Detection and Response Lead
$160k - $200kJobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Lead based in the United States.
As Detection and Response Lead, you will build and lead a technically deep detection and response capability across enterprise and cloud environments. You will own advanced investigations, incident response, threat hunting, and continuous improvement of defensive security operations. Working closely with security engineering and external MSSP/MDR partners, you will serve as the escalation point for complex security events and drive incidents through investigation, containment, and remediation. The role combines hands-on technical execution with operational leadership and close partnership with the CISO and senior stakeholders. You will strengthen detection quality, improve monitoring coverage, and develop repeatable response processes and playbooks. Your work will directly improve the organization’s ability to detect, understand, and contain sophisticated threats across AWS, Azure, endpoints, identities, and enterprise infrastructure.
\n Accountabilities:- Lead incident response for escalated MSSP and MDR alerts, including scoping, investigation, containment, and remediation across cloud, endpoint, identity, and enterprise environments.
- Provide emergency-only on-call support for high-severity security incidents when required.
- Conduct detailed forensic investigations using SIEM, EDR, proxy, WAF, DLP, cloud, endpoint, and network telemetry to reconstruct events and identify attacker activity.
- Correlate logs and security events to establish accurate incident timelines, determine scope and impact, and identify attacker techniques and behaviors.
- Produce concise, high-quality investigative reports outlining findings, timelines, root causes, business impact, and recommended remediation actions for both technical and non-technical stakeholders.
- Conduct hypothesis-driven and data-driven threat hunts to uncover malicious or suspicious activity that has bypassed automated detections and external monitoring workflows.
- Develop repeatable threat-hunting methodologies based on attacker behavior, business-specific risks, historical incidents, and emerging threat patterns.
- Document and communicate threat-hunting outcomes, translating discoveries into new detection opportunities and defensive improvements.
- Review MSSP and MDR escalations for quality, signal-to-noise ratio, accuracy, and detection fidelity, establishing structured feedback loops to improve external security operations.
- Identify gaps in logging, telemetry, detection logic, monitoring coverage, and investigative capabilities, and partner with security engineering and technology teams to close those gaps.
- Establish and improve metrics such as Mean Time to Detect, Mean Time to Contain, and detection coverage to measure and strengthen defensive effectiveness.
- Serve as the primary technical escalation point for security incidents requiring advanced analytical, investigative, or containment expertise.
- Coordinate cross-functional response efforts involving IT, cloud teams, application owners, security engineering, and other technical stakeholders during active incidents.
- Maintain strong alignment with MSSP and MDR partners by defining clear escalation criteria, severity thresholds, response procedures, ownership models, and communication expectations.
- Report significant incidents, detection trends, response performance, and security risks to the CISO and senior leadership.
- Develop and maintain operational runbooks, investigation procedures, incident response guides, and defensive playbooks.
- Analyze recurring attacker behaviors and translate lessons learned from investigations and hunts into durable operational processes and detection improvements.
- Help shape and mature the broader detection and response program, identifying opportunities to improve tools, processes, workflows, and organizational readiness.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
- 7+ years of hands-on experience in cybersecurity operations, incident response, threat detection, or a closely related security discipline.
- Demonstrated experience leading complex security investigations involving cloud environments, identity systems, endpoints, networks, and modern security tooling.
- Proven ability to build, mature, or significantly improve a detection and response program in partnership with security leadership.
- Strong knowledge of attacker tactics, techniques, and procedures, including practical application of frameworks such as MITRE ATT&CK.
- Hands-on expertise in log analysis, event correlation, security telemetry, and investigative techniques.
- Practical knowledge of digital forensics fundamentals, including artifact analysis, timeline creation, host investigation, and network investigation.
- Experience independently taking ownership of escalated MDR or MSSP alerts and driving investigations through deeper analysis, containment, and remediation.
- Strong experience analyzing AWS and Azure security telemetry, including CloudTrail, CloudWatch, IAM, network telemetry, and workload-level events.
