Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Threat Detection & Response - Blue Team Lead

$150k - $180k

Stage

COMPANY OVERVIEW

KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR’s insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR’s investments may include the activities of its sponsored funds and insurance subsidiaries.

TEAM OVERVIEW

KKR's Technology organization is a group of passionate technologists and product managers, unified by a shared mission to deliver exceptional products and solutions that drive value for our stakeholders, clients, and investors. Our passion for technology and innovation fuels our commitment to creating high-quality, impactful solutions that address complex challenges and meet the evolving needs of our sophisticated businesses. Teamwork is at the core of the organization’s success. We thrive on open collaboration and continuous learning, driving a culture that values diversity of thought and collective achievement. Our global footprint enables us to integrate diverse perspectives into product and solution delivery, resulting in comprehensive, adaptable, and scalable solutions. We optimize for impact, prioritizing and delivering solutions with excellence while remaining agile in response to the evolving needs of our businesses.

POSITION OVERVIEW

We are seeking a Blue Team Lead to serve as KKR’s U.S. Regional Lead and escalation point for complex cyber incidents within the Threat Detection & Response (TD&R) function in our New York or Boston office. This is a senior incident response leadership role combining deep investigative expertise with ownership of incident command, containment strategy, stakeholder communication, and response readiness. This is an in-office position, 5 days per week. KKR operates in a hybrid environment today; however, our operating model is increasingly cloud-first and identity-first, with growing focus on runtime and SaaS as primary investigative surfaces. This role will help shape how we respond in that future state – partnering closely with our MSSP, internal Computer Incident Response Team (CIRT), and engineering counterparts to drive faster, more consistent outcomes. You will also be a key operational partner to the TDR SOC Engineer (SOC Engineering, Automation & Agentic Workflows) role. The Blue Team Lead defines the incident response requirements, validates that workflows and automation are usable under pressure, and ensures lessons learned translate into durable improvements across people, process, and technology.

RESPONSIBILITIES

Incident Leadership & Command (U.S. Regional Lead) Act as U.S. escalation lead / incident commander for high‑severity incidents, owning response strategy, containment decisions, and coordination through resolution. Lead cross‑functional response with internal CIRT, infrastructure/platform teams, cloud teams, identity teams, legal/compliance, and business stakeholders. Provide executive‑ready briefings and situational updates during active incidents, clearly communicating risk, impact, trade‑offs, and next steps. Ensure post‑incident reviews are completed and translated into measurable remediation and program improvements. Advanced Investigations (Cloud/Identity/Runtime First; Hybrid Aware) Perform and lead advanced investigations across endpoint, network, identity, cloud control plane, SaaS, and (as needed) on‑prem telemetry. Drive evidence collection and preservation strategies appropriate for hybrid environments, including cloud‑native logging and ephemeral workload considerations. Develop investigative narratives: attacker objectives, sequence of actions, impacted assets, containment efficacy, and residual risk. Readiness, Playbooks, and Exercising Own and continuously improve incident response playbooks (e.g., ransomware/extortion, BEC, cloud account compromise, token/key theft, data exfiltration, insider risk). Lead and coordinate exercises and simulations; ensure learnings become concrete improvements (process updates, training, tooling enhancements). Establish escalation criteria and decision frameworks (severity, containment triggers, business engagement, recovery prioritization). AI‑Enabled Response & Analyst Acceleration (Operational Owner) Operationalize AI‑assisted workflows to improve incident execution (e.g., alert/case summarization, timeline generation, correlation support, case documentation), ensuring strong governance, auditability, and human‑in‑the‑loop controls. Partner with SOC Engineering to define requirements and validate that automation/agentic workflows reduce toil and time‑to‑contain without increasing operational risk or noise. Continuous Improvement, Threat‑Informed Defense, and Partner Management Convert incident lessons‑learned into durable improvements across enrichment, routing/prioritization, response plays, and coverage enhancements in partnership with SOC Engineering and ReliaQuest. Support threat hunting and purple‑team efforts by shaping hypotheses and prioritizing validation based on real incident patterns and business risk (enablement and translation to controls – not primary hunt execution). Maintain strong operating rhythm with ReliaQuest and internal teams to ensure smooth escalations, clear responsibilities, and consistent response quality globally. Metrics & Reporting Help define, track, and improve operational KPIs such as MTTR, MTTC, time‑to‑triage, containment SLA adherence, repeat‑incident drivers, and quality of post‑incident actions. Provide insight‑driven reporting to TD&R leadership on trends, systemic issues, and targeted investments needed to raise response maturity.

