Threat Detection & Response - Blue Team Lead
$150k - $180kKKR
Threat Detection & Response - Blue Team Lead
New York or Boston
KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR's insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR's investments may include the activities of its sponsored funds and insurance subsidiaries.
KKR's Technology organization is a group of passionate technologists and product managers, unified by a shared mission to deliver exceptional products and solutions that drive value for our stakeholders, clients, and investors. Our passion for technology and innovation fuels our commitment to creating high-quality, impactful solutions that address complex challenges and meet the evolving needs of our sophisticated businesses.
Teamwork is at the core of the organization's success. We thrive on open collaboration and continuous learning, driving a culture that values diversity of thought and collective achievement. Our global footprint enables us to integrate diverse perspectives into product and solution delivery, resulting in comprehensive, adaptable, and scalable solutions. We optimize for impact, prioritizing and delivering solutions with excellence while remaining agile in response to the evolving needs of our businesses.
We are seeking a Blue Team Lead to serve as KKR's U.S. Regional Lead and escalation point for complex cyber incidents within the Threat Detection & Response (TD&R) function in our New York or Boston office. This is a senior incident response leadership role combining deep investigative expertise with ownership of incident command, containment strategy, stakeholder communication, and response readiness. This is an in-office position, 5 days per week.
KKR operates in a hybrid environment today; however, our operating model is increasingly cloud-first and identity-first, with growing focus on runtime and SaaS as primary investigative surfaces. This role will help shape how we respond in that future state - partnering closely with our MSSP, internal Computer Incident Response Team (CIRT), and engineering counterparts to drive faster, more consistent outcomes.
You will also be a key operational partner to the TDR SOC Engineer (SOC Engineering, Automation & Agentic Workflows) role. The Blue Team Lead defines the incident response requirements, validates that workflows and automation are usable under pressure, and ensures lessons learned translate into durable improvements across people, process, and technology.
Responsibilities
- Act as U.S. escalation lead / incident commander for high-severity incidents, owning response strategy, containment decisions, and coordination through resolution.
- Lead cross-functional response with internal CIRT, infrastructure/platform teams, cloud teams, identity teams, legal/compliance, and business stakeholders.
- Provide executive-ready briefings and situational updates during active incidents, clearly communicating risk, impact, tradeoffs, and next steps.
- Ensure post-incident reviews are completed and translated into measurable remediation and program improvements.
- Perform and lead advanced investigations across endpoint, network, identity, cloud control plane, SaaS, and (as needed) on-prem telemetry.
- Drive evidence collection and preservation strategies appropriate for hybrid environments, including cloud-native logging and ephemeral workload considerations.
- Develop investigative narratives: attacker objectives, sequence of actions, impacted assets, containment efficacy, and residual risk.
- Own and continuously improve incident response playbooks (e.g., ransomware/extortion, BEC, cloud account compromise, token/key theft, data exfiltration, insider risk).
- Lead and coordinate exercises and simulations; ensure learnings become concrete improvements (process updates, training, tooling enhancements).
- Establish escalation criteria and decision frameworks (severity, containment triggers, business engagement, recovery prioritization).
- Operationalize AI-assisted workflows to improve incident execution (e.g., alert/case summarization, timeline generation, correlation support, case documentation), ensuring strong governance, auditability, and human-in-the-loop controls.
- Partner with SOC Engineering to define requirements and validate that automation/agentic workflows reduce toil and time-to-contain without increasing operational risk or noise.
- Convert incident lessons-learned into durable improvements across enrichment, routing/prioritization, response plays, and coverage enhancements in partnership with SOC Engineering and ReliaQuest.
- Support threat hunting and purple-team efforts by shaping hypotheses and prioritizing validation based on real incident patterns and business risk (enablement and translation to controls - not primary hunt execution).
- Maintain strong operating rhythm with ReliaQuest and internal teams to ensure smooth escalations, clear responsibilities, and consistent response quality globally.
- Help define, track, and improve operational KPIs such as MTTR, MTTC, time-to-triage, containment SLA adherence, repeat-incident drivers, and quality of post-incident actions.
