Jobless Developer
Jobgether logo

Posted 3 days ago

Open

Detection and Response Engineer

United StatesRemoteFull-time

AI Summary

Engineers and improves security detection and incident response capabilities across endpoint, network, cloud, and identity environments, including AI/LLM-powered SOC operations.

About this role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States.

This full-time remote role focuses on strengthening detection, incident response, security automation, and AI-enabled SOC operations.
You will engineer and continuously improve security detection capabilities across endpoint, network, cloud, and identity environments.
The role combines hands-on threat detection with incident investigation, forensic support, automation, and security tooling.
You will help close visibility gaps, reduce manual analyst effort, and accelerate the path from detection through resolution.
A key component of the position involves evaluating and implementing AI and LLM-powered capabilities for security operations.
You will collaborate closely with SOC, IT, cloud, network, identity, and engineering teams in a fast-moving security environment.
Your work will directly contribute to improving the organization's ability to identify, investigate, contain, and respond to evolving cyber threats.

Accountabilities

  • Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources.

  • Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements.

  • Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness.

  • Maintain and version-control detection rules, associated documentation, coverage information, and known gaps.

  • Triage, investigate, and contain security incidents and alerts across the environment.

  • Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements.

  • Document incident timelines, indicators of compromise, remediation activities, and investigative findings.

  • Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required.

  • Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows.

  • Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond.

  • Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation.

  • Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations.

  • Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing.

  • Build and maintain incident response playbooks, runbooks, and supporting procedures.

  • Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources.

  • Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps.

  • Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments.

  • Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders.

  • Maintain procedures and policy documentation supporting detection and response operations.

  • Requirements

    • Bachelor’s degree in a technical field or equivalent professional experience.

    • 3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations.

    • Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel.

    • Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources.

    • Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis.

    • Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.

    • Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms.

    • Working knowledge of PCI-DSS or a comparable security and compliance framework.

    • Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences.

    • Experience with SOAR platforms such as n8n or Tines is a plus.

    • Experience integrating or building with LLM and AI APIs for security use cases is beneficial.

    • Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous.

    • Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus.

    • Familiarity with payment or fintech regulatory environments is beneficial.

    • Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized.

    • Benefits

      • Salary: $100,000–$145,000 annually.

      • Compensation within the range varies based on work location, job-related knowledge, skills, and experience.

      • Full-time, fully remote position within the United States.

      • Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations.

      • Opportunity to work with emerging AI and LLM technologies applied to cybersecurity.

      • Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams.

      • Opportunity to contribute to security capabilities within a payment technology environment.

      • Benefits and total rewards offerings are discussed throughout the interview process.

      • Inclusive work environment with a focus on employee well-being and professional development.

      • No current or future visa sponsorship is available for this position.

Skills

AWSAWS GuardDutyAzureClaude CodeCodexCrowdStrike NG-SIEMEDR/XDRGCPGemini CLIGoogle Security Command CenterMicrosoft SentinelMITRE ATT&CKN8nPCI-DSSPowerShellPythonSOARSplunkTines

Explore related jobs

Browse these categories

Market data for this role

All reports →