Mid- Senior Cyber Security Incident Responder

Guaranteed Rate, Inc.Chicago, IllinoisOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.

Job Profile:
Senior Cyber Security Incident Responder

Job Description Summary:

We are committed to providing a competitive and equitable total rewards package. The compensation for this role is designed to attract, retain, and motivate top talent.

The expected base salary range for this position is $130,000 to $150,000

Job Description:

Why Rate is the BEST Place to Work

Rate is one of the nation’s top retail mortgage lenders, delivering a seamless, tech-driven experience that helps customers reach their homeownership and financial goals. Founded in 2000 and based in Chicago, Rate is licensed in all 50 states and D.C. and has helped over 2 million homeowners with a wide range of loan products, competitive rates and personalized service. With 5,000+ employees across 300+ offices and 12+ subsidiaries, Rate’s Loan Officers rank among the best in the country. From purchases and refinances to tapping into equity, Rate makes financing faster, simpler and less stressful. Our technology — including Same Day Mortgage, the Rate App, FlashClose℠, MyAccount and the Language Access Program — has earned recognition from HousingWire, Scotsman Guide, NerdWallet, the Chicago Tribune and Crain’s Chicago Business. Learn more at rate.com.

What Makes Our Team Awesome

We are a gritty group of passionate technologists on a mission to dominate the mortgage world!

The Information Technology Team within Rate passionately and consistently puts our customers first. We are building the latest technology to help create the best mortgage experience on the planet and get your mortgage, your way, anytime, anywhere. Whether that is improving our digital mortgage platform, automating loan coordination and underwriting processes, or building out the latest marketing and customer engagement platform, we’re doing it all. We build high-performing, self-organized, cross-functional agile teams that operate with minimal hierarchy. Information Technology team members hold themselves and others accountable and live and breathe the tenets of autonomy, mastery, and purpose.

What’s the Role?

Every week, somewhere in our environment, something tries to break. A credential gets phished. A mule account starts moving money it shouldn't. An adversary finds a gap between two systems that were never designed to talk to each other. Most people at Rate never see it happen, because a tight, sharp, and relentless team already did. That team is the Risk Operations Center (ROC), and Rate is looking for a mid-to-senior level response engineer who wants to be the one that gets the page, reads the signal that no one else caught, and calls the shots when the room goes quiet and everyone looks at you.

This opportunity is not simply a one-lane job.  You will rotate and flex across five unique, yet overlapping terrains, often in the same week.  You'll work from a real IR plan mapped to NIST CSF 2.0, a growing playbook library, and a team that has already done the hard work of building the scaffolding — you're here to run on it, sharpen it, and push it further.  The five domains are:

- Incident Response — Take incident command on active events. Establish ground truth fast, drive containment and eradication, and own the post-incident review that makes the next one shorter.

- Threat Hunting — Don't wait for the alert. Go looking for what the tooling missed — hypothesis-driven hunts across endpoint, identity, and network telemetry.

- Detection Engineering — Turn every incident and hunt into a new detection. Write, tune, and retire rules; you're building the team's muscle memory into code.

- Threat Intelligence — Track the actors and techniques relevant to financial services. Translate raw intel into detections, playbooks, and briefings people actually use.

- Fraud Investigations — Cross into fraud ops when account takeover, mule activity, or payment fraud overlaps with a security incident — which, in this environment, is often.

Responsibilities

- Mature the cybersecurity incident response program, including preparation, detection, containment, eradication, recovery, and lessons learned.

- Investigate and analyze security events and incidents to determine impact, root cause, and remediation steps.

- Build, update, and maintain incident response runbooks, procedures, and playbooks aligned with evolving threat landscapes.

- Support cross-functional response efforts involving IT, Legal, Compliance, and executive leadership during major cyber incidents.

- Optimize Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), and threat intelligence tooling to reduce detection and response time.

- Serve as an escalation point for high-severity incidents and communicate findings to security leadership clearly and effectively.

- Develop metrics and reporting to measure incident trends, mean time to detect/respond (MTTD/MTTR), and overall program effectiveness.

- Collaborate on training and the development and execution of tabletop exercises to increase incident readiness across the organization.

- Collaborate with engineering teams to continuously strengthen detection and response capabilities.

Qualifications

- 5+ years of hands-on experience in cybersecurity with at least 2 years in a Tier 2/3 Security Operations / Incident Response role.

- Knowledge of cyber threat vectors, malware behavior, APTs, and attacker TTPs (tactics, techniques, and procedures).

- Proficiency with tools and technologies such as SIEM (e.g., Splunk, Sentinel), EDR (e.g., CrowdStrike, Carbon Black), and forensics platforms.

- Strong understanding of incident response frameworks (e.g., NIST, SANS), MITRE ATT&CK, and threat hunting methodologies.

- Experience developing and executing incident response plans, tabletop exercises, and post-incident reviews.

- Familiarity with regulatory frameworks and compliance requirements such as NIST CSF and NYDFS.

- Solid scripting or automation experience using Python, PowerShell, or similar tools is a plus.

- Excellent communication skills to interact with technical teams, business stakeholders, and executive leadership.

- Bachelor’s degree in cybersecurity, information technology, or equivalent experience.

Preferred Certifications:

- GIAC Certified Incident Handler (GCIH)

- GIAC Certified Forensic Analyst (GCFA)

- Certified Information Systems Security Professional (CISSP)

- Certified Ethical Hacker (CEH)

- Certified Information Security Manager (CISM)

Other Useful Details

Employee Type: Full-Time

Pay Range: annual pay + bonus and/or commissions

Location: Remote

Rate Companies is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other any other protected characteristic. #LI-Remote

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits;  well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State:  https://www.rate.com/careers/open-positions/disclosures

Additional Job Description Summary:

Rate is an Equal Opportunity Employer that welcomes and encourages all applicants to apply regardless of age, race, sex, religion, color, national origin, disability, veteran status, sexual orientation, gender identity and/or expression, marital or parental status, ancestry, citizenship status, pregnancy or other reason protected by law.

The company offers a comprehensive benefits program to eligible employees, including eligibility to participate in a company-sponsored 401(k); vacation benefits; eligibility for medical, dental, vision, and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; critical care insurance; personal accidental insurance; commuter benefits; pet insurance; certain time off and leave of absence benefits; well-being benefits (e.g., employee assistance program); and other supplemental benefits (e.g. legal planning assistance; identity theft protection; pet insurance; wellness resources).

Please click this link to learn more about our benefit offerings for Washington State: Benefit Offerings for Washington State