Security Engineer, Detection & Response
Cybersecurity Jobs
The Security Engineer, Detection & Response will be an essential member of the Lockton Global Security Operations team, driving technical incident response from detection through recovery while also strengthening detections when there is no active incident. The role also leads cyber threat intelligence, threat hunting, and red and purple team activities, serving as the senior SOC technical escalation point.
Key Responsibilities
- Incident Leadership: Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
- Incident Documentation and Process Adherence: Own incident documentation and ensure required communication and escalation processes are followed.
- Forensic Analysis: Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
- Evidence Integrity and Reporting: Preserve data integrity and produce detailed forensic and incident reports.
- Root Cause and Lessons Learned: Conduct root cause analysis for significant incidents and convert findings into concrete improvements to detections, controls, and playbooks.
- Readiness: Maintain and improve incident response playbooks and runbooks.
- Exercises and Coordination: Plan and run tabletop exercises with both technical and executive audiences across regions.
- Cyber Threat Intelligence Program: Build and run Lockton’s CTI capability.
- Intelligence Collection and Prioritization: Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
- Threat Actor Tracking: Track threat actors, campaigns, and techniques relevant to Lockton, the insurance and financial services sector, and the regions where Lockton operates.
- Threat Briefings: Maintain actor profiles and deliver regular threat briefings to security leadership and the broader team.
- Operationalizing Intelligence: Convert intelligence into action by feeding indicators and behaviors into the detection stack, generating hunt hypotheses, informing vulnerability prioritization, and supporting security awareness content for active phishing, vishing, and social engineering campaigns.
- Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
- Detection Improvement from Hunt Outcomes: Convert hunt findings into durable detections.
- Red Team and Purple Team Exercises: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement; emulate actor TTPs identified through CTI.
- Detection Validation: Partner with the SOC and detection engineering to measure whether controls detect and respond as expected, mapping coverage and gaps to MITRE ATT&CK .
- Remediation Workflow: Deliver prioritized remediation recommendations based on findings, then retest to confirm gaps are closed.
- SOC Escalation: Serve as the senior technical escalation point for complex or high-severity alerts, including those involving Lockton’s managed detection and response partner.
- Triage and Incident Determination: Guide triage decisions and determine when an alert escalates to an incident.
- Reduce False Positives: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results to reduce false positives and close visibility gaps.
- Mentoring and Knowledge Sharing: Improve SOC capability through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
- Cross-Functional Collaboration: Coordinate with IT, Legal, and other departments to support a comprehensive response to security threats.
- On-Call Coverage: Respond to security-related emergencies that may occur outside regular business hours and participate in the security team On-Call rotation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Minimum 5 years of information security experience with hands‑on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
- Relevant certifications are highly desirable, such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP .
- Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
- Hands‑on experience with EDR and SIEM platforms.
- Strong plus: experience with CrowdStrike Falcon , Microsoft Sentinel , and Microsoft Defender XDR .
- Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
- Experience with scripting and query languages ( PowerShell , Python , KQL ) for automation, analysis, and detection development.
- Experience with adversary emulation tooling (examples include Atomic Red Team , MITRE Caldera , or command and control frameworks) and running exercises safely in production environments.
- Excellent problem‑solving skills, including the ability to work under pressure.
- Meticulous attention to detail to ensure accuracy and integrity of forensic investigations and incident reports.
- Strong written and verbal communication skills, including the ability to produce intelligence products and incident reports for technical and executive audiences.
- Ability to collaborate effectively in a team environment with cross‑functional stakeholders.
- Willingness to stay current with attacker tradecraft, cloud security, and emerging threats, including AI‑enabled attacks, and continuously enhance skills.
