Skip to content

Open nowPosted 9 days ago

Mid- Senior Cyber Security Incident Responder

Rate8 open roles

Pay
$130,000 – $150,000 a year
Where
GRI - IL - Chicago - 3940 N Ravenswood
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowMid- Senior Cyber Security Incident ResponderRate · GRI - IL - Chicago - 3940 N Ravenswood
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Rate's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Rate postings stay open a median of 6 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 9 days ago

Rate median: 6 days open

The posting

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.

Job Profile:

Senior Cyber Security Incident Responder

Job Description Summary:

We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.

The expected base salary range for this position is $130,000 to $150,000

Job Description:

Why Rate is the BEST Place to Work

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.

What Makes Our Team Awesome

We are a gritty group of passionate technologists on a mission to dominate the mortgage world!

The Information Technology Team within Rate passionately and consistently puts our customers first. We are building the latest technology to help create the best mortgage experience on the planet and get your mortgage, your way, anytime, anywhere. Whether that is improving our digital mortgage platform, automating loan coordination and underwriting processes, or building out the latest marketing and customer engagement platform, we’re doing it all. We build high-performing, self-organized, cross-functional agile teams that operate with minimal hierarchy. Information Technology team members hold themselves and others accountable and live and breathe the tenets of autonomy, mastery, and purpose.

What’s the Role?

Every week, somewhere in our environment, something tries to break. A credential gets phished. A mule account starts moving money it shouldn't. An adversary finds a gap between two systems that were never designed to talk to each other. Most people at Rate never see it happen, because a tight, sharp, and relentless team already did. That team is the Risk Operations Center (ROC), and Rate is looking for a mid-to-senior level response engineer who wants to be the one that gets the page, reads the signal that no one else caught, and calls the shots when the room goes quiet and everyone looks at you.

This opportunity is not simply a one-lane job. You will rotate and flex across five unique, yet overlapping terrains, often in the same week. You'll work from a real IR plan mapped to NIST CSF 2.0, a growing playbook library, and a team that has already done the hard work of building the scaffolding — you're here to run on it, sharpen it, and push it further. The five domains are:

  • Incident Response — Take incident command on active events. Establish ground truth fast, drive containment and eradication, and own the post-incident review that makes the next one shorter.
  • Threat Hunting — Don't wait for the alert. Go looking for what the tooling missed — hypothesis-driven hunts across endpoint, identity, and network telemetry.
  • Detection Engineering — Turn every incident and hunt into a new detection. Write, tune, and retire rules; you're building the team's muscle memory into code.
  • Threat Intelligence — Track the actors and techniques relevant to financial services. Translate raw intel into detections, playbooks, and briefings people actually use.
  • Fraud Investigations — Cross into fraud ops when account takeover, mule activity, or payment fraud overlaps with a security incident — which, in this environment, is often.

Responsibilities

  • Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned.
  • Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps.
  • Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes.
  • Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents.
  • Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time.
  • Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively.
  • Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness.
  • Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization.
  • Collaborate with engineering teams to continuously strengthen detection and response capabilities.

Qualifications

  • 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role.
  • Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures).
  • Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms.
  • Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies.
  • Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews.
  • Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS.
  • Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus.
  • Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership.
  • Bachelor’s degree in cybersecurity, information technology, or equivalent experience.

Preferred Certifications:

  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Ethical Hacker (CEH)
  • Certified Information Security Manager (CISM)

Other Useful Details

Employee Type: Full-Time

Pay Range: annual pay + bonus and/or commissions

Location: Remote

Rate Companies is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other any other protected characteristic. #LI-Remote

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State: https://www.rate.com/careers/open-positions/disclosures

Additional Job Description Summary:

Rate is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other reason protected by law.

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State: Benefit Offerings for Washington State

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Rate's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Rate's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Rate's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.