← Back to results

incident-response jobs in San Diego

Posted 1 month ago

Build and test agent behavior for an AI-driven service, including test case design and evaluation checks distinct from traditional software testing. Support data ingestion pipelines using AWS and BigData tools (PySpark, Airflow), collaborate with product and senior engineers to ship features, and contribute to production support (monitoring, alerting, incident response).… Requires 1–2 years of software engineering experience, a Master's in Computer Science or related field, proficiency in Python or another backend language, SQL/NoSQL fundamentals, basic REST API design, and hands-on experience with at least one LLM project (tool calling, chaining, retrieval, or multi-step coordination). Self-directed learner excited about AI tooling and focused on shipping end-to-end products.

San DiegoLast seen 1 month ago
$250,000 – $250,000 · Posted 1 month ago

The CISO will develop and execute a firm-wide security strategy encompassing cybersecurity, data protection, and operational resilience, establishing governance frameworks aligned with industry standards like NIST, ISO, and SOC 2. The role requires leading threat detection, incident response, digital forensics, and vulnerability management while protecting client confidentiality and attorney-client privilege through robust technical and procedural controls.… The candidate must ensure secure architecture across cloud, on-premise, and hybrid environments and drive compliance with data protection and privacy regulations including GDPR, CCPA, and HIPAA. This is a senior executive position requiring 8+ years of cybersecurity experience and 6+ years in a senior leadership role managing global security programs.

San DiegoLast seen 1 month ago
$117,000 – $130,000 · Posted 1 month ago

The Cybersecurity Analyst owns Bumble Bee's day-to-day security operations, investigating and responding to incidents, hunting threats, and tuning detection tooling to close coverage gaps. Responsibilities include managing the full incident response lifecycle, optimizing SIEM platforms, conducting vulnerability assessments, performing access control audits, and building incident response playbooks and procedures.… The role requires 4+ years of cybersecurity experience, proficiency with SIEM platforms, EDR tools, vulnerability management platforms, and hands-on knowledge of Windows/Linux, networking, and the MITRE ATT&CK framework. Success demands both technical operations expertise and cross-functional collaboration to strengthen security posture, ensure compliance, and assess third-party cyber risk.

San DiegoLast seen 1 month ago
$120,001 – $160,000 · Posted 1 month ago

Software Integration Engineer responsible for designing, developing, and deploying a hybrid container/virtualization platform-as-code solution supporting enterprise-scale workloads across on-prem and cloud environments. The role involves integrating core platform services (identity, PKI, DNS, logging, monitoring, secrets management), configuring container runtimes and networking, and developing infrastructure-as-code automation.… Requires 9+ years of experience (or equivalent with advanced degree) with cloud platforms, Kubernetes, virtualization, DevSecOps practices, CI/CD tooling, and automation frameworks, plus the ability to mentor junior engineers and collaborate across security, platform, and application teams on compliance, incident response, and AI/ML workload enablement.

San DiegoLast seen 1 month ago
$184,600 – $277,000 · Posted 1 month ago

Lead multiple engineering teams building social experiences on the PlayStation platform, translating product objectives into technical plans across client applications, APIs, distributed services, and cloud infrastructure. Establish standards for software design, testing, deployment, and operations while managing 24/7/365 service reliability, incident response, and observability.… Coach engineers across career stages, partner cross-functionally with Product, Design, Data, and Security leaders, and evaluate responsible AI integration across development, testing, and customer-facing capabilities.

San DiegoLast seen 1 month ago
$198,500 – $297,700 · Posted 1 month ago

Lead the design, development, and operation of Qualcomm's enterprise AI platform, supporting agentic AI, model lifecycle management, and multi-cloud ML/inference infrastructure. Own core platform services including identity/RBAC, secrets, service meshes, observability, vector stores, and model gateways across on-prem GPU clusters and managed cloud services.… Manage a ~10-engineer global team (platform, SRE, MLOps/LLMOps), drive incident response and continuous improvement, and partner with product and security teams on AI governance and high-impact use cases.