QUALIFICATIONS

6+ years in Incident Response, Security Operations, or Blue Team roles, including leading high‑severity incidents end‑to‑end. Proven ability to serve as an escalation lead and incident commander – calm, decisive leadership in ambiguous, high‑pressure situations. Strong communication skills: able to translate complex technical details into clear, actionable updates for executives and stakeholders. Experience operating in cloud‑forward enterprises, including hybrid environments spanning SaaS, cloud‑native workloads, and on‑prem systems. Strong familiarity with identity‑centric security models and investigations (federated identity, IAM abuse patterns, token theft, conditional access signals). Working knowledge of cloud‑native architectures (containers/Kubernetes, serverless, CI/CD) and the investigative/containment challenges they introduce. Experience partnering with MSSPs and distributed teams; comfortable operating in a hybrid SOC model (internal + ReliaQuest). Familiarity with MITRE ATT&CK and applying it to investigative thinking, readiness planning, and validation priorities. Experience designing, using, or validating automated response workflows (SOAR) and promoting safe automation patterns. Exposure to AI‑assisted SOC/IR tooling, including governance considerations (data handling, audit logging, human approval, evaluation). Experience with purple teaming, detection validation, or adversary simulation platforms (e.g., Atomic Red Team, Caldera, Cymulate). (Preferred) Ability to influence engineering roadmaps (telemetry, enrichment, workflow improvements) based on operational pain points and incident learnings. (Preferred)

IDEAL CANDIDATE PROFILE

Incident leader: takes ownership, drives clarity, and brings structure to high‑severity response. Technically deep and business‑aware: understands attacker behavior and business impact equally well. Operationally disciplined: strong instincts for repeatability, playbooks, and learning loops. Collaborative and influential: can align MSSP + internal teams, and partner effectively with SOC Engineering and platform teams. Future‑oriented: comfortable modernizing response for cloud‑first and AI‑enabled operating models.

WHY JOIN US

This is a pivotal leadership role in a globally scaled Threat Detection & Response function at a leading investment firm. As U.S. Regional Lead, you will shape incident response outcomes for critical enterprise operations and directly influence how KKR modernizes response for a cloud‑first, AI‑enabled future. You’ll partner with a high‑performing MSSP and an engineering‑driven TDR team to improve readiness, accelerate containment, and raise the bar on response quality across the organization. Base Salary Range: $150,000 – $180,000 USD

EEO STATEMENT

KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law. KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email View email address on click.appcast.io. Emails sent for unrelated issues, such as following up on an application, will not receive a response. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access because of your disability. You can request reasonable accommodations by sending an email to View email address on click.appcast.io. Only emails left for this purpose will be returned. Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. This notice applies only to applicants and employees who work or will work in Massachusetts, in accordance with applicable state law. #J-18808-Ljbffr Stage

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Threat Detection & Response - Blue Team Lead in New York, NY vacancy
  • $234k - $300k

     ...s Cloud SIEM product enables security teams to detect, investigate, and respond to threats across modern cloud and SaaS environments...  ...Product Manager, you will define and lead the vision for our Threat Detection and Incident Response (TDIR) capabilities, with direct... 
    Suggested
    Work at office

    Datadog

    New York, NY
    2 days ago
  • $105.1k - $172.6k

     ...Inc. is one of the world's leading manufacturers, marketers, and...  ...Beauty. Job Overview The Cyber Threat Response (CTR) Lead is a junior...  ...and collaborates with global teams across the company. Responsibilities...  ...incident response, threat detection, security monitoring, and... 
    Suggested
    Full time
    Night shift

    ESTÉE LAUDER COMPANIES

    New York, NY
    a month ago
  •  ...MGA and insurance wholesaler leading innovation in the market....  ...forward-thinking management team, ISC is combining the worlds...  ...hands‑on defender to build a detection and response function responsible for defensive...  ..., incident ownership, threat hunting, and maturing our detection... 
    Suggested

    Integrated Specialty Coverages, LLC

    New York, NY
    14 hours ago
  • A leading cybersecurity firm is seeking an experienced professional for managing Security Incident Response and Threat Hunting. The role requires over 8 years of experience in IT Security...  ...hands-on experience with advanced detection technologies. This is a remote position... 
    Suggested
    Remote job

    Turtle Trax S.A.

