Detection and Response Engineer
Unisys
Security Analyst
What success looks like in this role:
- Develop and Implement Custom Detections:
- Design, develop, and maintain high-fidelity detection rules, signatures, and analytics for a diverse array of enterprise security tools, including Security Information and Event Management (SIEM) systems, Endpoint Detection and Response (EDR) platforms, and Intrusion Detection Systems (IDS). The objective is to identify both known and emerging threats effectively.
- Translate complex threat intelligence, sophisticated attack methodologies (e.g., leveraging the MITRE ATT&CK Framework), and vulnerability insights into precise, actionable, and automated detection logic.
- Continuously tune and optimize existing detection mechanisms to significantly reduce false positives, enhance alert fidelity, and ensure a high signal-to-noise ratio, thereby minimizing alert fatigue for security analysts.
- Perform Tier 3 Security Investigations and Proactive Threat Hunting:
- Lead and conduct advanced, complex security investigations (Tier 3) escalated from lower tiers, encompassing root cause analysis, malware and indicator analysis, and recommending robust corrective measures to prevent future incidents.
- Proactively conduct threat hunting activities across network, endpoint, and cloud environments to identify novel or hidden threats, subtle anomalies, and security gaps that may evade existing detection controls.
- Collaborate closely with Incident Response (IR) teams to ensure effective communication, facilitate rapid response to detected threats, and integrate lessons learned into the development of new or refined detection capabilities.
- Manage and Optimize MSSP Tier 1 & Tier 2 Operations:
- Serve as the primary technical liaison for Managed Security Service Provider (MSSP) partners, providing expert guidance and strategic oversight for their Tier 1 and Tier 2 security monitoring and operational activities.
- Ensure MSSP adherence to organizational security policies, detection standards, and incident escalation procedures, thereby contributing to the overall security posture.
- Collaborate with MSSP teams on detection rule deployment, tuning, and validation, leveraging continuous feedback loops to enhance overall detection efficacy and reduce alert fatigue experienced by their analysts.
- Review MSSP-generated alerts and reports, providing constructive feedback and precise technical direction for continuous improvement in their detection and response capabilities.
- Security Automation and Tooling:
- Develop and maintain automation scripts and tools (e.g., Python, PowerShell, Bash) to streamline security detection operations, facilitate efficient data parsing, integrate disparate security tools, and enhance response capabilities.
- Build, design, run, and troubleshoot playbooks within a Security Orchestration, Automation, and Response (SOAR) solution to automate incident response processes and significantly improve operational efficiency.
- Documentation and Continuous Improvement:
- Maintain comprehensive and up-to-date documentation of detection logic, configurations, incident response procedures, and investigation findings for robust knowledge sharing and auditing purposes.
- Stay abreast of the latest security threats, vulnerabilities, attack vectors, industry trends, and emerging security technologies to proactively enhance detection measures and fortify digital boundaries.
Required Qualifications:
- Experience: 4-6 years of hands-on experience working in a Security Operations Center (SOC), Network Operations Center (NOC), Digital Forensics, or Incident Response role, demonstrating a foundational understanding of operational security challenges and the incident lifecycle.
- Technical Proficiency:
- In-depth understanding and practical experience with Security Information and Event Management (SIEM) systems (e.g., Splunk, LogRhythm, Google SecOps, Elastic) for log analysis, sophisticated rule creation, and dashboard development.
- Strong knowledge of Endpoint Detection and Response (EDR) and Intrusion Detection/Prevention Systems (IDS/IPS).
- Proficiency in scripting languages (e.g., Python, PowerShell, Bash) for automation, data manipulation, and custom tool development.
- Solid understanding of network security, protocols, and traffic analysis.
- Familiarity with threat intelligence platforms and frameworks (e.g., MITRE ATT&CK) to inform detection strategy and rule development.
- Analytical and Problem-Solving Skills:
- Exceptional analytical skills to analyze large, complex datasets, identify subtle anomalies, patterns, and indicators of malicious activity.
