Source Job

US

  • Investigating security events across the organization using your experience and knowledge in multiple security domains.
  • Creating, deploying and maintaining high signal threat detections based on your understanding of threat actor TTPs.
  • Architecting a highly scalable incident response process by developing, applying and refining automation for steps of the Incident Response life cycle

Detection Engineering Incident Response Threat Intelligence Python

18 jobs similar to Detection and Response Engineer

Jobs ranked by similarity.

$120,000–$160,000/yr

  • Lead complex security investigations and drive automated response workflows.
  • Perform host-based triage and forensic analysis across Windows, Linux, and macOS, and conduct cloud-native IR across AWS and Azure.
  • Integrate threat intelligence into active investigations and operationalize it proactively.

VERSANT is a leading force in news, sports and entertainment and is home to iconic and trusted brands. As an independent, publicly traded company, VERSANT brings together powerhouse cable networks with dynamic digital and direct-to-consumer brands, fueled by innovation.

$120,000–$160,000/yr
US

  • Research adversary tradecraft, translate threat intelligence into detection logic
  • Tune and optimize existing detections to reduce alert fatigue while maintaining detection fidelity
  • Document detection logic, response guidance, and follow-on analysis to support SOC and incident responders

Fidelity National Financial (FNF) is seeking a Detection Engineer to join our Information Security Office (ISO). They are an Equal Opportunity employer.

Global

  • Lead and execute security incident response, leveraging your deep expertise to manage and mitigate threats across Ivanti’s global footprint.
  • Uncover both known and unknown threats using advanced incident response techniques, threat hunting, threat intelligence, and a strong understanding of attacker TTPs.
  • Conduct thorough investigations involving external attacks, insider threats, and digital forensics, ensuring stakeholders stay informed with comprehensive reporting.

Ivanti's mission is to elevate human potential within organizations by managing, protecting and automating technology for continuous innovation. It is through diverse and inclusive hiring, decision-making, and commitment to our employees and partners that they will continue to build and deliver world-class solutions for their customers.

$98,400–$147,600/yr
US Canada UK

  • Reduce operational toil by experimenting with AI and automation in security workflows, building simple tools that make your team's work easier, and sharing what you learn.
  • Build trust across engineering and cloud teams by responding to security requests with genuine care, clear communication, and reliable follow-through.
  • Own alert triage and incident response with thoroughness and accuracy, ensuring security findings are investigated quickly, escalated at the right time to the right people, and documented clearly for the whole team to learn from.

Jane is a founder-led, high-growth SaaS company that builds products and tools that thousands of clinics rely on every day to run their businesses, care for their patients, and grow their communities. They are a team of more than 700 people working remotely across Canada, the US, and the UK.

US Unlimited PTO

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

OnePay is a consumer fintech company trusted by millions of Americans to make money better by offering an all-in-one financial services platform. They are backed by Walmart and Ribbit Capital, giving them scale and distribution to build something category-defining.

Europe

  • Lead high-severity incident response
  • Improve detection logic and workflows
  • Contribute to metrics and reporting

Atlas Technica provides IT management, user support, and cybersecurity for hedge funds and investment firms. Founded in 2016, they value ownership, execution, growth, intelligence, and camaraderie, and offer competitive salaries and comprehensive benefits.

South America

  • Monitor security events through SIEM and other security tools, performing initial triage and correlating signals across multiple sources.
  • Execute Incident Response activities, including detection, investigation, containment, remediation, and documentation of security incidents.
  • Analyze alerts and security anomalies to identify legitimate threats, false positives, and areas requiring escalation.

Pismo provides a comprehensive processing platform for banking, card issuing and financial market infrastructure and helps customers innovate and build the next generation of banking and payment solutions. Pismo’s 500+ employees are located in more than 10 countries around the world.

$125,000–$145,000/yr
US

  • Own end-to-end security operations including SOC, monitoring, and detection capabilities.
  • Act as technology incident commander for security events and incidents.
  • Own the operational lifecycle of vulnerability management including scanning, prioritization, and remediation tracking.

Best Egg is a tech-enabled financial platform that helps people build financial confidence through lending solutions and financial health tools. They foster an inclusive and flexible workplace with top-tier benefits and growth opportunities, employing collaborative and innovative team players.