    New York, NY
    4 hours ago
  • $10k

    About RampRamp is building the smart infrastructure for finance teams, embedded in the transaction flow of every dollar a business...  ...RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Flexible hours

    Ramp

    New York, NY
    14 hours ago
  • Datadog is seeking a Group Product Manager in New York to lead the vision for Threat Detection and Incident Response capabilities. In this role, you'll define product strategy and manage a team while driving innovation in security operations. The ideal candidate has 7+... 

    Dormont Manufacturing Co

    New York, NY
    2 days ago
  • Sophos is seeking an experienced Incident Response & Threat Intelligence Lead to support clients facing sophisticated security threats. You will lead...  ...insights into actionable guidance for clients and internal teams. You will also act as a key liaison with Sophos Counter... 

    Sophos

    New York, NY
    2 days ago
  • $10k

     ...About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing...  ...Design and implement automation to detect and respond to threats What You Need 3-4 years of information technology... 
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    RAMP

    New York, NY
    5 days ago
  • Pfizer in the United States seeks a Lead Analyst, Threat Remediation to drive remediation across detection, incident response, vulnerability management, and engineering. You will...  ..., GRC, Legal, Privacy, and business teams, and report to the Sr. Manager, Threat Remediation... 

    Pfizer

    New York, NY
    14 hours ago
  •  ...Infrastructure Engineer to protect and enhance the City’s IT infrastructure. You will spearhead cybersecurity incident response, forensics, threat detection, vulnerability management, and governance across on‑premises and cloud environments. The role requires a strong... 

    NYC Citywide Administrative Services

    New York, NY
    1 day ago
  •  ...based opportunity has arisen for a Threat Intelligence Lead to join our Technology team, reporting to the Chief...  ...support strategic decisions, incident response and continuous improvements to our...  ...and procedures and strengthen our detection capabilities. Develop the Proactive... 
    Local area
    Remote work

    Everywhen

    New York, NY
    2 days ago
  • A leading fitness technology company is seeking a Senior Cyber Analyst. You will support their Security Program, perform in-depth intelligence analysis, and develop incident response protocols. The ideal candidate will have at least 5 years of experience in Information... 

    Peloton Interactive

    New York, NY
    3 days ago
  •  ...with us means joining a team of more than 230,000...  ...Citi's Cloud Incident Response (Cloud IR) team seeks a...  ...own and strategically lead security incident response...  ...proactively address emerging threats across cloud, SaaS,...  ...monitoring, threat detection, and response capabilities... 
    Full time

    Citi

    New York, NY
    14 hours ago
  • $115.4k - $192.3k

     ...risk and enhancing fraud detection. We use the power of...  ...of our experienced team, we continuously evolve...  ...roleAs an Analytics Team Lead, you will provide...  ...needs and project demand.Responsibilities· Lead analytics workstreams...  ...emerging and dormant threats. Inspire the wider... 
    Full time
    Local area
    Immediate start
    Remote work

    RELX Group

    New York, NY
    14 hours ago
  • Aegis AI in New York seeks an AI Product Manager to own the roadmap for our threat detection engine—the core layer that identifies, classifies and explains modern email attacks. You will partner with data scientists, AI engineers and security researchers to design how... 

    Aegis AI

    New York, NY
    2 days ago
  •  ...Overview: An IR analyst L3 is responsible for the daily operations of IR...  .... Act as the Incident Lead during significant security events...  ...frameworks, etc.) Experience with threat hunting and operating system...  ...to lead a collaborative team while building inter-departments... 
    Local area
    Worldwide

    B&H Photo-Video-Pro Audio

    New York, NY
    4 days ago
  • Coinbase is seeking a Regional Threat Assessment Manager to lead the Protective Intelligence program regionally...  ...with multiple security and legal teams. You will drive intelligence-led...  ...maturity with structured frameworks and responsible AI practices, while collaborating... 
    Remote job

    Omaze

    New York, NY
    3 days ago
  • $192.6k - $260.5k

     ...Specialized Businesses Security team is seeking a Security Engineer Manager to lead our Specialized Detections team. This is a forward-...  ...Amazon's estate.Key job responsibilities- Work backwards from our Business...  ...- Experience applying threat modeling or other risk identification... 
    Remote work
    Flexible hours

