Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Detection and Response Lead

$160k - $200k
Full-time

jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Lead based in the United States.

As Detection and Response Lead, you will build and lead a technically deep detection and response capability across enterprise and cloud environments. You will own advanced investigations, incident response, threat hunting, and continuous improvement of defensive security operations. Working closely with security engineering and external MSSP/MDR partners, you will serve as the escalation point for complex security events and drive incidents through investigation, containment, and remediation. The role combines hands-on technical execution with operational leadership and close partnership with the CISO and senior stakeholders. You will strengthen detection quality, improve monitoring coverage, and develop repeatable response processes and playbooks. Your work will directly improve the organization’s ability to detect, understand, and contain sophisticated threats across AWS, Azure, endpoints, identities, and enterprise infrastructure.

Accountabilities:

  • Lead incident response for escalated MSSP and MDR alerts, including scoping, investigation, containment, and remediation across cloud, endpoint, identity, and enterprise environments.
  • Provide emergency-only on-call support for high-severity security incidents when required.
  • Conduct detailed forensic investigations using SIEM, EDR, proxy, WAF, DLP, cloud, endpoint, and network telemetry to reconstruct events and identify attacker activity.
  • Correlate logs and security events to establish accurate incident timelines, determine scope and impact, and identify attacker techniques and behaviors.
  • Produce concise, high-quality investigative reports outlining findings, timelines, root causes, business impact, and recommended remediation actions for both technical and non-technical stakeholders.
  • Conduct hypothesis-driven and data-driven threat hunts to uncover malicious or suspicious activity that has bypassed automated detections and external monitoring workflows.
  • Develop repeatable threat-hunting methodologies based on attacker behavior, business-specific risks, historical incidents, and emerging threat patterns.
  • Document and communicate threat-hunting outcomes, translating discoveries into new detection opportunities and defensive improvements.
  • Review MSSP and MDR escalations for quality, signal-to-noise ratio, accuracy, and detection fidelity, establishing structured feedback loops to improve external security operations.
  • Identify gaps in logging, telemetry, detection logic, monitoring coverage, and investigative capabilities, and partner with security engineering and technology teams to close those gaps.
  • Establish and improve metrics such as Mean Time to Detect, Mean Time to Contain, and detection coverage to measure and strengthen defensive effectiveness.
  • Serve as the primary technical escalation point for security incidents requiring advanced analytical, investigative, or containment expertise.
  • Coordinate cross-functional response efforts involving IT, cloud teams, application owners, security engineering, and other technical stakeholders during active incidents.
  • Maintain strong alignment with MSSP and MDR partners by defining clear escalation criteria, severity thresholds, response procedures, ownership models, and communication expectations.
  • Report significant incidents, detection trends, response performance, and security risks to the CISO and senior leadership.
  • Develop and maintain operational runbooks, investigation procedures, incident response guides, and defensive playbooks.
  • Analyze recurring attacker behaviors and translate lessons learned from investigations and hunts into durable operational processes and detection improvements.
  • Help shape and mature the broader detection and response program, identifying opportunities to improve tools, processes, workflows, and organizational readiness.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
  • 7+ years of hands-on experience in cybersecurity operations, incident response, threat detection, or a closely related security discipline.
  • Demonstrated experience leading complex security investigations involving cloud environments, identity systems, endpoints, networks, and modern security tooling.
  • Proven ability to build, mature, or significantly improve a detection and response program in partnership with security leadership.
  • Strong knowledge of attacker tactics, techniques, and procedures, including practical application of frameworks such as MITRE ATT&CK.
  • Hands-on expertise in log analysis, event correlation, security telemetry, and investigative techniques.
  • Practical knowledge of digital forensics fundamentals, including artifact analysis, timeline creation, host investigation, and network investigation.
  • Experience independently taking ownership of escalated MDR or MSSP alerts and driving investigations through deeper analysis, containment, and remediation.
  • Strong experience analyzing AWS and Azure security telemetry, including CloudTrail, CloudWatch, IAM, network telemetry, and workload-level events.
  • Demonstrated ability to take appropriate containment actions in cloud environments while balancing security, operational continuity, and business requirements.
  • Experience working with SIEM, EDR, proxy, WAF, DLP, or related security technologies from an investigative and incident-response perspective.
  • Strong understanding of how to operate effectively alongside managed SOC, MSSP, or MDR providers and integrate external security operations with internal response capabilities.
  • Prior threat-hunting experience in cloud-first, hybrid, or complex enterprise environments is highly desirable.
  • Incident response or digital forensics certifications such as GCIH, GCFA, GNFA, or GCFE are advantageous.
  • Excellent written and verbal communication skills, with the ability to communicate complex technical findings clearly and concisely to both technical teams and senior leadership.
  • Strong analytical thinking, investigative curiosity, sound judgment, and the ability to remain composed during high-severity incidents.
  • Ability to work independently while collaborating effectively across security engineering, IT, cloud, application, and business teams.
  • Must be legally authorized to work in the United States.

