Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Detection and Response Lead

$160k - $200k
Full-time

Integrated Specialty Coverages, LLC

About Integrated Specialty Coverages

Integrated Specialty Coverages, LLC (ISC) is a growth stage technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market.

Backed by one of the leading private equity firms, Onex Partners, and led by a forward-thinking management team, ISC is combining the worlds of insurance and technology to create an Insurtech powerhouse. As a leading online distributor of insurance products for a range of industries and “Main Street USA”, we are looking for the right people to help us in our mission of achieving exponential growth. We strive to be the number one place to go for brokers and agents to source insurance. To accomplish this, we’re building a digitally focused team that deeply understands the intersection between user experience, data, and AI/ML to optimize the way we engage with our customers and partners.

Job Summary

ISC Cybersecurity is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across our enterprise and AWS environments. The role will report to the CISO and will partner with internal security engineering, as well as with our managed security services provider (MSSP) and managed detection and response (MDR) provider. The Detection & Response Lead focuses on detection engineering, advanced investigation, incident ownership, threat hunting, and maturing our detection and response capabilities. The role serves as the escalation point for security events, ensuring timely containment, high‑quality analysis, and actionable recommendations for improvement. This position is operational and technically deep, driving defensive execution across our AWS and enterprise environments.

Position Responsibilities

  • Incident Response & Investigation
    • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.
    • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and DLP technologies.
    • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Threat Hunting
    • Conduct hypothesis‑driven and data‑driven hunts to identify malicious or suspicious activity not already surfaced by automated detections or MSSP/MDR workflows.
    • Develop internal hunting methodologies rooted in observed attacker behavior, business‑specific risks, and historical incident patterns.
    • Document and socialize hunt outcomes, including new detection opportunities and defensive insights.
  • Detection Quality & Continuous Improvement
    • Review MSSP/MDR escalations for quality, signal‑to‑noise ratio, and fidelity; drive improvements through structured feedback loops.
    • Identify gaps in log coverage, detection logic, or monitoring effectiveness and coordinate with engineering partners to close them.
    • Drive Mean-Time-To-Detect and Mean-Time-To-Contain metrics as well as detection coverage metrics.
  • Escalation Ownership & Internal Coordination
    • Serve as the technical escalation point for security incidents requiring deep analytical expertise.
    • Coordinate cross‑functional responders (IT, cloud, application owners) during active investigations.
    • Maintain tight alignment with MSSP/MDR workflows, ensuring clarity in escalation criteria, response procedures, and incident severity thresholds.
  • Operational Security Leadership
    • Report to CISO and interface with senior leadership during incidents.
    • Maintain operational runbooks, investigation procedures, and response guides.
    • Track recurring attacker patterns and translate them into defensible operational playbooks.

Minimum Qualifications

  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload‑level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings.

Preferred Qualifications

  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting threat hunts in cloud‑first or hybrid environments.
  • Exposure to SIEM/SOAR platforms from an investigative.
  • Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE).

This role also offers bonus pay. Your ISC Talent Acquisition representative will share more details about the bonus component should you advance in the interview process.

The starting annual pay scale for this position is listed below. Actual starting pay will be based on factors such as skills, qualifications, training, and experience. In addition, the company offers comprehensive benefits including medical, dental and vision insurance, 401(k) plan with match, paid time off, and other benefits.

ISC's salary ranges are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.

National Pay Range

$160,000—$200,000 USD

Benefits of Working at ISC

  • Employee Ownership Program - every eligible employee shares in the financial rewards that grow when the company grows
  • Professional development opportunities
  • Owner Referral Program
  • Work from home reimbursement for remote/hybrid roles
  • Canary emergency financial assistance program
  • Comprehensive medical, dental, vision
  • Life/AD&D Insurance
  • Confidential, Employee Assistance Program
  • Health Savings Account, includes company contribution
  • Short-term disability
  • Voluntary benefits - supplemental accident, critical illness, hospital insurance
  • Employee discounts
  • 401(k) Plan with company match contribution
  • Addition Wealth Financial Wellness Program
  • Various Time Off Programs
  • 11 company paid holidays

Applicants may contact the ISC HR department via e-mail or phone to request and arrange for an accommodation that will allow the applicant to successfully complete the application process. Applicants needing assistance may request accommodation at any time. Please contact ISC at View email address on us.fitly.work or View phone number on us.fitly.work.

