Security Engineer, Detection & Response
Lockton, Inc.
Job Summary: The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active incident, their time goes toward preventing the next one: running cyber threat intelligence (CTI), executing red team and purple team exercises, hunting for threats in our environment, and strengthening our detections. The role also serves as the senior technical escalation point for the Security Operations Center (SOC). The ideal candidate is a hands-on practitioner who is equally comfortable leading a live incident bridge, tracking the threat actors most likely to target Lockton, and emulating those actors to prove our defenses work.
Key Responsibilities:
Incident Response •Incident Leadership: Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover. Own incident documentation and ensure communication and escalation processes are followed. •Forensic Analysis: Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence. Preserve the integrity of data and produce detailed forensic and incident reports. •Root Cause and Lessons Learned: Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks. •Readiness: Maintain and improve incident response playbooks and runbooks. Plan and run tabletop exercises with technical and executive audiences across regions.
Cyber Threat Intelligence •Intelligence Program: Build and run Lockton's CTI capability. Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships. •Threat Actor Tracking: Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate. Maintain actor profiles and produce regular threat briefings for security leadership and the broader team. •Operationalizing Intelligence: Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns. •Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry. Convert hunt findings into durable detections.
Red Team and Purple Team Exercises •Adversary Emulation: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement. Emulate the TTPs of the actors identified through CTI. •Detection Validation: Work side by side with the SOC and detection engineering to measure whether our controls detect and respond as expected. Map coverage and gaps to MITRE ATT&CK. •Remediation: Deliver clear findings with prioritized remediation, then retest to confirm gaps are closed.
SOC Escalation •Escalation Point: Serve as the senior technical escalation for the SOC, including our managed detection and response partner, on complex or high-severity alerts. Guide triage decisions and make the call on when an alert becomes an incident. •Detection Improvement: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results. Reduce false positives and close visibility gaps. •Mentoring: Raise the technical bar of the SOC through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
General •Collaboration: Work closely with IT, Legal, and other departments to ensure a coordinated and comprehensive response to security threats. •Must be able to respond to security-related emergencies that may arise outside of regular business hours. •Participate in security team On-Call rotation. Requirements: • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience. • Minimum of 5 years of experience in information security, with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing. • Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable. • Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation. • Hands-on experience with EDR and SIEM platforms. Experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR is a strong plus. • Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure. • Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development. • Experience with adversary emulation tooling (for example, Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments. • Excellent problem-solving skills and the ability to work under pressure. • Meticulous attention to detail to ensure the accuracy and integrity of forensic investigations and incident reports. • Strong written and verbal communication skills, with the ability to produce intelligence products and incident reports for both technical and executive audiences. • Ability to work effectively in a team environment and collaborate with cross-functional teams. • Willingness to stay current with attacker tradecraft, cloud security, and emerging threats such as AI-enabled attacks, and continuously enhance skills. #LI-JM
Key Responsibilities:
Incident Response •Incident Leadership: Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover. Own incident documentation and ensure communication and escalation processes are followed. •Forensic Analysis: Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence. Preserve the integrity of data and produce detailed forensic and incident reports. •Root Cause and Lessons Learned: Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks. •Readiness: Maintain and improve incident response playbooks and runbooks. Plan and run tabletop exercises with technical and executive audiences across regions.
Cyber Threat Intelligence •Intelligence Program: Build and run Lockton's CTI capability. Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships. •Threat Actor Tracking: Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate. Maintain actor profiles and produce regular threat briefings for security leadership and the broader team. •Operationalizing Intelligence: Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns. •Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry. Convert hunt findings into durable detections.
Red Team and Purple Team Exercises •Adversary Emulation: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement. Emulate the TTPs of the actors identified through CTI. •Detection Validation: Work side by side with the SOC and detection engineering to measure whether our controls detect and respond as expected. Map coverage and gaps to MITRE ATT&CK. •Remediation: Deliver clear findings with prioritized remediation, then retest to confirm gaps are closed.
SOC Escalation •Escalation Point: Serve as the senior technical escalation for the SOC, including our managed detection and response partner, on complex or high-severity alerts. Guide triage decisions and make the call on when an alert becomes an incident. •Detection Improvement: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results. Reduce false positives and close visibility gaps. •Mentoring: Raise the technical bar of the SOC through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
General •Collaboration: Work closely with IT, Legal, and other departments to ensure a coordinated and comprehensive response to security threats. •Must be able to respond to security-related emergencies that may arise outside of regular business hours. •Participate in security team On-Call rotation. Requirements: • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience. • Minimum of 5 years of experience in information security, with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing. • Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable. • Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation. • Hands-on experience with EDR and SIEM platforms. Experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR is a strong plus. • Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure. • Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development. • Experience with adversary emulation tooling (for example, Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments. • Excellent problem-solving skills and the ability to work under pressure. • Meticulous attention to detail to ensure the accuracy and integrity of forensic investigations and incident reports. • Strong written and verbal communication skills, with the ability to produce intelligence products and incident reports for both technical and executive audiences. • Ability to work effectively in a team environment and collaborate with cross-functional teams. • Willingness to stay current with attacker tradecraft, cloud security, and emerging threats such as AI-enabled attacks, and continuously enhance skills. #LI-JM
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Engineer, Detection & Response in Kansas City, MO vacancy
$2,500 per month
The Red Team - SrSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes... ...environments, and applications, and partner with detection engineering to close the gaps those exercises...SuggestedFull timeWork experience placement- ...you. We are seeking a Senior Security Engineer to join our team. They will be a key... ...the Information Security department, responsible for performing cybersecurity risk mitigation... ..., and endpoint security solutions, to detect potential threats Safely acquire...SuggestedFull timeWork experience placement
$126k - $188k
...and services by identifying security risks early, partnering closely with product and engineering teams, and guiding practical... ...millions of users daily. Responsibilities Work with cross-functional... ...Security and Response, Detection Engineering, Network Security...SuggestedWork experience placementLocal areaRemote work$119k - $169.4k
...Role Overview The Network Security Team is seeking a Sr. Network and Firewall Security Engineer to secure and operate... ...complex problems from initial detection through resolution. This... ...capability of the team. Your responsibilities will be: ~ Design,...SuggestedFull timeWork at officeImmediate startNight shift- ...Senior Product Security Engineer The Senior Product Security Engineer is a deeply technical... ...engineering and architect-level role responsible for establishing and leading the Product... ...container image scanning, and secrets detection. Define vulnerability remediation...Suggested
$118.91k - $214.36k
...role is essential to the Threat Response (TR) organization, strengthening how the Security Operations Center (SOC) and Incident Response (IR) teams detect, investigate, and contain cyber threats... .... It applies cybersecurity engineering judgment to the delivery of TR initiatives...Full timeTemporary workPart timeWork experience placementLocal areaFlexible hours$41.57 per hour
...Security Engineer Do you envision finding a meaningful role with an inclusive and compassionate team? At Children's Mercy, we believe... ...our hospital. Overview The Security Engineer will be responsible for installing, configuring, and managing security tools to...Work experience placementSeasonal workRemote work- ...check mark everything below. Job Title: Part-Time Security Engineer (25 hours/week) Location: Remote (Kansas City Area)... ...transition), including specialists in network security, incident response, and data security. Approval: Any work exceeding 25...Full timeContract workPart timeImmediate startRemote workMonday to Friday
$95k - $180k
...GENERAL STATEMENT OF RESPONSIBILITY: Identify, implement and monitor security systems and processes for the protection of the computer systems, networks and... ...Direct experience with anti-virus software, intrusion detection, firewalls and content filtering Knowledge of...Full timeContract workTemporary workWork experience placementLocal areaWeekend work$105.4k - $207.8k
...Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth,... ...Enterprise Security team, you will be responsible for…Designing, deploying, and managing... ...intrusion prevention system/intrusion detection system (IPS/IDS), Anti-Spyware,...Work experience placementLocal areaRemote work- ...be hired anywhere in the continental U.S.The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR... .... The role owns the engineering function behind Managed Detection and Response (MDR), co-managed SIEM, data engineering, and...Full timeWork experience placementLocal areaRemote workWork from home
$2,500 per month
The ApplicationSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes... ...incident response process by aiding in the detection, containment, and reporting of incidents.Deploy, integrate...Full timeWork experience placement$134.5k - $265.1k
