Detection and Response Engineer

JobgetherUnited StatesOn-siteFull-timeMid level, 2–5 yearsListed 3 hours ago

Apply now

About this role

Accountabilities

- Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources.

- Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements.

- Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness.

- Maintain and version-control detection rules, associated documentation, coverage information, and known gaps.

- Triage, investigate, and contain security incidents and alerts across the environment.

- Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements.

- Document incident timelines, indicators of compromise, remediation activities, and investigative findings.

- Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required.

- Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows.

- Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond.

- Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation.

- Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations.

- Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing.

- Build and maintain incident response playbooks, runbooks, and supporting procedures.

- Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources.

- Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps.

- Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments.

- Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders.

- Maintain procedures and policy documentation supporting detection and response operations.

Requirements

- Bachelor’s degree in a technical field or equivalent professional experience.

- 3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations.

- Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel.

- Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources.

- Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis.

- Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.

- Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms.

- Working knowledge of PCI-DSS or a comparable security and compliance framework.

- Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences.

- Experience with SOAR platforms such as n8n or Tines is a plus.

- Experience integrating or building with LLM and AI APIs for security use cases is beneficial.

- Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous.

- Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus.

- Familiarity with payment or fintech regulatory environments is beneficial.

- Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized.

Benefits

- Salary: $100,000–$145,000 annually.

- Compensation within the range varies based on work location, job-related knowledge, skills, and experience.

- Full-time, fully remote position within the United States.

- Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations.

- Opportunity to work with emerging AI and LLM technologies applied to cybersecurity.

- Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams.

- Opportunity to contribute to security capabilities within a payment technology environment.

- Benefits and total rewards offerings are discussed throughout the interview process.

- Inclusive work environment with a focus on employee well-being and professional development.

- No current or future visa sponsorship is available for this position.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1