Relevant Technologies
- MITRE ATT&CK
- EDR
- SIEM
- CrowdStrike Falcon
- Microsoft Sentinel
- Microsoft Defender XDR
- PowerShell
- Python
- KQL
- Atomic Red Team
- MITRE Caldera
- Active Directory
- Entra ID
- Microsoft 365
- Azure
Role Details
- Business Unit: Lockton Center Services
- Schedule: Full‑time
- Workplace: Hybrid
- Location: Kansas City, MO
Minimum Experience
Minimum 5 years of experience in information security.
#J-18808-Ljbffr- ...Job Summary: The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active...Suggested
- ...Security Engineer TENEX is an AI-native, automation-first, built-for-scale Managed Detection and Response (MDR) provider. We are a force multiplier for defenders, helping organizations enhance their cybersecurity posture through advanced threat detection, rapid response...Suggested
- ...Security Detection Engineer The Security Detection Engineer is a senior, hands-on technical role responsible for building, tuning, validating, and operating security detections across CBIZ environments. Detection engineering is the core of the role: translating threat...Suggested
$2,500 per month
The Red Team - SrSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes... ...environments, and applications, and partner with detection engineering to close the gaps those exercises...SuggestedFull timeWork experience placement$119k - $154k
...Description:Role Overview The Senior Information Security Engineer will be a part of Cboe’s Security Engineering and... ...Management (SIEM), Security Orchestration and Automation Response (SOAR / Case Management), Endpoint Detection and Response (EDR), Secure Email Gateways, and...SuggestedFull time$119k - $169.4k
...Role Overview The Network Security Team is seeking a Sr. Network and Firewall Security Engineer to secure and operate... ...complex problems from initial detection through resolution. This... ...capability of the team. Your responsibilities will be: Design, deploy...Work at officeImmediate startNight shift- ...Senior Security Engineer Propio Language Services is a provider of the highest quality interpretation... ...the Information Security department, responsible for performing cybersecurity risk... ..., and endpoint security solutions, to detect potential threats Safely acquire...Work experience placement
- ...seeking a highly motivated and passionate Security Engineer with a specialized focus on Google... ...Google security solutions. Your responsibilities will include: Infrastructure Provisioning... ...response processes, and threat detection methodologies. Google SecOps Focus...Temporary work
$198k - $368k
...currently seeking a Director, Global Security Engineering Lead to join our Global Digital Group which is part of KPMG International.Responsibilities:Own the engineering architecture, availability... ...analyst effort and mean time to detect and respondLead the design,...H1bLocal area- ...Senior Product Security Engineer The Senior Product Security Engineer is a deeply technical... ...engineering and architect-level role responsible for establishing and leading the Product... ...container image scanning, and secrets detection. Define vulnerability remediation...
$119k - $154k
...productivity and growth.Role OverviewThe Senior Information Security Engineer will be a part of Cboe’s Security Engineering and... ...(SIEM), Security Orchestration and Automation Response (SOAR / Case Management), Endpoint Detection and Response (EDR), Secure Email Gateways, and...Full timeWork at officeImmediate start$41.57 per hour
...Security Engineer Requisition ID 2026-39456 Requisition Post Information* : Posted Date 6 days ago(9/23/2026 9:37... ...our hospital. Overview The Security Engineer will be responsible for installing, configuring, and managing security tools to...Full timeWork experience placementSeasonal workLive inRemote workWork from homeMonday to Friday$105.4k - $207.8k
...Summary Cyber Palo Alto Networks Security Engineer/ Senior Consultant, Strategy, Growth,... ...Enterprise Security team, you will be responsible for…Designing, deploying, and managing... ...intrusion prevention system/intrusion detection system (IPS/IDS), Anti-Spyware,...Work experience placementLocal areaRemote work$2,500 per month
The ApplicationSecurity Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes... ...incident response process by aiding in the detection, containment, and reporting of incidents.Deploy, integrate...Full timeWork experience placement- ...be hired anywhere in the continental U.S.The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR... .... The role owns the engineering function behind Managed Detection and Response (MDR), co-managed SIEM, data engineering, and...Full timeWork experience placementLocal areaRemote workWork from home
