All roles

Detection and Response Engineer

Remote · USA Full-time New today

About the position We are seeking an experienced Security Engineer, Detection & Response to join our dynamic security team. In this role, you will provide Level 2 support to our managed Security Operations Center (SOC), monitoring and analyzing security alerts and emerging threats across our corporate, cloud and production environments to identify and respond to potential security incidents and critical vulnerabilities. You'll work closely with the broader Security and IT team and other engineering teams to develop a strong understanding of our ecosystem to enable you to act effectively as an Incident Commander when required, and coordinate incident resolution with cross-functional teams to ensure 24/7 coverage. This understanding will aid you in your threat hunting and forensic investigations to uncover indicators of compromise and patterns of malicious activity, as well as fine-tune and develop additional detection rules, configurations, custom playbooks and automations tailored to our environment in collaboration with our managed SOC. In the area of vulnerability management, you will monitor security advisories and threat intelligence feeds, and drive automation to strive for containment. Your collaboration with cross-functional teams will be essential in proactively detecting and responding to security threats and ensuring the overall security of our digital assets.

Responsibilities

  • Provide Level 2 support to a managed SOC and support monitoring security alerts and events from various sources, including corporate tools, WAF, security information and event management (SIEM) systems, and AWS to identify potential security incidents, intrusions and vulnerabilities.
  • Conduct threat hunting and perform forensic investigations to identify indicators of compromise (IOCs) and patterns of malicious activity.
  • Coordinate and manage incident resolution with cross-functional teams, including acting as Incident Commander during incidents to help provide 24/7 coverage with other team members.
  • Support Cloud Detection & Response platforms to enable various automated notification and containment workflows.
  • Fine-tune and develop detection rules, configurations, and automations based on new threats, lessons learned, or environmental changes.
  • Work with the managed SOC to develop custom playbooks.
  • Write scripts and develop custom tools to automate the detection and response processes. Adhere to SSDLC best practices when writing scripts or developing tools.
  • Identify any gaps in logging coverage to ensure we maintain the highest visibility into any threats to our environment.
  • Manage Cloudflare security products for web application security, including WAF rules and DDoS protection.
  • Collaborate with cross-functional teams to proactively detect and respond to potential security threats and ensure the overall security of our organization's digital assets.
  • Monitor security advisories, threat intelligence feeds, and vendor updates for critical threats to drive action back into the enterprise/product organization.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 3 years of experience in a SOC analyst or security operations role.
  • Proficiency in programming and relevant scripting languages such as Python, JavaScript, Bash, and PowerShell.
  • Experience with AWS security services and best practices.
  • Familiarity with Cloudflare, SentinelOne, Okta, and related security tools.
  • Understanding of network protocols, firewalls, and intrusion detection systems.
  • Strong analytical and problem-solving abilities.
  • Excellent communication skills, both written and verbal.
  • Ability to work independently and as part of a team.

Nice-to-haves

  • Certifications such as CISSP, CEH, and AWS Certified Security Specialty.
  • Experience with infrastructure as code tools (e.g., Terraform).
  • Knowledge of DevSecOps practices and CI/CD pipelines.
  • Familiarity with regulatory compliance standards (e.g., GDPR, ISO 27001).

Benefits

  • Full medical coverage
  • Flexible PTO
  • Wellness reimbursement
  • Monthly lunch stipend
  • Wellness programs
  • Frequent team-building events
  • Donation-matching program

Apply tot his job Apply To this Job

Related roles

TJ Maxx Poplar Creek Maintenance Associate Weekends

Remote · USA Full-time

Truck Dispatcher Baton Rouge, LA

Remote · USA Full-time

HR Business Partner (Hybrid)

Remote · USA Full-time

Senior Provider Network Pricing Analyst - Remote for Pacific / Hawaii Time Zones

Remote · USA Full-time

Freelance UI Designer

Remote · USA Full-time

Tech Lead - Customer Journey Analytics

Remote · USA Full-time

Sr Counsel - Employment

Remote · USA Full-time

Credit & Underwriting Analyst

Remote · USA Full-time

Senior Data Analyst - IT: Remote Data Entry and Opinion Sharing Opportunity with United Airlines and Continuum Global Solutions

Remote · USA Full-time

Principal Application Security Architect – Cloud & Enterprise Cyber Defense Leader (Remote/Hybrid) – United Airlines

Remote · USA Full-time

Job Title: Creative Customer Experience Designer - Part-Time Remote Position | Multi-Platform Digital Media & Services at arenaflex

Remote · USA Full-time

Experienced Full Stack Program Manager – Live Chat Strategy and Roadmap Development

Remote · USA Full-time

Quantitative Developer (Fintech)

Remote · USA Full-time

Online Cloud Security Policy Analyst

Remote · USA Full-time

Job Title: Metro Network Deployment Engineer - Google Global Networking

Remote · USA Full-time

Part-Time Customer Service Representative - Flexible Hours, Competitive Pay, and Career Growth at blithequark

Remote · USA Full-time

Specialist, Market Growth & Retention (Remote in NY) - Bilingual – Spanish

Remote · USA Full-time

Governance, Risk, and Compliance Specialist - Customer Assurance (Remote)

Remote · USA Full-time

Experienced Non-Voice Customer Service Representative – Temporary | arenaflex US

Remote · USA Full-time

Accounts Receivable (AR) Specialist

Remote · USA Full-time