ISC believes in creating long-term relationships by being responsive and relevant and by consistently delivering value to our community of customers. Specifically, we focus on attracting, developing, and retaining the best talent for our business, challenging our people, demonstrating a “can-do” attitude, and fostering a collaborative and mutually supportive environment.

Diversity creates a healthier atmosphere: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, gender, gender identity, sexual orientation, marital status, medical condition, genetic information, mental or physical disability, military or veteran status, or any other characteristic protected by local, state, or Federal law.

**Must be legally authorized to work in the United States.**

**ISC participates in the Federal E-Verify program**

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Detection and Response Lead in Remote vacancy
  • $10k

     ...move and manage billions, Ramp is the place to do it.About the RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Flexible hours

    Ramp

    New York, NY
    20 hours ago
  • $160k - $200k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Lead based in the United States. As Detection and Response Lead, you will build and lead a technically deep detection and... 
    Suggested
    Full time
    Temporary work
    Remote work
    Work from home

    Jobgether

    Remote
    1 day ago
  • Role Description We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Nebius

    Remote
    1 day ago
  • Blackbaud is seeking a Sr. Manager of Cyber Threat Detection and Response to lead the detection engineering and incident response teams. Responsibilities include developing threat detection frameworks and managing incident response efforts across varied security operations... 
    Suggested
    Remote work
    Flexible hours

    Blackbaud

    New York, NY
    10 hours ago
  • $10k

     ...move and manage billions, Ramp is the place to do it. About the Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    Visa Hunt

    New York, NY
    2 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent...  ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    4 days ago
  • $164.9k - $245k

     ...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense...  ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that...  ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution... 
    Permanent employment
    Full time
    Temporary work
    Remote work

    Joby Aviation

    Santa Cruz, CA
    4 days ago
  •  ...Leading incident response efforts, the full-time Incident Response Lead will manage threat hunting, develop detection mechanisms, and coordinate remediation processes, operating in a hybrid environment from the Washington, DC office or remotely. Key responsibilities Oversee... 
    Full time
    Work at office
    Remote work

    Virtual Vocations Inc

    United States
    20 hours ago
  • $86.8k - $130.2k

     ...information for clients worldwide.Your ImpactThe Lead Service Manager is a senior technical...  ...within the MSS SOC and CSIRT function, responsible for leading and delivering incident...  ...commitments are met without degrading day-to-day detection and response operations. The role... 
    Remote work
    Worldwide

    OpenText

    Waterloo, IL
    4 days ago
  • $40 - $80 per hour

     ...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours
    Night shift

    Alignerr

    United States
    4 days ago
  • $10k

     ...About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our federal and public sector environments. Please note... 
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    RAMP

    New York, NY
    20 hours ago
  •  ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’...  ...actions based upon that analysis. Responsibilities include rapidly responding to potential...  ...the development of security operations detections, playbooks, and automations to ensure threat... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Tempe, AZ
    20 hours ago
  •  ...Job Title: Senior SOC L3 Analyst / Incident Response Lead Location: San Jose, CA (4 days onsite, 1 day remote) About The AES Group...  ..., incident response activities, threat hunting, and detection improvement initiatives across our global environment.... 
    Remote work

    The AES Group

    San Jose, CA
    1 day ago
  • Socket.dev is seeking a Public Health Response Manager to spearhead engagement with state and local public health to translate detection into effective response. You will leverage existing peer relationships to establish partnerships and craft proactive crisis communication... 
    Remote job
    Local area

    Socket.dev

    Cambridge, MA
    4 days ago
  • First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations... 
    Remote job

    First Citizens Bank

    Phoenix, AZ
    3 days ago
  • Tetrad Digital Integrity (TDI) is seeking a Senior Incident Response Analyst to join our SOC and help monitor, detect, investigate, and respond to cybersecurity threats across a large enterprise. The role supports coordinated incident response for a government program,... 
    Remote job
    2 days per week

    Tetrad-Digital-Integrity-LL

    Arlington, VA
    10 hours ago
  •  ...Expert (SME) to provide deep domain expertise supporting fraud detection and identity theft analytics initiatives. This role guides...  ...programs within government or financial institutions. Responsibilities include but are not limited to: Provide domain expertise in... 
    Full time
    Work at office
    Local area
    Remote work

    Elder Research Inc.

