
Detection and Response Engineer
Posted 5 hours ago

Posted 5 hours ago
This is a fully remote position, open to applicants in United States.
• Gather, analyze, and implement threat intelligence to enhance proactive detection and threat-hunting initiatives, leading to measurable improvements in security posture within client environments.
• Create, refine, and sustain custom detection and threat-hunting queries across multiple SIEM platforms, fine-tuning alerts for enhanced accuracy and developing dashboards and saved searches that facilitate repeatable, operational use cases.
• Organize and oversee cyclical, hypothesis-driven threat hunts utilizing threat intelligence and behavior-based analytics; pinpoint detection deficiencies and telemetry blind spots, and convert hunt results into detection enhancements, alert adjustments, and revised runbooks.
• 2–4 years of experience in large-scale enterprise security environments, including familiarity with cloud-hosted or hybrid infrastructures.
• Fundamental working knowledge of at least one major cloud platform (Azure, AWS, or GCP) and the application of cloud telemetry for security monitoring and investigations.
• Practical experience with at least two SIEM platforms (e.g., Splunk, Microsoft Sentinel, ELK, LogRhythm, or Sumo Logic) in a production detection and response setting.
• Proven capability to independently monitor, validate, and escalate SIEM alerts according to established runbooks, SLAs, and severity thresholds.
• Demonstrated ability to autonomously investigate and address security alerts, conducting in-depth analysis across various log sources to assess scope, root cause, and impact.
• Experience in escalating confirmed or high-confidence incidents with clear timelines, evidence, and MITRE ATT&CK mapping to Incident Response teams or senior engineers.
• Background in conducting structured and cyclical threat-hunting activities using hypothesis-driven and behavior-based methodologies.
• Skill in leveraging threat intelligence to comprehend threat actor tactics, attack chains, and anticipated telemetry, applying this knowledge to investigations and hunts.
• Hands-on experience in developing, refining, and maintaining custom detection and threat-hunting queries across at least two SIEM platforms, translating investigative needs into efficient, reusable query logic.
• Experience in identifying detection gaps, telemetry blind spots, and data quality challenges, and converting findings into alert tuning, new detection logic, dashboards, and updated runbooks or SOPs.
• Excellent communication, organizational, and problem-solving abilities, with proficiency in articulating complex technical information clearly.
• Strong documentation skills for producing technical diagrams, written descriptions, and other supporting materials.
• Proven ability to work both independently and collaboratively within a team, maintaining a professional attitude and demeanor.
• Critical thinking skills to balance comprehensive security requirements with mission objectives.
• Established record of quickly and effectively adapting in fast-paced, dynamic environments.
• Experience utilizing a Detection-as-Code framework.
• Familiarity with NIST 800-53 environments.
• **__REQUIRED CERTIFICATIONS:__**
• At least one of the following:
• Splunk Enterprise Certified Administrator
• Splunk Enterprise Security Certified Administrator
• SumoLogic Administrator
• Microsoft Security Operations Associate
• Elastic Stack Certified Administrator
• Paid parental leave
• Flexible time off
• Certification and training reimbursement
• Digital mental health and wellbeing support membership
• Comprehensive insurance options
Lumata Health
Minuteman Security & Life Safety
Samsara
Get handpicked remote jobs straight to your inbox weekly.