    Amazon

    New York, NY
    2 days ago
  •  ...Army. The candidate will provide vital counterintelligence analysis to protect national interests. Responsibilities include producing intelligence reports, analyzing threats, and supporting strategic military operations. Qualifications include a Master's degree, active... 
    Long term contract

    careers-bluehawk

    New York, NY
    2 days ago
  • $80 - $120 per hour

     ...organization is seeking a First-Line Supervisor of Police and Detectives for a remote role. This position requires strong professional experience and excellent written communication skills. Responsibilities include creating deliverables and reviewing peer work to enhance... 
    Remote job
    Hourly pay
    Contract work
    10 hours per week

    Crossing Hurdles

    New York, NY
    14 hours ago
  • $100k - $120k

    SkyePoint Decisions, Inc. seeks a cybersecurity leader for a remote position focused on threat hunting and analytics. The role involves coordinating with various teams to combat advanced threats and requiring a Bachelor’s degree with 10+ years of experience. Candidates... 
    Remote job
    Flexible hours

    SkyePoint Decisions, Inc.

    New York, NY
    1 day ago
  • $116k - $154k

     ...join the Datadog Procurement team and help expand the Strategic...  ...best fits them.What You'll Do:Lead strategic sourcing for enterprise...  ...IT hardware procurement team responsible for purchasing, sourcing, and...  ...security into one place, using AI to detect and resolve issues before they... 
    Work at office

    Datadog

    New York, NY
    1 day ago
  • $126.82k - $149.2k

     ...One.Job DescriptionThe AI Red Team Lead Engineer leads the execution...  ..., adversarial testing, and threat emulation exercises...  ...articulation of business impact.Key Responsibilities:Lead AI Red Team operations,...  ...defensive gaps.Partner with detection, engineering, and governance... 
    Full time
    Local area
    3 days per week

    US Bank

    New York, NY
    4 days ago
  •  ...Job Details: SOC Team Lead * Oversee day-to-day SOC operations ensuring effective detection, investigation, and response to cybersecurity threats. * Mentor and coach L1 and L2 SOC analysts, fostering professional growth and knowledge sharing. * Perform root... 
    Remote work

    3B Staffing LLC

    New York, NY
    4 days ago
  •  ...you will carry outsized responsibility and grow as quickly as...  ...built. You will lead security across the company...  ...secure defaults other teams can operate. You own...  ...and sensitive-data detection, reusable authorization...  ...prioritized roadmap Threat-model product, data,... 
    For contractors

    Sunsets HQ Corp.

    New York, NY
    5 days ago
  •  ...Senior Associate, Security Operations to join its expanding team in New York. This role is pivotal in managing day-to-day security operations and involves coordinating with our managed detection and response provider. The ideal candidate should have over 5 years of experience... 

    Andersen

    New York, NY
    4 days ago
  •  ...looking for a Customer Support Lead to build and run Fun's end‑...  ...'ll join a lean, high‑caliber team with outsized impact on how this...  ...SOPs, escalation frameworks, and response playbooks across all user‑...  ...reduce ticket volume — intent detection, automated classification, self... 
    Live in
    Work from home
    Monday to Thursday
    Shift work

    Funxyz

    New York, NY
    5 days ago
  • $100k - $130k

    A leading cybersecurity firm is seeking a proactive Security Analyst to join their team in the United States. This role involves monitoring security alerts, responding to incidents, and developing threat detection capabilities. The ideal candidate will have 4-6 years of... 
    Remote job

    BLACKCLOAK

    New York, NY
    14 hours ago
  • $130k - $200k

     ...unmet medical needs. As a leading innovator of Digital...  ...inspire a high-performing team, while strategically collaborating...  ...in office each week. Responsibilities: Maintain, and...  ...capabilities, including threat intelligence, monitoring, detection, and analysis.... 
    Permanent employment
    Temporary work
    Work at office
    Local area
    Visa sponsorship
    Flexible hours

    Click Therapeutics

    New York, NY
    3 days ago
  •  ...Our Fraud Intelligence team's mission is to turn fraud...  ...the Fraud Intelligence Lead, you will build and run...  ...a Staff Researcher) responsible for live casework across...  ...tooling, and emerging threat vectors Proactively...  ...toolchains (BI tools, anomaly detection, case trackers) ~ SQL... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    Plaid

    New York, NY
    11 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Threat Detection & Response - Blue Team Lead. Be the first to apply!