$90k - $110k
...Design, develop, and operationalize secure agentic AI capabilities in risk &... ...powered security agents to augment detection, investigation, and response workflowsIdentify high-value use cases... ...leading enterprise-scale security engineering initiatives5+ years of progressive...Full time- We are looking for a Cyber Security Engineer to join our growing Cyber Defense team in our Overland... ....Hands-on experience with incident response, alert handling, and SOC‑driven... ...Assist in tuning scanning tools, adjusting detection policies, and improving asset coverage...Full timeWork at officeMonday to Friday3 days per week
- ...are seeking a full-time Senior Cyber Security Engineer at Garmin's U.S. headquarters in the Greater... ...City area. In this role, you will be responsible for developing security roadmaps,... ...stakeholders to strengthen protection, detection, and response capabilities in alignment...Full time
$140.3k - $233.8k
...want to hear from you.CoverMyMeds is seeking a Senior Product Security Engineer, AI & DevSecOps to embed security throughout our software... ...including SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure scanningDesign security...Full timeH1bRemote work- ...DescriptionCollaborate with the Information Security team and IT, OT, and asset owners to... ...), and plant networks.Job Duties and Responsibilities:Own day-to-day execution and continuous... ...infrastructure, application owners, plant engineers, and operations teams, ensuring clear...
$134.5k - $265.1k
...As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...Engineering team, you will be responsible for:Translating business and cybersecurity... ...concepts (e.g., application security, cloud security, identity, detection engineering).Experience with...Local areaVisa sponsorship$153k - $297k
...currently seeking an Associate Director, AI Security Frontier Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as the primary technical subject... ...of security telemetry, monitoring, and detection engineering capabilities by...H1bLocal area- ...needs and requirements. Develop effective Security, VMS, and Access Control system... ...and customer expectations. CORE RESPONSIBILITIES include, but are not limited to the following... ...disabilities. Communications Engineering Company is an Equal Opportunity/...Seasonal workWork at officeRemote work
$155.6k - $306.8k
...and proactively manage their security posture.Recruiting for this role... ...:As a Cyber Forward Deployed Engineer (FDE) Manager, you will lead... ..., GPT-4o, Assistants API, Responses API, OpenAI Agents Experience... ...security, cloud security, identity, detection engineering).Experience with...Local areaVisa sponsorship$82.6k - $162.8k
...resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be responsible for:Supporting the design and implementation of Customer Identity...Local areaVisa sponsorship- Position Summary Deloitte Global is the engine of the Deloitte network. Our... ...organization. Work you'll do This role is responsible for providing penetration testing services... ...integrating emerging AI-assisted offensive security tooling into team methodology and...Visa sponsorship
$105.4k - $207.8k
...opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in... ...Cybersecurity, Information Technology, Engineering, Information Systems, or a related...Local areaWorldwideVisa sponsorship$198k - $368k
...your future as we are, join our team.KPMG is currently seeking a Director, Cyber Architecture & Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as a senior security architect and trusted advisor, leading the development and...H1bLocal area$122k - $240.5k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...Trust & Privacy team, you will be responsible for:Translating client business objectives...Local areaVisa sponsorship- ...importantly, the patients we serve. We are EVERSANA. Job Description THE POSITION : The AI Security Engineer I supports the security, governance, and responsible use of AI, Machine Learning (ML), and Generative AI technologies across EVERSANA. This role assists...Full timeWork at officeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Detection & Response. Be the first to apply!
- senior cloud security engineer Kansas City, MO
- aws cloud security engineer Kansas City, MO
- sr information security engineer Kansas City, MO
- network security engineer Kansas City, MO
- information technology security engineer Kansas City, MO
- security engineer Kansas City, MO
- IT security engineer Kansas City, MO
- application security engineer
- principal security engineer
- senior cloud security engineer




