Bentley Systems logo

Incident Responder I — Detection & Automation Oversight

Bentley Systems

Philadelphia, US PHILADELPHIA OLD CITY OFFICE · HybridFull-timeSeen todaySeen in employer's feed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Philadelphia, US PHILADELPHIA OLD CITY OFFICEHybrid
Schedule
Full-time
Work Authorization
US work authorization required

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Bentley’s Information Security team seeks an Incident Responder I to verify automated alerts, own case handling, and improve detections. The role blends monitoring, investigation, and playbook tuning within a hybrid Philadelphia setting, offering a path toward detection and security engineering.

Skills & qualifications

RequiredNice to have

Skills

Alert MonitoringSIEMSOAREndpoint SecurityCloud Security PlatformsOperating SystemsAuthentication ProtocolsNetwork ProtocolsEmail SystemsCloud Service ModelsMITRE ATT&CK FrameworkAutomationShift RotationPythonPowerShellKQLSPLCrowdStrike FalconWizMicrosoft SentinelSecurity+CySA+CuriosityDocumentation

Qualifications

1–2 Years Education or Equivalent ExperienceWorking Knowledge of Operating Systems, Authentication Protocols, Network Protocols, Email Systems, Cloud Service ModelsBasic Understanding of Cyberattacks and Threats Using MITRE ATT&CKComfort Working With AutomationShift Rotation Availability 24×7Authorized to Work in U.S. Without Sponsorship

Full job description

Hybrid

US Philadelphia Old City Office

Full time

RC110

Location: Hybrid - Philadelphia, PA preferred. Home-based arrangements will be considered for exceptional candidates where business needs permit.

Position Summary:

Bentley’s Information Security team is building a security operation where automation does the first pass and people do the judgment. Automated investigation agents already triage most of our alerts, investigate cloud risks, and test our own defenses around the clock. What they cannot do is decide whether they were right, handle the cases they could not resolve, or make the next detection better.

As an Incident Responder I, you join the Security Operations Center at the point where an alert becomes a decision. You will verify what automation concluded, own the cases it hands back, take containment actions within clearly defined limits, and feed what you learn back into detections and playbooks. You will work with modern tooling — CrowdStrike, Wiz, a cloud-native SIEM and SOAR platform — across a global engineering and SaaS environment spanning three public clouds.

This is an entry point, not a destination. The role is designed so that the share of your time spent on routine response falls as your share of engineering and improvement work grows, and it sits on a defined career path into detection engineering, security engineering, architecture, or governance.

Responsibilities:

Keep us safe today

  • Monitor and respond to alerts and cases from the SIEM, SOAR, endpoint, and cloud security platforms, including the output of automated investigation agents.

  • Review automated verdicts — malicious, not malicious, inconclusive — and act on them: confirm and close, escalate, or contain within the approved autonomy tier (isolate a host, revoke a session, block an indicator).

  • Own the inconclusive queue: investigate what automation could not resolve and document the outcome so the same class of case can be automated next time.

  • Hand off and receive incidents cleanly across shifts with complete, structured notes; escalate to senior responders and management per the incident response procedure.

Sharpen what we have

  • Sample automated verdicts for accuracy (false positives and false negatives) and report findings; your sampling doubles as audit evidence for our compliance program.

  • Tune existing detections and playbooks based on what your shift observed; keep runbooks current.

  • Watch the health of the tooling the SOC depends on — sensor coverage, connector status, log sources — and raise gaps before they become blind spots.

Help build what’s next

  • Contribute to detection-as-code: propose new detections and playbook steps, version them, and test them with a senior engineer.

  • Learn the behavioral baselines of AI agents operating in our environment and flag abnormal agent activity — a new class of alert this SOC owns.

  • Take part in post-incident reviews and turn lessons into automation requests for the engineering team.

Qualifications:

  • 1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration.

  • Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS).

  • A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference.

  • Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why.

  • Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system.

