Detection and Response Lead

New
I
Integrated Specialty CoveragesInsurtech
Remote United StatesFull-TimeLead
Salary$160,000 — $200,000 USD
Apply NowOpens the employer's application page

Job Details

Experience
7+ years
Required Skills
AWSAzure

Requirements

  • Bachelors in Computer Science, Cybersecurity, or equivalent work experience.
  • 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry) and executing cloud containment.
  • Excellent written and verbal communication skills for producing investigative findings.

Responsibilities

  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment.
  • Perform forensic reviews including log correlation, event reconstruction, and identification of attacker techniques.
  • Conduct hypothesis-driven and data-driven threat hunts to identify malicious activity.
  • Develop internal hunting methodologies based on attacker behavior and business-specific risks.
  • Review MSSP/MDR escalations for quality and fidelity; coordinate with engineering to close detection gaps.
  • Serve as the technical escalation point for security incidents requiring deep analytical expertise.
  • Maintain operational runbooks, investigation procedures, and response guides.
View Full Description & ApplyYou'll be redirected to the employer's site
$160,000 — $200,000 USD
Apply Now