US

  • Manage event and information intake, including intelligence reports and monitoring ticket queues.
  • Triage alerts and correlate and analyze events to determine the scope of cybersecurity incidents.
  • Provide 24x7 on-call support and monitor and manage security incidents using SIEM, SOAR, and DLP tools.

Brightspeed provides fast, reliable internet connections and an awesome customer experience in twenty states throughout the Midwest and South. Backed by funds managed by Apollo Global Management, they are accelerating the upgrade of copper to fiber optic technologies.

$100,000–$130,000/yr
US

  • Monitor client environments performing Incident Detection, Validation, and Reporting.
  • Responsible for the implementation and maintenance of cloud-based SIEM Solutions.
  • Partner with client Security to continuously improve and enhance Managed Security support.

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, they help enterprises deliver on the promise of digital transformation. They prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard.

US

  • Lead a globally distributed cyber defense team.
  • Own enterprise incident response strategy and playbooks.
  • Drive hypothesis-based threat hunting aligned to adversary behaviors.

FNF is an Equal Opportunity employer. They are committed to creating a diverse and inclusive workplace where all employees feel valued and respected.

India

  • Investigate intrusion attempts and perform in-depth analysis of exploits
  • Monitor and analyze network traffic and alerts
  • Provide network intrusion detection expertise to support timely and effective decision making of when to declare an incident

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, they help enterprises deliver on the promise of digital transformation. At AHEAD, they prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard.

US 4w PTO

  • Working cross functionally to design, build, and operate solutions that continuously improve and automate our security capabilities
  • Leveraging data to understand trends, metrics, and opportunities to improve our security posture and then helping execute on those opportunities with stakeholders
  • Leading and enhancing incident / issues response efforts, spearheading analysis, containment, and mitigation strategies in a cross-functional environment to ensure effective resolution and remediation of security incidents / issues

Aledade, a public benefit corporation, empowers independent primary care practices. Founded in 2014, they've become the largest network of independent primary care in the country with a collaborative, inclusive and remote-first culture.

US

  • Represent Surefire Cyber as a skilled technical forensic and consulting expert.
  • Play a pivotal role in detecting and analyzing intrusions, offering clear guidance to clients.
  • Provide career development for a Forensic team consisting of 3-4 Consultants.

Surefire Cyber redefines the incident response model by delivering a swifter, stronger response to cyber incidents. Their client-centric approach reduces stress and provides clients the confidence needed to prepare, respond, and recover from cyber incidents.

  • Proactively hunt down, analyze, and patch system weak spots before they become a problem.
  • Act as the calm, collected, and decisive first responder when the digital alarms ring, leading security investigations.
  • Turn mountains of raw data logs into digestible, actionable insights to keep our defenses sharp.

Miovision is unlocking transportation networks that move people and enable smart, fast, safe communities. They are backed by advanced traffic AI and their innovations in traffic signal planning and operations improve the transportation experience for drivers, cyclists and pedestrians.

$185,000–$200,000/yr
US

  • Build and cultivate strong client relationships based on trust and communication.
  • Lead and oversee active client-facing incident response engagements.
  • Invest in career development and provide mentorship to Forensic professionals.

Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents. Their approach and delivery are designed by industry veterans to address the industry’s persistent challenges of efficiency, predictability, and transparency

US

  • Design and implement scalable vulnerability scanning solutions.
  • Automate vulnerability ingestion, prioritization, and remediation workflows.
  • Partner with Engineering and DevOps teams to remediate vulnerabilities.

Keeper Security is a cybersecurity software company protecting organizations and individuals globally. They are known for zero-knowledge and zero-trust security, securing passwords, infrastructure secrets, and remote connections with role-based enforcement policies.

  • Lead detection-focused trials, demos, and proof-of-concepts for mid-market prospects.
  • Provide technical guidance and ensure best practices are followed throughout the sales cycle and instance deployment.
  • Develop and validate detection strategies that align with customer environments while leading customer-specific platform configurations.

Doppel is the first platform built to dismantle digital deception at scale. They scan over 150 billion entities daily and deploy continuously adaptive AI SOC agents. They are backed by top-tier investors and trusted by some of the world’s most recognized brands, and are growing fast.