  • Availability for a shift rotation as part of a 24×7 operation.

  • This is a full-time role expected to work 40 hours per week, based in the USA and does not require travel.

  • Requires sitting or standing at will while performing work on a computer.

  • Applicants must be authorized to work in the U.S. without current or future employer sponsorship.

Preferred Qualifications:

  • Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL.

  • Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM.

  • Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications.

#LI-MG1

#LI-REMOTE

#LI-HYBRID

This is a Hybrid role.

What We Offer:

  • Step into a collaborative work environment where ideas flourish, and teamwork propels us forward towards shared success.

  • An attractive salary and benefits package.

  • Bentley Impact Day: take a day off from work to volunteer with an organization of your choice.

  • Celebrate milestone achievements and moments that matter through our colleague recognition award programs and our Bentley Achievers platform.

  • A commitment to inclusion, belonging and colleague wellbeing through global initiatives and resource groups.

  • Be part of a company committed to making a real difference by advancing the world’s infrastructure for better quality of life, where your contributions help build a more sustainable, connected, and resilient world. Discover our latest user success stories for an insight into our global impact.

Who We Are:

Bentley Systems (Nasdaq: BSY) is the infrastructure engineering software company. We provide innovative software to advance the world’s infrastructure – sustaining both the global economy and environment. Our industry-leading software solutions are used by professionals, and organizations of every size, for the design, construction, and operations of roads and bridges, rail and transit, water and wastewater, public works and utilities, buildings and campuses, mining, and industrial facilities. Our offerings, powered by the iTwin Platform for infrastructure digital twins, include MicroStation and Bentley Open applications for modeling and simulation, Seequent’s software for geoprofessionals, and Bentley Infrastructure Cloud encompassing ProjectWise for project delivery, SYNCHRO for construction management, and AssetWise for asset operations. Bentley Systems’ 5,200 colleagues generate annual revenues of more than $1 billion in 194 countries.

Equal Opportunity Employer:

Bentley is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, sex, sexual orientation, gender identity, disability, pregnancy, protected veteran status, religion, national origin, age, genetic information or any other protected characteristic. This commitment extends to all aspects of employment, including, but not limited to, hiring, placement, promotion, compensation, and training. Know Your Rights as an applicant under the law.

Bentley Policy on EEO, Affirmative Action and Pay Transparency Non-Discrimination

Bentley participates in e-Verify / Bentley participate in e-Verify / Right to Work Notice

Request an Accommodation:

As an Equal Opportunity Employer, Bentley is committed to providing reasonable accommodations to applicants with disabilities. We encourage you to request a reasonable accommodation if you are not able to fully use or access our online application system. You can make an accommodation request by calling 610-458-5000 or sending us an email at [email protected]

At Bentley, you'll help shape the future of infrastructure with innovative solutions, a global impact, and a culture that values growth, collaboration, and sustainability.

Built by engineers for engineers, Bentley has been the leading global provider of infrastructure engineering software for 40 years. Join us on our continued journey leading industry change.

Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.

Bentley Systems (Nasdaq: BSY) is the infrastructure engineering software company. We provide innovative software to advance the world’s infrastructure – sustaining both the global economy and environment. Our industry-leading software solutions are used by professionals, and organizations of every size, for the design, construction, and operations of roads and bridges, rail and transit, water and wastewater, public works and utilities, buildings and campuses, mining, and industrial facilities. Our offerings, powered by the iTwin Platform for infrastructure digital twins, include MicroStation and Bentley Open applications for modeling and simulation, Seequent’s software for geoprofessionals, and Bentley Infrastructure Cloud encompassing ProjectWise for project delivery, SYNCHRO for construction management, and AssetWise for asset operations. Bentley Systems’ 5,200 colleagues generate annual revenues of more than $1 billion in 194 countries.

Equal Opportunity Employer/Minorities/Females/Veterans/Disabled

You've read the whole posting — now see how you match it.