Detection and Response Lead
New
I
Integrated Specialty CoveragesInsurtech
Remote United StatesFull-TimeLead
Salary$160,000 — $200,000 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- AWSAzure
Requirements
- Bachelors in Computer Science, Cybersecurity, or equivalent work experience.
- 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
- Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
- Experience building or shaping a detection and response program in partnership with leadership.
- Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
- Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
- Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry) and executing cloud containment.
- Excellent written and verbal communication skills for producing investigative findings.
Responsibilities
- Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment.
- Perform forensic reviews including log correlation, event reconstruction, and identification of attacker techniques.
- Conduct hypothesis-driven and data-driven threat hunts to identify malicious activity.
- Develop internal hunting methodologies based on attacker behavior and business-specific risks.
- Review MSSP/MDR escalations for quality and fidelity; coordinate with engineering to close detection gaps.
- Serve as the technical escalation point for security incidents requiring deep analytical expertise.
- Maintain operational runbooks, investigation procedures, and response guides.
View Full Description & ApplyYou'll be redirected to the employer's site