- Demonstrated ability to take appropriate containment actions in cloud environments while balancing security, operational continuity, and business requirements.
- Experience working with SIEM, EDR, proxy, WAF, DLP, or related security technologies from an investigative and incident-response perspective.
- Strong understanding of how to operate effectively alongside managed SOC, MSSP, or MDR providers and integrate external security operations with internal response capabilities.
- Prior threat-hunting experience in cloud-first, hybrid, or complex enterprise environments is highly desirable.
- Incident response or digital forensics certifications such as GCIH, GCFA, GNFA, or GCFE are advantageous.
- Excellent written and verbal communication skills, with the ability to communicate complex technical findings clearly and concisely to both technical teams and senior leadership.
- Strong analytical thinking, investigative curiosity, sound judgment, and the ability to remain composed during high-severity incidents.
- Ability to work independently while collaborating effectively across security engineering, IT, cloud, application, and business teams.
- Must be legally authorized to work in the United States.
Benefits
- $160,000–$200,000 USD annual base salary , with actual starting compensation determined by skills, qualifications, training, and experience.
- Eligibility for bonus compensation .
- Comprehensive medical, dental, and vision insurance.
- 401(k) retirement plan with company matching contributions.
- Employee Ownership Program, allowing eligible employees to share in financial rewards as the organization grows.
- Professional development opportunities.
- Owner Referral Program.
- Work-from-home reimbursement for eligible remote or hybrid roles.
- Canary emergency financial assistance program.
- Life and AD&D insurance.
- Confidential Employee Assistance Program.
- Health Savings Account with company contribution.
- Short-term disability coverage.
- Voluntary accident, critical illness, and hospital insurance options.
- Employee discounts.
- Addition Wealth financial wellness program.
- Various paid time-off programs.
- 11 company-paid holidays.
- Collaborative and mutually supportive work environment.
- Opportunities to work closely with security leadership and help shape a growing detection and response function.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
$10k
...move and manage billions, Ramp is the place to do it.About the RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our...SuggestedFull timeWork experience placementWork at officeHome officeFlexible hours$160k - $200k
...technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market. Backed by one of the leading... ...is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across...SuggestedFull timeTemporary workWork experience placementLocal areaRemote workWork from home- Role Description We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and...SuggestedFull timeRemote workFlexible hours
- Blackbaud is seeking a Sr. Manager of Cyber Threat Detection and Response to lead the detection engineering and incident response teams. Responsibilities include developing threat detection frameworks and managing incident response efforts across varied security operations...SuggestedRemote workFlexible hours
$10k
...move and manage billions, Ramp is the place to do it. About the Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our...SuggestedFull timeWork experience placementWork at officeHome officeRelocation packageFlexible hours2 days per week$140k - $150k
Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent... ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the...Work at officeRemote work$164.9k - $245k
...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense... ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that... ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution...Permanent employmentFull timeTemporary workRemote work- ...Leading incident response efforts, the full-time Incident Response Lead will manage threat hunting, develop detection mechanisms, and coordinate remediation processes, operating in a hybrid environment from the Washington, DC office or remotely. Key responsibilities Oversee...Full timeWork at officeRemote work
$86.8k - $130.2k
...information for clients worldwide.Your ImpactThe Lead Service Manager is a senior technical... ...within the MSS SOC and CSIRT function, responsible for leading and delivering incident... ...commitments are met without degrading day-to-day detection and response operations. The role...Remote workWorldwide$40 - $80 per hour
...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned...Hourly payOngoing contractContract workFreelanceRemote workFlexible hoursNight shift$10k
...About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our federal and public sector environments. Please note...Full timeWork experience placementWork at officeHome officeRelocation packageFlexible hours2 days per week- ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’... ...actions based upon that analysis. Responsibilities include rapidly responding to potential... ...the development of security operations detections, playbooks, and automations to ensure threat...Full timeWork at officeLocal areaRemote work1 day per week
