Verified current Job

Detection and Response Engineer

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the Unite

Job Remote Full source details
Jobgether Source published Sep 21, 2026 Verified 57 minutes ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the Unite

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States. This full-time remote role focuses on strengthening detection, incident response, security automation, and AI-enabled SOC operations. You will engineer and continuously improve security detection capabilities across endpoint, network, cloud, and identity environments. The role combines hands-on threat detection with incident investigation, forensic support, automation, and security tooling. You will help close visibility gaps, reduce manual analyst effort, and accelerate the path from detection through resolution. A key component of the position involves evaluating and implementing AI and LLM-powered capabilities for security operations. You will collaborate closely with SOC, IT, cloud, network, identity, and engineering teams in a fast-moving security environment. Your work will directly contribute to improving the organization's ability to identify, investigate, contain, and respond to evolving cyber threats.

Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources. Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements. Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness. Maintain and version-control detection rules, associated documentation, coverage information, and known gaps. Triage, investigate, and contain security incidents and alerts across the environment. Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements. Document incident timelines, indicators of compromise, remediation activities, and investigative findings. Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required. Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows. Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond. Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation. Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations. Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing. Build and maintain incident response playbooks, runbooks, and supporting procedures. Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources. Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps. Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments. Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders. Maintain procedures and policy documentation supporting detection and response operations. Requirements Bachelor’s degree in a technical field or equivalent professional experience. 3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations. Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel. Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources. Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis. Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex. Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms. Working knowledge of PCI-DSS or a comparable security and compliance framework. Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences. Experience with SOAR platforms such as n8n or Tines is a plus. Experience integrating or building with LLM and AI APIs for security use cases is beneficial. Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous. Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus. Familiarity with payment or fintech regulatory environments is beneficial. Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized. Benefits Salary: $100,000–$145,000 annually. Compensation within the range varies based on work location, job-related knowledge, skills, and experience. Full-time, fully remote position within the United States. Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations. Opportunity to work with emerging AI and LLM technologies applied to cybersecurity. Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams. Opportunity to contribute to security capabilities within a payment technology environment. Benefits and total rewards offerings are discussed throughout the interview process. Inclusive work environment with a focus on employee well-being and professional development. No current or future visa sponsorship is available for this position.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

jobgether (lever) ↗

Browse current Job and Scholarship listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books