- Demonstrated ability to think critically, troubleshoot complex problems, and make sound decisions under pressure, particularly during incident investigations.
- Collaboration and Communication:
- Strong verbal and written communication skills for reporting findings, documenting procedures, and collaborating effectively with cross-functional teams and external partners.
Preferred Qualifications:
- Experience working with Google Cloud Platform (GCP) security services, audit logs, and cloud-native detection tools.
- Hands-on experience with Kubernetes incident response and forensic analysis.
- Familiarity with Detection-as-Code principles, version control (e.g., Git/GitHub), and CI/CD pipelines for detection rule management.
- Relevant security certifications (e.g., SANS, Offensive Security, cloud security certifications).
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Detection and Response Engineer in United States vacancy
- ...Threat Detection & Response Engineer Location: New York City, (Hybrid) Compensation: Top-tier compensation We're representing a global investment and technology development firm that sits at the intersection of high-finance and deep-tech. They're known for...Suggested
$125k - $140k
..., today, solving real-world problems and seeing the impact of their work. Join us. Job Summary As a Systems Engineer, Event Detection & Response Engineer you will leverage a comprehensive understanding of our autonomous system to facilitate high-impact, cross-functional...SuggestedOdd jobWork at officeImmediate startFlexible hours- ...Sr. Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles / Seattle / NYC Duration: Long-Term Contract The Global Security Organization provides industry-leading security and privacy services, globally. Our organization uses...SuggestedLong term contract
$146k - $184k
...diverse perspectives. Come join us for the ride! Role overview CarGurus is looking for a Senior Security Engineer to add to our growing Threat Detection and Response (TD&R) Team. This is a hands-on technical role that will build our first line of defense against...SuggestedFlexible hours- ...from national security, to global connectivity, to disaster response can unlock their full potential and operate every day... ...government and commercial space communications. We need a Senior Detection and Response Engineer to build and operate our security operations center, hunt...SuggestedPermanent employment
$243.29k - $295.25k
...and helping to create safer, more civil shared experiences for everyone. About the role: As a Senior Security Engineer on the Detection and Response (D&R) team at Roblox, you’ll protect a community of hundreds of millions of monthly users alongside the...Full timeH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$166k - $220k
...Senior Detection & Response Engineer Costa Mesa, California, United States Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business...Full timeWork experience placementImmediate start- A leading financial services organization is seeking a Lead Detection Engineer in Newark, NJ to enhance cyber threat detection capabilities... ...requires extensive experience in detection engineering, incident response, and threat hunting. Candidates should possess relevant...
- ...impact in your role. Feel free to reference any tools, platforms, or workflows you use today. ROLE OVERVIEW As a Detection and Response Engineer at Benchling you'll be joining a team responsible for building a best-in-class security program from the ground up. Our...Temporary workLocal areaRemote work
- ...Mobility Tech Solutions LLC is seeking a Cyber Security Engineer to join its Information Security & Cyber Security... ...candidate will have strong experience in incident response, digital forensics, and threat detection, ensuring robust security measures across environments...