    Arlington, VA
    4 days ago
  •  ...partner is looking for a Senior Data Scientist / AI-ML & Anomaly Detection Lead based in United States. This role leads the technical...  ...such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification... 
    Contract work
    Temporary work
    Part time
    Local area
    Remote work
    Flexible hours

    jobgether

    United States
    2 days ago
  •  ...Chameleon is seeking a Senior Data Scientist / AI-ML & Anomaly Detection Lead to drive the technical intelligence layer of a high-...  ...accuracy rate and a 5% or lower false-positive rate. Principal Responsibilities ~POC Library Modernization: Evaluate, enhance, and... 
    Contract work
    Work at office
    Local area

    Chameleon Integrated Services

    Remote
    1 day ago
  • $126k - $180k

     ...appropriate actions based on that analysis. Responsibilities include rapidly responding to potential...  .... Develop security operations detection playbooks, and automate threat detection...  ...processes align with policies and regulations. Lead and mentor junior analysts as needed.... 
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG Bank, Ltd.

    Tempe, AZ
    2 days ago
  •  ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing...  ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their... 
    Work experience placement
    Remote work

    Antigen Security

    Royal Oak, MI
    1 day ago
  •  ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for...  ...team of analysts and associates who detect, investigate, and respond to cyber security...  ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence... 
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Tampa, FL
    20 hours ago
  • $100k - $120k

     ...This position requires a Bachelor's degree and a minimum of 8 years of IT experience, including 4 years specifically in incident response. An active Secret clearance is also essential. The role involves overseeing incident operations, ensuring compliance with standards... 
    Remote work

    SkyePoint Decisions

    New York, NY
    1 day ago
  • $90k - $104.5k

     ...including substantial experience in complex emergency or rapid response settings ~Excellent English oral and written communication skills...  ...interpersonal and professional relationships with the co-leads of the program, donor representatives, host-country counterparts... 
    Full time
    Home office

    World Relief

    Remote
    20 hours ago
  • $58k - $62k

     ...Catholic Charities of the Archdiocese of Newark is currently seeking a  Full Time Lead Mobile Response Worker  for its Mobile Response & Stabilization Services Program located in Jersey City, NJ. POSITION DUTIES: Provides mobile crisis intervention and assessment... 
    Full time
    Immediate start

    Catholic Charities of the Archdiocese of Newark

    Jersey City, NJ
    more than 2 months ago
  • Hewlett Packard Enterprise is searching for a Principal Advanced Threat Response Analyst to lead cybersecurity efforts. The role involves extensive hands-on experience in incident response, threat hunting, and investigations of advanced persistent threats. You will collaborate... 
    Remote job
    Flexible hours

    Hewlett Packard Enterprise

    Spring, Montgomery County, TX
    1 day ago
  • Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading cybersecurity investigations, providing 24/7 emergency response, and managing client relationships during security incidents. Candidates... 
    Remote job

    Zurich North America

    Kansas City, MO
    10 hours ago
  • TTEC is seeking an Incident Response Manager to lead the cybersecurity incident response team from a fully remote position in the United States. You will manage detection, containment, and remediation of threats while guiding analysts, developing IR playbooks, and coordinating... 
    Remote job

    TTEC

    Austin, TX
    10 hours ago
  • TeleTech Holdings, Inc. is seeking an Incident Response Manager to lead our security operations from a remote location in the United States. You will oversee detection, containment, and remediation of cybersecurity threats while guiding a skilled team of analysts. You’... 
    Remote work

    TeleTech Holdings, Inc.

    Austin, TX
    10 hours ago
  • RTX is hiring an AI Governance Analyst to lead governance, risk management and incident response across AI use cases. The role requires managing moderately sized processes, coaching staff and operating with minimal oversight. The ideal candidate brings strong analytics... 
    Remote job

    Relha LLC

    New York, NY
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Detection and Response Lead. Be the first to apply!