Benefits

  • $160,000–$200,000 USD annual base salary , with actual starting compensation determined by skills, qualifications, training, and experience.
  • Eligibility for bonus compensation .
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) retirement plan with company matching contributions.
  • Employee Ownership Program, allowing eligible employees to share in financial rewards as the organization grows.
  • Professional development opportunities.
  • Owner Referral Program.
  • Work-from-home reimbursement for eligible remote or hybrid roles.
  • Canary emergency financial assistance program.
  • Life and AD&D insurance.
  • Confidential Employee Assistance Program.
  • Health Savings Account with company contribution.
  • Short-term disability coverage.
  • Voluntary accident, critical illness, and hospital insurance options.
  • Employee discounts.
  • Addition Wealth financial wellness program.
  • Various paid time-off programs.
  • 11 company-paid holidays.
  • Collaborative and mutually supportive work environment.
  • Opportunities to work closely with security leadership and help shape a growing detection and response function.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Detection and Response Lead in United States vacancy
  • $10k

     ...move and manage billions, Ramp is the place to do it.About the RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Flexible hours

    Ramp

    New York, NY
    1 day ago
  •  ...Ramp is seeking a security-focused engineer to join our security team in NYC, focusing on detection and response across federal and public sector environments. You will review logs, triage incidents, develop runbooks, and work with engineers to improve alerting and automated... 
    Suggested
    2 days per week

    Visa Hunt

    New York, NY
    2 days ago
  • Role Description We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Nebius

    Remote
    2 days ago
  •  ...Synopsys is seeking a senior cybersecurity leader to own the detection engineering, SOC operations, and incident response strategy across global environments, including Austin, Hillsboro, and Morrisville. You will guide teams through major incidents as Incident Commander... 
    Suggested

    Jobleads-US

    Austin, TX
    2 days ago
  • A leading global technology company is seeking a Senior Manager for our Insider Risk Detection & Response team. In this role, you will own the insider risk program, managing a team while collaborating closely with Cyber Security and Legal departments. Responsibilities include... 
    Suggested

    Applied Materials, Inc.

    Austin, TX
    3 days ago
  • Blackbaud is seeking a Sr. Manager of Cyber Threat Detection and Response to lead the detection engineering and incident response teams. Responsibilities include developing threat detection frameworks and managing incident response efforts across varied security operations... 
    Remote work
    Flexible hours

    Blackbaud

    New York, NY
    1 day ago
  • Toyota Tsusho Systems US, Inc. is seeking a Senior Detection and Response Analyst to provide ongoing support to the Regional Security Operations...  ...include acting as escalation point for security incidents, leading the ID team, triaging threats, and driving improvements in... 

    Toyota Tsusho Systems US, Inc.

    Plano, TX
    22 hours ago
  •  ...technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market. Backed by one of the leading...  ...is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across... 

    Integrated Specialty Coverages, LLC

    New York, NY
    1 day ago
  • $347k

    Global Detection and Response Lead | OpenAI Careers Global Detection and Response Lead Security - San Francisco Apply now (opens in a new window) About the Team OpenAI’s Security organization exists to enable safe, responsible innovation at scale. As our systems, infrastructure... 

    OpenAI

    Los Angeles, CA
    3 days ago
  • $150k - $180k

    COMPANY OVERVIEW KKR is a leading global investment firm that offers alternative asset management...  ...excellence while remaining agile in response to the evolving needs of our businesses....  ...cyber incidents within the Threat Detection & Response (TD&R) function in our New York... 
    Work at office
    Local area

    STAGE-M

    New York, NY
    4 days ago
  • RB Global Inc. is seeking a Lead, Cybersecurity Operations to drive the growth of our global CSOC capabilities. The role combines...  ...leadership with strategic vision, overseeing threat detection, incident response, and continuous improvement of security operations across the... 

    RB Global Inc.

    Westchester, IL
    1 day ago
  • Toyota Tsusho Systems US, Inc. is seeking a Senior Detection and Response Analyst to provide ongoing 24x7 monitoring and incident response support...  ...Regional Security Operations program. The role includes leading the ID team on shift when needed and guiding analysts to... 
    Shift work

    Toyota Tsusho Systems Corporation

    Plano, TX
    1 day ago
  • Toyota Tsusho Systems US, Inc. (TTS-US) is seeking a Senior Detection and Response Analyst to provide 24x7 monitoring and threat detection for...  ...clients. You will act as escalation point for security incidents, lead shift operations, and coordinate with the Incident Detection... 
    Shift work

    Socket.dev

    New York, NY
    3 days ago
  • $10k

     ...move and manage billions, Ramp is the place to do it. About the Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our... 
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    Ramp Corp.

