Detection and Response Engineer
AI Summary
Engineers and improves security detection and incident response capabilities across endpoint, network, cloud, and identity environments, including AI/LLM-powered SOC operations.
About this role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States.
This full-time remote role focuses on strengthening detection, incident response, security automation, and AI-enabled SOC operations.
You will engineer and continuously improve security detection capabilities across endpoint, network, cloud, and identity environments.
The role combines hands-on threat detection with incident investigation, forensic support, automation, and security tooling.
You will help close visibility gaps, reduce manual analyst effort, and accelerate the path from detection through resolution.
A key component of the position involves evaluating and implementing AI and LLM-powered capabilities for security operations.
You will collaborate closely with SOC, IT, cloud, network, identity, and engineering teams in a fast-moving security environment.
Your work will directly contribute to improving the organization's ability to identify, investigate, contain, and respond to evolving cyber threats.
Accountabilities
-
Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources.
-
Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements.
-
Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness.
-
Maintain and version-control detection rules, associated documentation, coverage information, and known gaps.
-
Triage, investigate, and contain security incidents and alerts across the environment.
-
Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements.
-
Document incident timelines, indicators of compromise, remediation activities, and investigative findings.
-
Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required.
-
Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows.
-
Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond.
-
Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation.
-
Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations.
-
Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing.
-
Build and maintain incident response playbooks, runbooks, and supporting procedures.
-
Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources.
-
Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps.
-
Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments.
-
Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders.
-
Maintain procedures and policy documentation supporting detection and response operations.
-
Bachelor’s degree in a technical field or equivalent professional experience.
-
3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations.
-
Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel.
-
Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources.
-
Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis.
-
Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.
-
Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms.
-
Working knowledge of PCI-DSS or a comparable security and compliance framework.
-
Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences.
-
Experience with SOAR platforms such as n8n or Tines is a plus.
-
Experience integrating or building with LLM and AI APIs for security use cases is beneficial.
-
Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous.
-
Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus.
-
Familiarity with payment or fintech regulatory environments is beneficial.
-
Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized.
-
Salary: $100,000–$145,000 annually.
-
Compensation within the range varies based on work location, job-related knowledge, skills, and experience.
-
Full-time, fully remote position within the United States.
-
Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations.
-
Opportunity to work with emerging AI and LLM technologies applied to cybersecurity.
-
Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams.
-
Opportunity to contribute to security capabilities within a payment technology environment.
-
Benefits and total rewards offerings are discussed throughout the interview process.
-
Inclusive work environment with a focus on employee well-being and professional development.
-
No current or future visa sponsorship is available for this position.
Requirements
Benefits
Skills
Explore related jobs
More jobs at Jobgether
Browse these categories
Market data for this role
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.