San DiegoLast seen 18 days ago
$158,400 – $237,600 · Posted 1 month ago

Design, build, and maintain scalable batch and streaming data pipelines on AWS and Databricks, developing reusable data engineering frameworks and standardized patterns for ingestion, transformation, and validation. Leverage AI-based techniques to automate data quality checks, anomaly detection, and pipeline self-healing.… Define SLIs/SLOs, participate in on-call rotations, and mentor junior engineers while driving adoption of data frameworks and best practices across analytics, reporting, and AI/ML teams.

San DiegoLast seen 17 days ago
$115,000 – $200,000 · Posted 1 month ago

Conduct software security assessments, vulnerability testing, penetration testing, and threat analysis on TrellisWare products. Perform static and dynamic analysis, reverse engineering, and incident investigation while ensuring compliance with FIPS 140, NIST STIG, and other regulatory standards.… Requires 5+ years industry experience with 3+ years software development and 2+ years vulnerability testing, proficiency in Python/C++/Java, and at least one security certification (Security+, CISSP, OSCP, or SANS/GIAC).

San DiegoLast seen 18 days ago
Posted 1 month ago

DevOps Engineer to build, maintain, and optimize AWS cloud infrastructure and CI/CD deployment systems, working with ECS, EKS, and EC2 workloads. The role requires hands-on experience with Infrastructure as Code (Terraform), containerization (Docker/Kubernetes), monitoring tools (Grafana), and CI/CD pipelines, with growing ownership of services and systems.… You'll troubleshoot infrastructure and application issues, collaborate with engineering teams on deployment workflows, and apply AI tooling to improve infrastructure automation and operational efficiency. The position reports to a DevOps Manager and is based in San Diego on a hybrid schedule.

San DiegoLast seen 18 days ago
$120,001 – $160,000 · Posted 1 month ago

Design, develop, and deploy a hybrid container/virtualization platform serving enterprise workloads across on-prem and cloud environments. Integrate core platform services (identity, PKI, DNS, logging, monitoring, secrets management) and support GPU-enabled AI/ML workloads.… Establish CI/CD pipelines, Infrastructure-as-Code automation, and standard operating procedures for configuration management, verification, and patch management. Lead cross-functional teams on containerization, DevSecOps, incident response, and ATO compliance efforts.

San DiegoLast seen 1 month ago
Posted 1 month ago

This role designs and implements cybersecurity architecture for complex electromagnetic and power systems across defense, space, and commercial programs. The Cybersecurity Architect develops secure network and system architectures aligned to NIST, DoD, and customer standards; performs vulnerability assessments and risk management; and serves as a technical liaison between security, hardware, software, and program teams.… The position requires deep expertise in cyber standards (NIST SP 800-53, NIST SP 800-171, DODI 8500.02, CNSSI 1253), secure system design, and incident response, plus the ability to communicate complex security issues and remediation strategies across all organizational levels.

San DiegoLast seen 1 month ago
$73,700 – $128,780 · Posted 1 month ago

This role combines incident response, forensic analysis, and security operations responsibilities, requiring hands-on experience with cybersecurity tools, patch management, and security system optimization. The analyst will develop automation scripts (Python, PowerShell, Bash), manage firewalls and VPN systems, leverage network observability and security telemetry for threat detection, and support incident response workflows.… The position demands 2–5 years of progressive cybersecurity experience, intermediate certifications (GSEC, CEH, CySA+), and familiarity with NGFW technologies, cloud platforms (AWS, Azure), and security frameworks.

San DiegoLast seen 1 month ago
$120,001 – $160,000 · Posted 1 month ago

Design, develop, and deploy a hybrid container/virtualization platform supporting enterprise-scale workloads across on-prem and cloud environments. Own infrastructure automation, CI/CD integration, monitoring, security compliance, and platform service integration (identity, PKI, logging, secrets management).… Collaborate with cross-functional teams on incident response, vulnerability remediation, and mentorship of junior engineers in cloud-native and containerization best practices.

San DiegoLast seen 1 month ago
$183,500 – $232,500 · Posted 1 month ago

Senior Staff Software Engineer owning end-to-end design, architecture, and delivery of a scalable AWS-based cloud platform integrating backend services, frontend applications, mobile clients, and IoT hardware. You'll make high-stakes architectural decisions independently, write production code across Node.js, React, React Native, Python, Rust, and C++, design infrastructure-as-code with AWS CDK, and work with PostgreSQL at depth.… Operating in a flat, autonomous team with no management hierarchy, you'll set engineering standards, drive technical direction, and operate critical systems from design through production support.

San DiegoLast seen 1 month ago
Posted 1 month ago

Principal Systems Administrator role managing enterprise Windows Server and Linux environments, including Active Directory, virtualization (VMware/Horizon), cloud identity (Azure AD), and endpoint security. Requires 7+ years of systems administration experience, CompTIA Security+ certification or DoD 8570 IAT Level II equivalent, and ability to obtain a US Secret clearance.… The role combines hands-on administration with mentorship, technical documentation, and Tier 1–2 escalation support, including automation via PowerShell, Bash, or Python.

San DiegoLast seen 20 days ago
Posted 1 month ago

Security Operations Analyst role monitoring and triaging alerts across endpoint, cloud, identity, network, and SaaS using enterprise SIEM and XDR platforms. Responsibilities include investigating alerts, performing root-cause analysis, tuning detections, owning initial response for mid-tier incidents, participating in on-call rotation, running targeted threat hunts, and contributing to playbooks and post-incident reviews.… Requires 2–5 years of hands-on SecOps, SOC, or incident response experience; proficiency with enterprise SIEM query languages, EDR tooling, and scripting in Python/PowerShell/Bash; and solid understanding of MITRE ATT&CK and network fundamentals.

San DiegoLast seen 1 month ago
Posted 1 month ago

The Cybersecurity Engineer III will support Assessment and Authorization (A&A) accreditation efforts under the NIWC PAC contract, maintaining cybersecurity monitoring operations, performing incident triage, identifying vulnerabilities, and recommending remediation strategies. Responsibilities include testing and applying security controls, conducting reconnaissance, authoring Plans of Milestones and Actions (POA&Ms), and developing A&A documentation such as System Security Plans (SSP) and Security Assessment Reports (SARs).… The role requires in-depth knowledge of the Risk Management Framework, eMASS workflow, DISA compliance, and security categorization overlays. A minimum of 10+ years of cybersecurity or incident response experience is required, along with security certifications such as CISSP, CASP, CISM, CAP, or GSLC.

San DiegoLast seen 1 month ago
$150,000 – $200,000 · Posted 1 month ago

Staff-level database engineer responsible for managing production database environments across MySQL, ClickHouse, and MongoDB at scale. The role demands independent execution, proactive monitoring, performance optimization through query tuning and indexing, and 24/7 on-call incident response.… Requires 4+ years of MySQL and cloud platform experience (Azure/AWS), strong Linux expertise, and scripting proficiency (Golang preferred); nice-to-have skills include AI tooling integration (LangChain, LlamaIndex), vector databases, and RAG for automating database operations.

San DiegoLast seen 19 days ago
$68,640 – $76,960 · Posted 1 month ago

Technical Lead responsible for managing IT support operations, incident response, and data assurance on classified networks (NIPR/SIPR). Lead peer coaching and mentorship of standard technicians while managing ticket resolution, troubleshooting hardware/software/networking issues, and supporting VoIP/VTC systems.… Provide 24/7 operational support with independent decision-making on technical problems and customer escalations.

San DiegoLast seen 1 month ago
Posted 1 month ago

Lead technical administration of ONI's Microsoft environment, including Microsoft 365, Microsoft Entra ID, SSO, and endpoint management across mixed Windows, macOS, and iOS devices. Own the full IT asset lifecycle from procurement through retirement, manage user identity and access controls with security best practices, and drive IT projects and process improvements.… Serve as senior technical escalation point for complex issues, maintain business continuity procedures, and coordinate with vendors and internal stakeholders on security compliance (GDPR, Cyber Essentials, ISO 27001) and incident response.

San DiegoLast seen 1 month ago
$83,527 – $119,480 · Posted 1 month ago

The Information System Security Officer (ISSO) serves as a steward of classified and high-side information systems, ensuring security compliance and operational resilience in accordance with DoD and DCSA standards. The role involves executing Risk Management Framework (RMF) activities, pursuing Authorization to Operate (ATO) via eMASS, conducting vulnerability scanning with tools like Nessus, and maintaining compliance with NISP and federal requirements.… Responsibilities include hands-on system administration, security monitoring, patch management, data transfer operations, and collaborative work with industrial security teams to integrate technical and administrative controls. Success requires proven experience processing ATO packages, system administration skills, security compliance knowledge, and the ability to balance rigorous security controls with operational effectiveness.

San DiegoLast seen 1 month ago
Posted 1 month ago

The Cybersecurity Engineer III will support Risk Management Framework (RMF) activities, Assessment & Authorization (A&A) processes, and continuous monitoring for DoD accredited systems. Responsibilities include developing and maintaining security documentation (SSPs, SAPs, SARs, POA&Ms), performing vulnerability assessments, managing eMASS tasking, and conducting security control validation and testing.… The role requires 10+ years in cybersecurity, RMF compliance, or incident response; expertise with eMASS, DISA STIGs, and vulnerability assessment tools; and an active Secret clearance with DoD 8570/8140 IAT Level III certification (CASP+, CCNP Security, CISA, CISSP, GCED, or GCIH).

San DiegoLast seen 1 month ago
$180,000 – $270,000 · Posted 1 month ago

Senior Staff Product Security Engineer responsible for security incident response, vulnerability detection and mitigation across Qualcomm products, particularly in mobile, IoT, and automotive domains. The role involves binary analysis and reverse engineering of exploits, secure code review, vulnerability assessment, security testing, and coordinating with external security researchers and customers on patch adoption and disclosure.… Requires 6+ years of security engineering experience with expertise in at least two areas such as binary analysis, incident response, fuzzing, malware analysis, embedded firmware security, or automotive security. Must work independently, evaluate new security tools and technologies, and communicate technical findings internally and externally.

San DiegoLast seen 1 month ago
$113,200 – $141,500 · Posted 1 month ago

This Cybersecurity Manager role owns vulnerability and exposure management, leads penetration testing, threat hunting, and threat intelligence programs. The position integrates AI and machine learning into security operations to enhance threat detection and anomaly identification, manages security tools and incident response, and ensures the security of AI/ML systems across the enterprise.… The candidate will develop automation scripts and SOAR workflows, conduct forensic investigations, and drive continuous improvement in the security posture. Required qualifications include 5+ years of cybersecurity experience, a relevant bachelor's degree, and an industry-recognized certification (Security+, SSCP, CCNP Security, CISSP, or equivalent).

San DiegoLast seen 1 month ago
$100,000 – $200,000 · Posted 1 month ago

Design and implement security strategies for Abbott's cloud-based applications and medical devices, including hardening, incident response, penetration testing, and disaster recovery. Apply expertise in user authentication, certificate management, digital signatures, and cloud security architecture while ensuring compliance with ISO, FDA, and regulatory standards.… Leverage AI-assisted development tools and cybersecurity platforms to automate vulnerability analysis, evidence collection, and remediation tracking. Conduct hands-on web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, and vulnerability scanning tools, with demonstrated experience in product security and medical device environments preferred.

San DiegoLast seen 1 month ago