certifications: GCFA, CASP+, SEC+, CISSP, OSCP, or equivalent.
- Experience with the MITRE ATT&CK framework is a plus.
- Background in gaming, media, or related industries is desirable.