...and proactively manage their security posture.Recruiting for this role... ...:As a Cyber Forward Deployed Engineer (FDE) Sr Consultant, you will... ..., GPT-4o, Assistants API, Responses API, OpenAI Agents Experience... ...security, cloud security, identity, detection engineering).Experience with...Local areaVisa sponsorship- ...a highly motivated and passionate Security Automation Engineer with a strong foundation in cybersecurity... ...throughout each engagement. Your responsibilities will include: Custom Scripting &... ...measurably decrease mean-time-to-detection (MTTD) and response (MTTR)....Temporary workWork at office
- We are looking for a Cyber Security Engineer to join our growing Cyber Defense team in our Overland... ....Hands-on experience with incident response, alert handling, and SOC‑driven... ...Assist in tuning scanning tools, adjusting detection policies, and improving asset coverage...Full timeWork at officeMonday to Friday3 days per week
$97.6k - $200.6k
...potential SIEM content/level I and II engineering security concerns as this role is the first... ...operational support. This role is also responsible for supporting Security application patching... ...security, and auditability. Threat Detection Threat detection development in...$44.7 - $52.4 per hour
...transformation who power applications, secure networks, and implement... ...job is to adhere to Incident Response protocol, administering... ...of SIEM utilities, intrusion detection system/intrusion prevention system... .... The Cyber Security Engineer II will be well versed in Incident...Hourly payFull timeWork at officeRemote workShift work1 day per week$102.17k
...optimizing water supply and demand, detecting leaks and anomalies, or... ...Join the Trinnex Security Team as a Senior Cyber Security... ...You will work closely with engineering and development teams to safeguard... ...detect emerging threats. Lead response efforts for complex...Work experience placementH1b$195k
...foreign exchange, digital assets, and securities. The organisation operates critical infrastructure... ...to reach out and apply today! Responsibilities: Design, deploy and manage Palo... ...escalation point, mentor junior engineers and help drive operational best practices...Full time- ...DescriptionCollaborate with the Information Security team and IT, OT, and asset owners to... ...), and plant networks.Job Duties and Responsibilities:Own day-to-day execution and continuous... ...infrastructure, application owners, plant engineers, and operations teams, ensuring clear...
$153k - $297k
...currently seeking an Associate Director, AI Security Frontier Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as the primary technical subject... ...of security telemetry, monitoring, and detection engineering capabilities by...H1bLocal area$134.5k - $265.1k
...As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...Engineering team, you will be responsible for:Translating business and cybersecurity... ...concepts (e.g., application security, cloud security, identity, detection engineering).Experience with...Local areaVisa sponsorship$82.6k - $162.8k
...resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be responsible for:Supporting the design and implementation of Customer Identity...Local areaVisa sponsorship$90k - $130k
...federal agencies across civilian, health, and national security environments. We apply modern capabilities,... ...a large-scale federal security operations program responsible for continuous monitoring, threat detection, incident response, and cyber threat intelligence across...Full timeWork experience placementLocal areaImmediate startRemote workFlexible hoursShift work$198k - $368k
...your future as we are, join our team.KPMG is currently seeking a Director, Cyber Architecture & Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as a senior security architect and trusted advisor, leading the development and...H1bLocal area- We are looking for a a Cyber Security Engineer to join our Information Security Team in Kasas City. The work involves SIEM/SOC operations,... ...Collaborate with SOC and monitoring teams to strengthen visibility, detection, and security control effectiveness.Support and improve the...Full timeWork experience placementRemote work
$134.5k - $265.1k
...confidence, and proactively manage to secure success.Recruiting for this role ends on... ...professional at Deloitte Consulting, you will be responsible for delivering high-quality work... ...combines deep technical ownership with engineering expertise, governance, and stakeholder...Local areaVisa sponsorship$127.2k - $246.9k
...as we are, join our team.KPMG is currently seeking a Manager, Content Development, Detection Engineering & Automation to join our Enterprise Security Services organization.Responsibilities:Execute the end-to-end engineering lifecycle (design, development, testing,...H1bLocal area$105.4k - $207.8k
...opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in... ...Cybersecurity, Information Technology, Engineering, Information Systems, or a related...Local areaWorldwideVisa sponsorship$122k - $240.5k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...Trust & Privacy team, you will be responsible for:Translating client business objectives...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Detection & Response. Be the first to apply!
Related searches
- network security engineer Kansas City, MO
- security engineer Kansas City, MO
- IT security engineer Kansas City, MO
- aws cloud security engineer Kansas City, MO
- senior application security engineer Kansas City, MO
- sr information security engineer Kansas City, MO
- information technology security engineer Kansas City, MO
- senior cloud security engineer Kansas City, MO
- associate security engineer
- entry level security engineer



