Senior Incident Responder

DocuSign
Sydney, India, Australia
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringSkills: ["Analytical","Problem-solving","Communication","Mentoring","Work independently"]

Join the CSIRT team as an individual contributor in the “Detect & Respond” function, triaging and investigating security incidents from SOC alerts. You’ll leverage AI/ML to enhance log analysis, alert triage, and threat hunting, and collaborate with detection engineering to tune AI-based detections. Conduct investigations using SIEM/SOAR and digital forensics techniques, support containment/eradication/recovery, and document post-incident findings and lessons learned.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
DocuSign
DocuSign
1 day ago

Senior Incident Responder

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 12 hours agoStatus: Live

Job Summary

Join the CSIRT team as an individual contributor in the “Detect & Respond” function, triaging and investigating security incidents from SOC alerts. You’ll leverage AI/ML to enhance log analysis, alert triage, and threat hunting, and collaborate with detection engineering to tune AI-based detections. Conduct investigations using SIEM/SOAR and digital forensics techniques, support containment/eradication/recovery, and document post-incident findings and lessons learned.
Location: Sydney, India, Australia
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Leverage AI and machine learning tools to improve log analysis, alert triage, and threat hunting efficiency.
  • •Monitor, investigate, and triage security incidents involving AI/ML models (e.g., adversarial attacks, prompt injection, model evasion).
  • •Correlate events from multiple log sources, determine threat scope/severity/impact, and perform malware/phishing/web compromise/insider threat investigations.
  • •Use SIEM and SOAR platforms to optimize alert processing and incident workflows, and identify automation opportunities to streamline security operations.
  • •Support incident containment, eradication, and recovery, and document incident findings, actions, and post-incident reports/lessons learned.

Key Requirements

  • •8+ years of hands-on cybersecurity experience focused on Security Operations (SOC) and/or Incident Response.
  • •Strong understanding of incident response lifecycles, security best practices, and cybersecurity principles.
  • •Experience with SIEM tools (e.g., Splunk, QRadar, Sentinel) for alert analysis and log correlation.
  • •Working knowledge of EDR and digital forensics principles/techniques for investigations.
  • •Familiarity with scripting (Python, PowerShell, Bash) and the MITRE ATT&CK framework, including AI-driven security threats and model evasion.
Experience:CybersecuritySOCIncident responseSIEMSOARDigital forensics
Skills:AnalyticalProblem-solvingCommunicationMentoringWork independently
Certifications:GCFAGCEDGCIHGCIACISSPCISM
Tech Stack:AIMachine learningSIEMSOARSplunkQRadarSentinelEDRDigital forensicsPythonPowerShellBashMITRE ATT&CKMITRE ATLASOWASP Top 10 for LLMsAdversarial attacksPrompt injectionModel evasionIAMContainer security

Company Brief

DocuSign
Provides a cloud-based electronic signature and intelligent agreement management platform that automates document workflows, identity verification, contract lifecycle management, and agreement analytics for enterprises and individuals worldwide.
Industry: LegalTech
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2003
Glassdoor
Glassdoor: 3.6
WebsiteLinkedInGlassdoor