Live opening · Posted 7 days ago

Detection and Response Engineer

Jobgether · United States (Remote)
Linkedin No
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyJobgether
LocationUnited States (Remote)
Work modeNo
SourceLinkedin
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
11 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
61,282 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States.
This full-time remote role focuses on strengthening detection, incident response, security automation, and AI-enabled SOC operations.
You will engineer and continuously improve security detection capabilities across endpoint, network, cloud, and identity environments.
The role combines hands-on threat detection with incident investigation, forensic support, automation, and security tooling.
You will help close visibility gaps, reduce manual analyst effort, and accelerate the path from detection through resolution.
A key component of the position involves evaluating and implementing AI and LLM-powered capabilities for security operations.
You will collaborate closely with SOC, IT, cloud, network, identity, and engineering teams in a fast-moving security environment.
Your work will directly contribute to improving the organization's ability to identify, investigate, contain, and respond to evolving cyber threats.
Accountabilities
Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources.
Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements.
Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness.
Maintain and version-control detection rules, associated documentation, coverage information, and known gaps.
Triage, investigate, and contain security incidents and alerts across the environment.
Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements.
Document incident timelines, indicators of compromise, remediation activities, and investigative findings.
Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required.
Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows.
Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond.
Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation.
Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations.
Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing.
Build and maintain incident response playbooks, runbooks, and supporting procedures.
Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources.
Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps.
Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments.
Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders.
Maintain procedures and policy documentation supporting detection and response operations.
Requirements
Bachelor’s degree in a technical field or equivalent professional experience.
3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations.
Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel.
Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources.
Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis.
Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.
Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms.
Working knowledge of PCI-DSS or a comparable security and compliance framework.
Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences.
Experience with SOAR platforms such as n8n or Tines is a plus.
Experience integrating or building with LLM and AI APIs for security use cases is beneficial.
Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous.
Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus.
Familiarity with payment or fintech regulatory environments is beneficial.
Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized.
Benefits
Salary: $100,000–$145,000 annually.
Compensation within the range varies based on work location, job-related knowledge, skills, and experience.
Full-time, fully remote position within the United States.
Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations.
Opportunity to work with emerging AI and LLM technologies applied to cybersecurity.
Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams.
Opportunity to contribute to security capabilities within a payment technology environment.
Benefits and total rewards offerings are discussed throughout the interview process.
Inclusive work environment with a focus on employee well-being and professional development.
No current or future visa sponsorship is available for this position.
How Jobgether Works
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App