What are the responsibilities and job description for the Security Engineer - Incident Response - up to $190k base plus bonus position at Saragossa?
You are joining a security function that is actively scaling, at a firm where no two days look the same.
This is an investment firm that serves as the technology investment and operations arm of a family office. That means you are not just working internally for one business. You are operating across a portfolio of companies, each with their own systems, infrastructure, and complexity. The exposure here is genuinely broad, covering cloud environments, identity platforms, endpoints, email, and everything in between.
You will be part of a team that is building and strengthening the incident response capability as the function grows. When something happens, you will be hands-on in the investigation: hunting threats, triaging alerts, supporting containment, and helping improve how the team detects and responds. This is not a mature, fully built-out function. It is a place where you can have real influence on how things are done.
Day to day you are working across Azure and AWS environments, digging into identity and endpoint telemetry, writing KQL to surface suspicious activity, and supporting the broader team in triage, investigation, and response. You are also bringing automation and AI into how the team operates, whether that is through security copilots, ML-based detections, or automated triage workflows.
You’ll need hands-on experience with the Microsoft Security ecosystem and confidence applying it in investigations.
This would be a strong next step if you have a background in SecOps or incident response and want more scope, more variety, and a role where you can help shape a growing team.
No up-to-date resume required.