- Provide insight-driven reporting to TD&R leadership on trends, systemic issues, and targeted investments needed to raise response maturity.
Qualifications
- 6+ years in Incident Response, Security Operations, or Blue Team roles, including leading high-severity incidents end-to-end.
- Proven ability to serve as an escalation lead and incident commander—calm, decisive leadership in ambiguous, high-pressure situations.
- Strong communication skills: able to translate complex technical details into clear, actionable updates for executives and stakeholders.
- Experience operating in cloud-forward enterprises, including hybrid environments spanning SaaS, cloud-native workloads, and on-prem systems.
- Strong familiarity with identity-centric security models and investigations (federated identity, IAM abuse patterns, token theft, conditional access signals).
- Working knowledge of cloud-native architectures (containers/Kubernetes, serverless, CI/CD) and the investigative/containment challenges they introduce.
- Experience partnering with MSSPs and distributed teams; comfortable operating in a hybrid SOC model (internal + ReliaQuest).
- Familiarity with MITRE ATT&CK and applying it to investigative thinking, readiness planning, and validation priorities.
- Experience designing, using, or validating automated response workflows (SOAR) and promoting safe automation patterns.
- Exposure to AI-assisted SOC/IR tooling, including governance considerations (data handling, audit logging, human approval, evaluation).
- Experience with purple teaming, detection validation, or adversary simulation platforms (e.g., Atomic Red Team, Caldera, Cymulate). (Preferred)
- Ability to influence engineering roadmaps (telemetry, enrichment, workflow improvements) based on operational pain points and incident learnings. (Preferred)
Ideal Candidate Profile
- Incident leader: takes ownership, drives clarity, and brings structure to high-severity response.
- Technically deep and business-aware: understands attacker behavior and business impact equally well.
- Operationally disciplined: strong instincts for repeatability, playbooks, and learning loops.
- Collaborative and influential: can align MSSP + internal teams, and partner effectively with SOC Engineering and platform teams.
- Future-oriented: comfortable modernizing response for cloud-first and AI-enabled operating models.
Why Join Us?
This is a pivotal leadership role in a globally scaled Threat Detection & Response function at a leading investment firm. As U.S. Regional Lead, you will shape incident response outcomes for critical enterprise operations and directly influence how KKR modernizes response for a cloud-first, AI-enabled future. You'll partner with a high-performing MSSP and an engineering-driven TDR team to improve readiness, accelerate containment, and raise the bar on response quality across the organization.
This is the expected annual base salary range for this New York-based position. Actual salaries may vary based on factors, such as skill, experience, and qualification for the role. Employees may be eligible for a discretionary bonus, based on factors such as individual and team performance.
Base Salary Range
$150,000 - $180,000 USD
KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law.
KKR will provide reasonable
- ...Position Name: Team Lead Reports to: Client Technology Manager Location/Type: Boston... ...growing support department. You will be responsible for a team of Junior Systems Engineers and... ...Sophos or similar product for endpoint threat management Basic understanding of...SuggestedFull timeWork at office
$79.4k - $136.4k
...Position Overview The Database Team Lead oversees the design, administration, and performance... ...and regulatory requirements. Key Responsibilities Lead multi-database administration... ...-planning tools to track utilization, detect performance or reliability risks, and...SuggestedContract workWork at office$40 per hour
...FIFA SRT Supervisor Security Response Team Location: City Hall Plaza, Boston, MA Pay: $... ...to the Venue Security Manager. You will lead all SRT activations, coordinate with public... ...during an active life-safety threat Lead joint responses with BPD, Boston...SuggestedWeekly payImmediate startAll shiftsShift work$145k - $155k
