Detection and Response Engineer [Remote]
$100k - $145kjobgether
- Remote job
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Engineer based in the United States.
This full-time remote role focuses on strengthening detection, incident response, security automation, and AI-enabled SOC operations.
You will engineer and continuously improve security detection capabilities across endpoint, network, cloud, and identity environments.
The role combines hands-on threat detection with incident investigation, forensic support, automation, and security tooling.
You will help close visibility gaps, reduce manual analyst effort, and accelerate the path from detection through resolution.
A key component of the position involves evaluating and implementing AI and LLM-powered capabilities for security operations.
You will collaborate closely with SOC, IT, cloud, network, identity, and engineering teams in a fast-moving security environment.
Your work will directly contribute to improving the organization's ability to identify, investigate, contain, and respond to evolving cyber threats.
Accountabilities
Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources.
Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements.
Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness.
Maintain and version-control detection rules, associated documentation, coverage information, and known gaps.
Triage, investigate, and contain security incidents and alerts across the environment.
Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements.
Document incident timelines, indicators of compromise, remediation activities, and investigative findings.
Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required.
Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows.
Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond.
Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation.
Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations.
Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing.
Build and maintain incident response playbooks, runbooks, and supporting procedures.
Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources.
Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps.
Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments.
Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders.
Maintain procedures and policy documentation supporting detection and response operations.
Requirements
Bachelor’s degree in a technical field or equivalent professional experience.
3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations.
Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel.
Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources.
Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis.
Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.
Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms.
Working knowledge of PCI-DSS or a comparable security and compliance framework.
Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences.
Experience with SOAR platforms such as n8n or Tines is a plus.
Experience integrating or building with LLM and AI APIs for security use cases is beneficial.
Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous.
Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus.
Familiarity with payment or fintech regulatory environments is beneficial.
Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized.
Benefits
Salary: $100,000–$145,000 annually.
Compensation within the range varies based on work location, job-related knowledge, skills, and experience.
Full-time, fully remote position within the United States.
Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations.
Opportunity to work with emerging AI and LLM technologies applied to cybersecurity.
Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams.
Opportunity to contribute to security capabilities within a payment technology environment.
Benefits and total rewards offerings are discussed throughout the interview process.
Inclusive work environment with a focus on employee well-being and professional development.
No current or future visa sponsorship is available for this position.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles / Seattle / NYC Duration: Long-Term Contract Responsibilities The Global Security Organization provides industry leading security and privacy services to the client, globally. Our organization...SuggestedLong term contract
$142.9k - $207.2k
...You're the detection engineer people turn to when they ask "what does Microsoft actually see here?" Not the marketing-slide answer, the real... ...talent gap by providing transparent Managed Detection and Response. To do this we build technology to make sure our security analysts...SuggestedFull timeLive inWork at officeRemote workVisa sponsorshipShift work$119.32k - $202.85k
Description ICF is actively recruiting for an experienced Senior Threat Detection & Response Engineer to support the research and development of new cyber analytic capabilities that will help the US protect and defend its networks and critical information systems. The successful...SuggestedFull timeContract workWork at officeRemote work- ICF is seeking an experienced Senior Threat Detection & Response Engineer to support R&D of cyber analytic capabilities for federal networks. The role is primarily telework-based with occasional client or ICF facility meetings in the DC metro area. Responsibilities include...SuggestedRemote job
$240k - $290k
...hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv. Runway is hiring a Detection & Response Engineer to own how we find and stop attacks against our infrastructure, our research environment and our products. Securing a...SuggestedFull timeRemote work$221k - $299k
...023, 2024) About the Role You'll own our Incident Detection and Response program, including threat modeling our systems and codebase... ...happen. You'll join a team that includes an AppSec-focused engineer and an infrastructure-focused engineer, and you'll guide technical...Full timeContract workWork at officeImmediate startRemote workFlexible hours3 days per week$77.9k - $153k
Cybersecurity Detection & Response Engineer Job Locations US-IL-Plainfield | US-IL-Tinley Park | US-IL-Chicago | US-IN-Evansville | US-IN-Highland Category/Function Information Technology Position Type Regular Full-Time Requisition ID 2026-20616 Workplace Type...Full time$320k - $405k
...growing group of committed researchers, engineers, policy experts, and business leaders... ...engineer to join Anthropic's Detection Platform team to build and scale our next... ...to transform security operations. Responsibilities: Build AI-powered platform responsible...Full timeWork at officeVisa sponsorshipFlexible hoursShift work$110k - $170k
...its competitive edge. Position Overview: The Alert, Detection, and Response Associate is a Tier 2 incident responder on the Alert,... ...with experience explaining an incident and its impact to both engineers and non-technical stakeholders ~ Experience self-organizing...Full timeLocal area$189k - $303k
Staff Cybersecurity Engineer Aurora's mission is to deliver the benefits of self-driving technology safely, quickly,... ...Cybersecurity Engineer to help mature Cloud & Enterprise Detection within our Detection & Response (D&R) team, under the Technical Assurance division....Work at officeLocal area3 days per week$200k - $240k
...build the tools and systems that defend it, and partner with engineering teams as they ship new products and features. Our work... ...Now is the time to join! Here's why: Build out our detection and response function. Liftoff has a mature security information and event...Full timeRemote work$123.7k - $254.67k
...philosophy and how we use AI in our recruiting process here. Pinterest is seeking an experienced Security Engineer to build and implement detection and response improvements and adapt to emerging threats to protect employees and infrastructure. In this role you will...Full timeWork at officeLocal areaRemote workRelocationRelocation package$209k - $313k
...Senior Security Engineer Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve... ...We're looking for a Senior Security Engineer to join our Detection and Response (D&R) team! What you'll do: Design, pilot, and implement...Live inWork at officeLocal area- ...Job Summary: The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active...