    New York, NY
    3 days ago
  •  ...Job Description Job Description Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The SOC Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed Detection & Response (MDR) operations... 

    cFocus Software Incorporated

    Washington DC
    a month ago
  • Fluidstack is seeking a seasoned Incident Response Lead to secure our frontier compute infrastructure across corporate, cloud, and data center environments. You will own end-to-end IR from detection to eradication, drive cross‑team investigations, and define severity models... 

    FluidStack

    Austin, TX
    2 days ago
  • OpenAI's Security organization seeks a Global Detection and Response Lead to own and scale threat detection and incident response across our global infrastructure in Seattle. You will build and mentor teams, drive strategy, and partner with Infrastructure, Research, Product... 

    OpenAI

    Seattle, WA
    1 day ago
  • OpenAI is seeking a Global Detection and Response Lead to own and scale cybersecurity detection and response operations across our global infrastructure. You will set strategy, build and mentor teams across observability, incident response, and threat intelligence, and... 

    Openai

    San Francisco, CA
    3 days ago
  • A leading AI research company in Los Angeles is seeking a Global Detection and Response Lead to oversee and scale their cybersecurity operations. This strategic leadership role demands over ten years in cybersecurity and expertise in detection engineering, along with the... 

    OpenAI

    Los Angeles, CA
    3 days ago
  • TENEX.AI is seeking a SOC Director to lead and scale our SOC, ensuring around-the-clock detection and response for customers. You will manage SOC Managers, stay hands-on in escalations, and partner with engineering, product, and customer success to deliver high-quality... 

    TENEX.AI

    Kansas City, MO
    2 days ago
  • Labcorp in Durham, NC, is seeking a Security Operations Center (SOC) Senior Manager to lead a 24/7 security operations team. This role involves enhancing Labcorp's detection and response strategies and ensuring compliance with security regulations. The ideal candidate... 

    Labcorp

    Durham, NC
    1 day ago
  • $234k - $300k

    Datadog’s Cloud SIEM product enables security teams to detect, investigate, and respond to threats across modern...  .... As a Group Product Manager, you will define and lead the vision for our Threat Detection and Incident Response (TDIR) capabilities, with direct impact on how our... 
    Work at office

    Doist

    New York, NY
    3 days ago
  • Plaid is recruiting a Head of Detection and Response to lead the formation of a new security function. You will guide a team of analysts and engineers, shape detection infrastructure, and drive AI-driven triage across the security lifecycle. In this leadership role you... 

    MoneyLion

    San Francisco, CA
    22 hours ago
  • $150k - $190.7k

     ...every connection. We do this by driving Responsible Growth and delivering for our clients, teammates...  ...Incident Response Orchestration Lead is the senior technical authority responsible...  ...data pipelines for incident context, detections, and response historyEvaluate and... 
    Full time
    Work at office
    Flexible hours
    Shift work
    Day shift

    Bank of America

    Washington DC
    3 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent...  ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the... 
    Work at office
    Remote work

    ECS Federal

    Washington DC
    1 day ago
  • $164.9k - $245k

     ...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense...  ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that...  ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution... 
    Permanent employment
    Full time
    Temporary work
    Remote work

    Joby Aviation

    Santa Cruz, CA
    22 hours ago
  • $130k - $170k

     ...training, recovery, and lifestyle.We are seeking a Incident Response Lead to drive security incident response across the enterprise. In...  ...regulatory notification processesDrive continuous improvement of detection and response capabilities across SIEM, EDR, cloud monitoring,... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    3 days ago
  • $123.7k - $204.1k

     ...advancing your profession at one of the world’s leading financial services institutions. Your...  ...and cloud environments. This role is responsible for leading complex hunts end-to-end (...  ...Threat Intelligence, Incident Response and Detection Engineering, and improving enterprise... 
    Full time
    Part time

    PGIM

    Newark, NJ
    22 hours ago
  •  ...Leading incident response efforts, the full-time Incident Response Lead will manage threat hunting, develop detection mechanisms, and coordinate remediation processes, operating in a hybrid environment from the Washington, DC office or remotely. Key responsibilities Oversee... 
    Full time
    Work at office
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  • $40 - $80 per hour

     ...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours
    Night shift

    Alignerr

    United States
    22 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Detection and Response Lead. Be the first to apply!