...experience to a new industry, join our team as we help shape a brighter way forward.... ...currently seeking a Project Management Team Lead join our Project and Development... ...project management with people leadership responsibilities. The role involves directly managing and...SuggestedDaily paidContract workFor contractorsLocal areaRemote work- ...Barracuda-Network is looking for a Manager, Offensive Security to lead a team focused on threat detection and attack simulation across various technologies. In this role, you'll mentor engineers, develop and manage detection rules, and drive security innovations. The ideal...SuggestedFlexible hours
$135k - $165k
...About Blue Earth Diagnostics: Blue Earth Diagnostics is an established molecular... ...Molecular Imaging Account Manager, Oncology is responsible for sales activities related to FDA... ...facilitation, and organizational skills; team player. Experience and skills with cross-...$99k - $123k
...comprehensive expertise in Gas Detection. Manage all aspects of... ...anywhere within territory) Key Responsibilities Manage and support... ...Windows, Word, Excel, PowerPoint, Teams, Zoom and CRM (preferably... ...urbanization. We are a leading software-industrial company...Temporary workWork experience placementRemote workFlexible hours$190k
...Consulting Project Team Lead - Launch & Commercialization Boston, Massachusetts, United States, New York, New York, United States... ...meets innovation. Project Lead (PL) Role Overview Responsibilities Manage between 2 to 5 projects at once and all corresponding...$201.37k - $236.9k
...required throughout the year. Team and company-wide... ...Internal Audit team is responsible for strategic analysis,... ...control potential events or threats and ultimately add... ...regions (US, EMEA, APAC). Lead Coinbase’s global IT &... ...monitoring, anomaly detection, automated evidence...Work at officeLocal area$44.09 - $78.7 per hour
...locations in eastern Massachusetts. Our entire team of providers (physicians, AP/NPs and... ...As the Nuclear Medicine - Team Lead, you will support the workflow of Nuclear... ...leader for unit support staff. Primary Responsibilities: Serves as a skilled clinical/administrative...Hourly payMinimum wageFull timeWork experience placementLocal areaRelocation package- ...England. They are looking for an experienced Personal Lines Team Lead to join their Needham, MA office and take ownership of a... ...capacity within a collaborative, professional environment. RESPONSIBILITIES: Serve as the primary point of contact for a portfolio of...Work at office2 days per week3 days per week
$206.25k - $297.92k
...Job title: US HEVA Immunology and Neurology Team Lead Location: Cambridge (US) / Morristown (US) / Hybrid (3 days onsite required... ...of science to improve people's lives. Main Responsibilities: This role leads US HEOR strategy and execution for Immunology...$206.25k - $297.92k
...Job title: US HEVA Immunology and Neurology Team Lead Location: Cambridge (US) / Morristown (US) / Hybrid (3 days onsite required... ...the miracles of science to improve people's lives. Main Responsibilities: This role leads US HEOR strategy and execution for...$23.41 - $41.83 per hour
...at 28 practice locations in eastern Massachusetts. Our entire team of providers (physicians, AP/NPs and ancillary clinicians) works... ...with established policies and procedures. Primary Responsibilities: Provide leadership and guidance to staff; train and cross...Hourly payMinimum wageFull timeWork experience placementLocal areaMonday to Friday$146.2k - $261.4k
...advance the public good. You will be responsible for managing significant research... ...and policy analysis projects, and leading multidisciplinary teams of policy researchers, engineers,... ...develop rigorous and comprehensive threat models and identify potential system...Fixed term contractWork experience placementRemote workWork from home- ...Team Leader Opportunity At CAVA At CAVA, we love what we do, and we try and make every... ...values: Generosity First, Always: We lead with kindness. Our best work happens... ...comprehensive list of all the duties and responsibilities of the position, and such duties and responsibilities...Local areaShift work
$144.05k - $206.78k
...hands-on solution that helps teams continuously assess, build, and... ...Advisors (CRAs) to lead our growing US-based Cyber Resilience... ...crisis simulations, dynamic threat range exercises, and technical... ...-wide cyber preparedness and responsiveness. ~ Ability to develop and deliver...Immediate startRemote workFlexible hours2 days per week$20 per hour