$132.95k - $189.93k
...capabilities needed to welcome a billion customers. Security engineers at Spotify protect our platform, employees, creators, and... ...looking for an experienced Security Engineer to join the Detection and Response organization and help identify, investigate, and respond to...Full timeWork from homeFlexible hours$70 - $80 per hour
...Francisco, CA Salary: $70.00 USD Hourly - $80.00 USD Hourly Description: Our client is currently seeking a Sr. Security Engineer, Threat Detection & Response This job will have the following responsibilities: Perform investigations of security incidents using your...Hourly pay$155k - $400k
...About The Role The Security Team is responsible for securing all things Sentry: our customers... ...problems with creativity and an engineering mindset. We work at a company with a strong... ...build and contribute to systems which detect malicious activity, you will have the unique...Hourly pay$167.5k - $235k
...If this sounds like you, you'll fit right in. Who You Are Justworks is looking for an experienced security engineer skilled in detection and response, who can help enhance and mature Justworks' Security. As a Senior Detection Engineer, you'll design, build, and maintain...Casual workLocal area- ...apply below. About the role We are looking for a Security Engineer to help build and strengthen security foundations from the... ...a fast-moving startup environment, with a primary focus on detection and response. This is a strong opportunity for someone early in their career...Work at officeImmediate startRemote workFlexible hoursShift work
- Security Engineer Detection & Response Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. We are technical in what we build but...
$320k - $405k
Security Software Engineer, Detection & Response Platform New York City, NY | Seattle, WA; San Francisco, CA | Washington, DC About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our...Work at officeVisa sponsorshipFlexible hoursShift work- Fluidstack is seeking a seasoned Incident Response Lead to secure our frontier compute infrastructure across corporate, cloud, and data center environments. You will own end-to-end IR from detection to eradication, drive cross‑team investigations, and define severity models...
$200k - $300k
...team of computer scientists, hardware engineers and experienced founders who saw a chance... ...by our commitment to using technology responsibly. We believe keeping data private and secure... ...improve Verkada’s Security Monitoring, Detection and Response infrastructure Onboard...Full timeWork visaFlexible hoursShift work$196.75k - $243.29k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a Senior Security Engineer on the Detection and Response (D&R) team at Roblox, you’ll protect our user community alongside the underlying platform infrastructure. You’ll design...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$174.5k - $240k
...to join us as we power the shop local movement. If you believe in community, come join ours.About this roleAs our first Detection & Response engineer, you'll build that capability from the ground up focused on our enterprise environment. Looking for and monitoring threats...Work experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hours3 days per week$174.5k - $240k
...Responsibilities Define the technical direction, roadmap, tooling needs, and operating standards for detection and response at Faire. Build enterprise detection engineering end to end, including telemetry pipelines, detection content, alert routing, and enrichment...Full timeWork at officeRemote workMonday to FridayFlexible hours3 days per week- ...Analyst III to join the Cybersecurity Operations Center team in Austin. This onsite role focuses on security engineering, monitoring, detection, and incident response across on-premises and cloud environments. As a CSOC Engineer you will design and maintain SIEM/EDR/XDR,...
- Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations... ...systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities....Local areaWorldwide
$187k - $220k
Senior Security Engineer, Detection & Response Bellevue, WA; Denver, CO; Menlo Park, CA Join Us In Building The Future Of Finance Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two...Work at officeFlexible hoursShift work3 days per week- ...engaging a robust security culture. About the Role As a Security Engineer you will join our OpenAI engineers and researchers in... ...transformational AI technologies. This role will focus on all aspects of Detection & Response but with a strong emphasis on detecting insider threats and...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection and Response Engineer [Remote]. Be the first to apply!
- supply chain analyst remote United States
- procurement specialist remote United States
- physician consultant remote United States
- remote insurance agent United States
- remote data manager United States
- training manager remote United States
- remote concierge United States
- remote ui developer United States
- remote customer service advisor United States
- it manager remote United States