- ...Job Title: Senior SOC L3 Analyst / Incident Response Lead Location: San Jose, CA (4 days onsite, 1 day remote) About The AES Group... ..., incident response activities, threat hunting, and detection improvement initiatives across our global environment....Remote work
- Socket.dev is seeking a Public Health Response Manager to spearhead engagement with state and local public health to translate detection into effective response. You will leverage existing peer relationships to establish partnerships and craft proactive crisis communication...Remote jobLocal area
- First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations...Remote job
- Tetrad Digital Integrity (TDI) is seeking a Senior Incident Response Analyst to join our SOC and help monitor, detect, investigate, and respond to cybersecurity threats across a large enterprise. The role supports coordinated incident response for a government program,...Remote job2 days per week
- ...Expert (SME) to provide deep domain expertise supporting fraud detection and identity theft analytics initiatives. This role guides... ...programs within government or financial institutions. Responsibilities include but are not limited to: Provide domain expertise in...Full timeWork at officeLocal areaRemote work
- ...partner is looking for a Senior Data Scientist / AI-ML & Anomaly Detection Lead based in United States. This role leads the technical... ...such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification...Contract workTemporary workPart timeLocal areaRemote workFlexible hours
- ...Chameleon is seeking a Senior Data Scientist / AI-ML & Anomaly Detection Lead to drive the technical intelligence layer of a high-... ...accuracy rate and a 5% or lower false-positive rate. Principal Responsibilities ~POC Library Modernization: Evaluate, enhance, and...Contract workWork at officeLocal area
$126k - $180k
...appropriate actions based on that analysis. Responsibilities include rapidly responding to potential... .... Develop security operations detection playbooks, and automate threat detection... ...processes align with policies and regulations. Lead and mentor junior analysts as needed....Work at officeLocal areaRemote work1 day per week- ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing... ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their...Work experience placementRemote work
- ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for... ...team of analysts and associates who detect, investigate, and respond to cyber security... ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence...Remote workFlexible hours
$100k - $120k
...This position requires a Bachelor's degree and a minimum of 8 years of IT experience, including 4 years specifically in incident response. An active Secret clearance is also essential. The role involves overseeing incident operations, ensuring compliance with standards...Remote work$90k - $104.5k
...including substantial experience in complex emergency or rapid response settings ~Excellent English oral and written communication skills... ...interpersonal and professional relationships with the co-leads of the program, donor representatives, host-country counterparts...Full timeHome office$58k - $62k
...Catholic Charities of the Archdiocese of Newark is currently seeking a Full Time Lead Mobile Response Worker for its Mobile Response & Stabilization Services Program located in Jersey City, NJ. POSITION DUTIES: Provides mobile crisis intervention and assessment...Full timeImmediate start- Hewlett Packard Enterprise is searching for a Principal Advanced Threat Response Analyst to lead cybersecurity efforts. The role involves extensive hands-on experience in incident response, threat hunting, and investigations of advanced persistent threats. You will collaborate...Remote jobFlexible hours
- Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading cybersecurity investigations, providing 24/7 emergency response, and managing client relationships during security incidents. Candidates...Remote job
- TTEC is seeking an Incident Response Manager to lead the cybersecurity incident response team from a fully remote position in the United States. You will manage detection, containment, and remediation of threats while guiding analysts, developing IR playbooks, and coordinating...Remote job
- TeleTech Holdings, Inc. is seeking an Incident Response Manager to lead our security operations from a remote location in the United States. You will oversee detection, containment, and remediation of cybersecurity threats while guiding a skilled team of analysts. You’...Remote work
- RTX is hiring an AI Governance Analyst to lead governance, risk management and incident response across AI use cases. The role requires managing moderately sized processes, coaching staff and operating with minimal oversight. The ideal candidate brings strong analytics...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection and Response Lead. Be the first to apply!