...Entertainment is the world's leading live entertainment company, comprised... ...to our Global Touring team, from Ticketing and Venue... ...Patrol premises to prevent and detect signs of intrusion and ensure... ...doors, windows, and gates. ~ Responsible for maintaining a fun,...Hourly payLocal areaWork from homeWorldwideShift workNight shiftWeekend workAfternoon shift- ...self-advocacy and test-taking. Role Description As a Team Lead, you will lead a group of 15 mentees and their mentors... ...and multi-channel communication. Position Requirements & Responsibilities: Prepare for and conduct Saturday session activities...Summer workAfternoon shiftWeekday work
$73.8k - $218.8k
...Supply Chain/Manhattan Manager is responsible for designing, developing and... ..., and value levers. Lead end-to-end discussions on supply... ...fulfillment solutions (e.g., Manhattan, Blue Yonder, e2Open). Advise on... ...Partner with cross-functional teams (finance, IT, operations) to...Work experience placementLive inWork at officeLocal area$22.22 - $31.71 per hour
...provide exceptional care. We believe that high-performing teams drive groundbreaking medical discoveries and invite all applicants... .... Job Summary The Emergency Department Supply Lead is primarily responsible for ensuring that supplies and equipment are stocked in...Hourly payRemote workShift work$99.3k - $159.33k
...cost objectives are met across the client environment. Key Responsibilities Architect and administer Windows server instances in... ...efficiency. Collaborate with application, security, and DevOps teams to integrate Windows-based services into broader cloud architectures...Contract workWork at office$20.38 - $36.44 per hour
...locations in eastern Massachusetts. Our entire team of providers (physicians, PA/NPs and... ...Under general supervision as a Team Lead, coordinates the daily support operations... ...Monday-Friday: 8AM-4:30PM Primary Responsibilities: Serves as a skilled clinical/administrative...Hourly payMinimum wageFull timeWork experience placementLocal areaMonday to Friday$210k - $303.33k
...Cross-Organization Excellence Lead Location: Cambridge, MA... ...the Specialty Care Leadership Team, driving high-impact initiatives... ...people’s lives. Main Responsibilities: 1. Enterprise Strategy Leadership... ...— including competitive threats, regulatory shifts, and macroeconomic...Immediate startShift work$18.74 - $25.22 per hour
...When you join the growing BILH team, you're not just taking a job, you're making a difference... ...operation in the absence of a manager. Leads employees to exceed customer... ...basis. Job Description: Primary Responsibilities: 1. In conjunction with the manager/...Hourly payWork experience placementInterim roleShift workNight shift$20 per hour
...occurrences. Patrol premises to prevent and detect signs of intrusion and ensure security of doors, windows, and gates. Responsible for maintaining a fun, friendly, and safe... ...to appropriate members of the management team in a timely manner Operate walkthrough metal...Hourly payLocal areaWork from homeShift workNight shiftWeekend workAfternoon shift$22.3 - $35.2 per hour
...Lead Coordinator, Collections About Navista We believe in the power of community... ...organization's assets. Collections is responsible for the collection of outstanding accounts... ...Responsibilities The Accounts Receivables (AR) Team Lead assists with daily operations of the...Hourly payTemporary workWork at officeLocal areaImmediate startFlexible hours$80k - $105k
...innovating for a healthier world, our dedicated team collaborates closely with commercial,... ...services. Job Title Team Lead - Oncology, ITCT Location(s) GSK... ...Customer Site MA Job Description Job Responsibilities Maintains cell cultures, protein...Full timeWork at officeLocal area- ...landscape, our dedicated multidisciplinary team, and our IT Service Desk position TTS to... ...and beyond. What You'll Do The Team Lead for Operations Technology Systems Analytics oversees a team of systems analysts responsible for the configuration, integration, implementation...Immediate start
$110k - $165k
...exciting opportunity for an Bridge Inspection Group Manager/Team Lead to join our Boston office. We are seeking an Inspection Group... ...positioning itself for long-term, sustainable growth. Responsibilities Assume leadership role and responsibility for managing inspection...Work at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Detection & Response - Blue Team Lead. Be the first to apply!
- member team lead Boston, MA
- team coordinator Boston, MA
- disability team leader Boston, MA
- mobile team lead Boston, MA
- operational excellence leader Boston, MA
- quality control team lead Boston, MA
- school leader Boston, MA
- group product manager Boston, MA
- quality assurance team leader Boston, MA
- key team leader Boston, MA


