Назад
Company hidden
7 дней назад

Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity

110 000 - 170 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity (SIEM/EDR/AI): Detecting, investigating, and responding to security incidents across email, endpoint, identity, network, and cloud telemetry with an accent on incident response, detection engineering, and AI-assisted investigations. Focus on handling complex escalations, containing intrusions, building reliable detections and automation, and improving coverage through threat hunting and purple team exercises.

Location: Miami, United States

Expected annual base salary: $110,000–$170,000

Company

hirify.global is an alternative asset manager with technology teams building systems that manage risk, improve efficiency, and increase transparency across its businesses and investment portfolio.

What you will do

  • Manage incident investigations from alert intake through containment, eradication, and closure across email, endpoint, identity, network, and cloud environments.
  • Handle Tier 1 escalations and complex investigations, including phishing, business email compromise, credential misuse, privilege abuse, session hijacking, and multi-factor authentication bypass.
  • Use SIEM and EDR platforms to pivot across telemetry, investigate endpoints, perform live response, collect artifacts, and contain hosts.
  • Investigate third-party and SaaS provider compromises, assess exposure, and coordinate remediation with legal, compliance, vendor risk, and business stakeholders.
  • Author and tune detections, reduce false positives, develop response automation, and improve coverage for AI-related threats.
  • Mentor Tier 1 analysts, document incidents with appropriate evidence handling, contribute to threat hunts and purple team exercises, and participate in an occasional quarterly on-call rotation.

Requirements

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role.
  • End-to-end investigation experience in a SOC or incident response environment, including root-cause analysis and containment.
  • Hands-on experience with an enterprise SIEM and query language such as Splunk SPL, Microsoft Sentinel KQL, or Elastic, plus an enterprise EDR platform.
  • Knowledge of cloud and identity investigations, IAM, SSO, Okta or Microsoft Entra ID, attacker behavior, and MITRE ATT&CK.
  • Scripting experience with Python and/or PowerShell for enrichment, parsing, and automation.
  • Demonstrated practical use of AI tooling, sound judgment regarding AI output, and clear technical communication with technical and non-technical stakeholders.

Nice to have

  • Detection-as-code, Git workflows, peer review, CI validation, SOAR automation, or Sigma content experience.
  • Digital forensics, malware triage, sandboxing, threat hunting, or agentic AI security tooling experience.
  • Experience with AWS, Azure, or GCP security logging and identity services.
  • Financial services experience, relevant security certifications, or a degree in computer science, cybersecurity, information systems, or a related field.

Culture & Benefits

  • Fast-paced, entrepreneurial technology environment with iterative design and rapid development.
  • Active mentoring, collaborative problem solving, and opportunities to translate ideas into operational solutions.
  • Medical, dental, vision, and FSA benefits.
  • Paid time off, life insurance, a 401(k) plan, discretionary bonuses, and potential equity or other incentive compensation.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →