Detection and Response Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Detection and Response Lead (Cybersecurity): Building and operating a detection and response function across enterprise and AWS environments with an accent on incident investigation, threat hunting, and detection engineering. Focus on leading complex cloud and endpoint investigations, improving MDR workflows, and driving rapid containment and measurable detection coverage.
Location: Remote United States. Must be legally authorized to work in the United States.
Salary: $160,000–$200,000 USD annual base pay, plus bonus pay and benefits.
Company
is a growth-stage insurtech combining commercial insurance distribution with technology, data, and AI/ML.
What you will do
- Lead escalated incident response investigations across cloud, endpoint, identity, and enterprise environments.
- Perform forensic analysis, log correlation, event reconstruction, and attacker technique identification using SIEM, EDR, proxy, WAF, and DLP tooling.
- Conduct hypothesis-driven and data-driven threat hunts and develop internal hunting methodologies.
- Review and improve MSSP/MDR alert quality, detection logic, log coverage, and monitoring effectiveness.
- Coordinate IT, cloud, application, MSSP, and MDR responders during active incidents.
- Maintain runbooks and response procedures while reporting findings and operational metrics to the CISO and senior leadership.
Requirements
- 7+ years of hands-on experience in cybersecurity operations, incident response, or threat detection.
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent experience.
- Experience leading complex investigations involving cloud environments, identity systems, and endpoint tooling.
- Strong knowledge of attacker TTPs, MITRE ATT&CK, log analysis, correlation, and digital forensics.
- Experience analyzing AWS and Azure security telemetry, including CloudTrail, CloudWatch, IAM, network, and workload-level events.
- Legal authorization to work in the United States is required.
Nice to have
- Experience integrating internal security operations with managed SOC or MDR providers.
- Threat hunting experience in cloud-first or hybrid environments.
- Exposure to SIEM/SOAR platforms.
- Incident response or forensics certifications such as GCIH, GCFA, GNFA, or GCFE.
Culture & Benefits
- Remote work with work-from-home reimbursement.
- Comprehensive medical, dental, and vision insurance.
- 401(k) plan with company match and employee ownership program.
- Paid time off, 11 company-paid holidays, and various time-off programs.
- Professional development opportunities, financial wellness support, employee assistance, and additional voluntary benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →