Detection and Response Engineer
J
JobgetherSecurity & IT
Based in the United StatesFull-TimeMiddle
Salary100,000 - 145,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 3–5 years
- Required Skills
- AWSPython
Requirements
- Bachelor’s degree in a technical field or equivalent professional experience.
- 3–5 years of hands-on information security experience in detection engineering, incident response, security automation, or SOC operations.
- Hands-on experience creating/tuning detection content in SIEM/NG-SIEM platforms (e.g., CrowdStrike, Splunk, Microsoft Sentinel).
- Experience with EDR/XDR platforms and log analysis across endpoint, network, cloud, and identity sources.
- Working knowledge of the MITRE ATT&CK framework.
- Proficiency in security scripting (Python, PowerShell) or experience with LLM coding tools (Claude Code, Gemini CLI, Codex).
- Understanding of networking and cloud infrastructure, particularly AWS (with exposure to Azure and GCP).
- Knowledge of Windows, Linux, and identity platforms.
- Working knowledge of PCI-DSS or comparable compliance frameworks.
- Strong written and verbal communication skills.
Responsibilities
- Design, build, tune, and maintain detection content across endpoint, network, cloud, and identity data sources.
- Perform detection coverage and gap analysis using the MITRE ATT&CK framework.
- Triage, investigate, and contain security incidents across the environment.
- Conduct root-cause analysis and structured post-incident reviews.
- Evaluate and implement AI- and LLM-powered solutions for alert triage and investigation.
- Develop security automation and orchestration using SOAR platforms, APIs, and scripts.
- Build and maintain incident response playbooks and runbooks.
- Partner with cloud, network, and engineering teams to address visibility gaps.
View Full Description & ApplyYou'll be redirected to the employer's site