- ...Cyber Security Engineer Fragomen, an AmLaw 100 Firm and the leading global immigration services provider, is... ...Security Engineer with strong experience in Incident Response, digital forensics, and threat detection to join our Information Security & Cyber Security team...Local areaRemote work
$120k - $180k
...Engineer III, CICD - AI Detection and Response (AIDR) (HYBRID) page is loaded## Engineer III, CICD - AI Detection and Response (AIDR) (HYBRID)locations: USA - Sunnyvale, CA: USA - Austin, TX: USA - Redmond, WAtime type: Full timeposted on: Posted Todayjob requisition...Work experience placementWork at officeLocal area2 days per week3 days per week- Senior Security Engineer - Detection & Response - EU/UK Remote, UK We are seeking a UK-based Senior Security Engineer to join our Security Operations and Response Team as a senior individual contributor. In this role, you will investigate and respond to security incidents...Remote jobWork at office
$120k - $180k
...A leading cybersecurity firm in Austin, Texas is looking for an Engineer III specializing in CICD for AI Detection and Response. The role requires developing and maintaining CI/CD pipelines and collaborating across engineering teams. Candidates should have over 5 years...$115k - $165k
.... It's the people. Our team is our competitive advantage and we are better together. YOUR MISSION As a Threat Detection & Response Engineer III, you will be an integral part of our threat detection and response function, helping build and mature the detection...Permanent employmentWork at office$200k - $340k
...Detection & Response Engineer Palo Alto, CA About XAI XAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This...Temporary work$260k - $405k
A leading AI research organization is seeking a mid-level to senior Security Engineer specialized in Insider Threat Detection & Response. This role involves innovating infrastructure for security, developing detection rules, and managing insider threats. Ideal candidates...Remote work- ...Health System, Inc. is seeking an experienced Information Security SOC Engineer to enhance security operations. This hands-on role focuses on engineering, operating, and automating detection and response capabilities utilizing Microsoft Sentinel and Defender. The ideal...
$116k - $145k
...Threat Detection and Response Engineer II CarGurus is looking for a Security Engineer II to add to our growing Threat Detection and Response (TD&R) Team. This is a hands-on technical role that will build our first line of defense against cybersecurity threats in a complex...$210k - $255k
...to lead the future of weight health care. Who We Are Engineering: At WeightWatchers, our Engineering Team drives... ...What You Will Do As our Senior Security Engineer - Detection and Response, you will be working alongside an existing team of experienced...Remote workWorldwide$168k - $240k
...with greater scale, reach, and impact. The Department: Threat Detection & Response In the emerging industry of digital assets, there is... ...tackle in the crypto space. From security architecture and engineering to maintenance of cold storage systems and data centers to...Work at officeRemote workFlexible hours$103k - $128k
...Cleveland is seeking a SOC/Incident Report Engineer to strengthen their cybersecurity measures. In this role, you will detect and respond to cybersecurity incidents, collaborate... ...requires 3-7 years of SOC or incident response experience, and familiarity with tools like...$140k - $215k
Sr. Engineer, AI - AI Detection and Response (AIDR) (Hybrid) page is loaded## Sr. Engineer, AI - AI Detection and Response (AIDR) (Hybrid)locations: USA - Sunnyvale, CA: USA - Austin, TX: USA - Redmond, WAtime type: Full timeposted on: Posted Todayjob requisition id: R...Work experience placementWork at officeLocal area2 days per week3 days per week- ...Job Description The Cybersecurity Incident Response (IR) Lead and Detection is responsible for the dual mission of advanced threat detection... ...precision and speed. KEY RESPONSIBILITIES: Detection Engineering (the "Hunt) Advanced Logic Development: Design...
- ...that possible. We're a team of doctors, engineers, designers, researchers, and creatives building... ...Do Build and maintain high-signal detections across cloud, infrastructure, and... ...retain it, and how we query it Develop response automation: playbooks, orchestration,...Work at officeRemote workWorldwideFlexible hours
- ...A forward-looking tech company is seeking an experienced Security Engineer specialized in detection and response. The role involves designing and implementing security measures to protect sensitive information and ensure compliance with regulations. Candidates should...
- ...trust, reliability, and compassion. JOB DESCRIPTION Join our Information Security team as an Information Security Engineer - Detection & Response, where you'll play a critical role in safeguarding the firm by monitoring and responding to security threats, managing...Local area
$251k - $377k
...move fast, with precision, and always execute with privacy at the forefront. We're looking for a Security Engineering Manager to lead our Detection & Response team here at Snap! What you'll do: Identify opportunities and assume direct ownership of multi-year...Temporary workLive inWork at officeLocal area$320k - $405k
...Security Software Engineer, Detection & Response Platform San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC About Anthropic Anthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial...Work at officeVisa sponsorshipFlexible hoursShift work- ...Staff Detection And Response Engineer Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated detection systems that identify attacks targeting...Full timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection and Response Engineer. Be the first to apply!

