Incident Responder 1

Date: Sep 24, 2026

Location: Philadelphia, PA, US

Company: Bentley Systems

Position Location Details:

  • Country: USA
  • Work mode: hybrid preferred, remote considered

 

Position Summary:

 

Bentley’s Information Security team is building a security operation where automation does the first pass and people do the judgment. Automated investigation agents already triage most of our alerts, investigate cloud risks, and test our own defenses around the clock. What they cannot do is decide whether they were right, handle the cases they could not resolve, or make the next detection better.

As an Incident Responder I, you join the Security Operations Center at the point where an alert becomes a decision. You will verify what automation concluded, own the cases it hands back, take containment actions within clearly defined limits, and feed what you learn back into detections and playbooks. You will work with modern tooling — CrowdStrike, Wiz, a cloud-native SIEM and SOAR platform — across a global engineering and SaaS environment spanning three public clouds.

This is an entry point, not a destination. The role is designed so that the share of your time spent on routine response falls as your share of engineering and improvement work grows, and it sits on a defined career path into detection engineering, security engineering, architecture, or governance.

 

Responsibilities:

Keep us safe today

  • Monitor and respond to alerts and cases from the SIEM, SOAR, endpoint, and cloud security platforms, including the output of automated investigation agents.
  • Review automated verdicts — malicious, not malicious, inconclusive — and act on them: confirm and close, escalate, or contain within the approved autonomy tier (isolate a host, revoke a session, block an indicator).
  • Own the inconclusive queue: investigate what automation could not resolve and document the outcome so the same class of case can be automated next time.
  • Hand off and receive incidents cleanly across shifts with complete, structured notes; escalate to senior responders and management per the incident response procedure.

Sharpen what we have

  • Sample automated verdicts for accuracy (false positives and false negatives) and report findings; your sampling doubles as audit evidence for our compliance program.
  • Tune existing detections and playbooks based on what your shift observed; keep runbooks current.
  • Watch the health of the tooling the SOC depends on — sensor coverage, connector status, log sources — and raise gaps before they become blind spots.

Help build what’s next

  • Contribute to detection-as-code: propose new detections and playbook steps, version them, and test them with a senior engineer.
  • Learn the behavioral baselines of AI agents operating in our environment and flag abnormal agent activity — a new class of alert this SOC owns.
  • Take part in post-incident reviews and turn lessons into automation requests for the engineering team.

 

Qualifications:

 

  • 1–2 years of education or training in a security-related field, or equivalent work experience in IT roles such as desktop support, network operations, or systems administration.
  • Working knowledge of operating systems, authentication protocols, network protocols and topologies, email systems, and cloud service models (IaaS, PaaS, SaaS).
  • A basic understanding of cyberattacks and threats, using the MITRE ATT&CK framework as a reference.
  • Comfort working alongside automation: you can read an automated investigation summary, judge whether it is right, and explain why.
  • Curiosity and a habit of writing things down. The value of this role is in what you feed back into the system.
  • Availability for a shift rotation as part of a 24×7 operation.
  • This is a full-time role expected to work 40 hours per week, based in the USA and does not require travel.
  • Requires sitting or standing at will while performing work on a computer.
  • Applicants must be authorized to work in the U.S. without current or future employer sponsorship. 

Preferred Qualifications:

  • Exposure to SOAR playbooks, scripting (Python or PowerShell), or query languages such as KQL or SPL.
  • Hands-on time with CrowdStrike Falcon, Wiz, Microsoft Sentinel or a comparable SIEM.
  • Security+, CySA+, or a similar foundational certification — or the intent to earn one; we fund training and certifications.

About Bentley Systems

 

Around the world, infrastructure professionals rely on software from Bentley Systems to help them design, build, and operate better and more resilient infrastructure for transportation, water, energy, cities, and more. Founded in 1984 by engineers for engineers, Bentley is the partner of choice for engineering firms and owner-operators worldwide, with software that spans engineering disciplines, industry sectors, and all phases of the infrastructure lifecycle. Through our digital twin solutions, we help infrastructure professionals unlock the value of their data to transform project delivery and asset performance. www.bentley.com

Equal Opportunity Employer:

Bentley is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, sex, sexual orientation, gender identity, disability, pregnancy, protected veteran status, religion, national origin, age, genetic information or any other protected characteristic.  This commitment extends to all aspects of employment, including, but not limited to, hiring, placement, promotion, compensation, and training. Know Your Rights as an applicant under the law.

 

Bentley Policy on EEO, Affirmative Action and Pay Transparency Non-Discrimination

Bentley participates in e-Verify / Bentley participate in e-Verify / Right to Work Notice

 

Request an Accommodation:

 

As an Equal Opportunity Employer, Bentley is committed to providing reasonable accommodations to applicants with disabilities. We encourage you to request a reasonable accommodation if you are not able to fully use or access our online application system.   You can make an accommodation request by calling 610-458-5000 or sending us an email at disabilityrequest@bentley.com

 

 

#LI-MG1

#LI-REMOTE

#LI-HYBRID


Nearest Major Market: Philadelphia

Job Segment: Engineer, Engineering