Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Threat Detection & Response - Blue Team Lead

$150k - $180k

KKR

COMPANY OVERVIEW

KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR's insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR's investments may include the activities of its sponsored funds and insurance subsidiaries.

TEAM OVERVIEW

KKR's Technology organization is a group of passionate technologists and product managers, unified by a shared mission to deliver exceptional products and solutions that drive value for our stakeholders, clients, and investors. Our passion for technology and innovation fuels our commitment to creating high-quality, impactful solutions that address complex challenges and meet the evolving needs of our sophisticated businesses.

Teamwork is at the core of the organization's success. We thrive on open collaboration and continuous learning, driving a culture that values diversity of thought and collective achievement. Our global footprint enables us to integrate diverse perspectives into product and solution delivery, resulting in comprehensive, adaptable, and scalable solutions. We optimize for impact, prioritizing and delivering solutions with excellence while remaining agile in response to the evolving needs of our businesses.

POSITION OVERVIEW

We are seeking a Blue Team Lead to serve as KKR's U.S. Regional Lead and escalation point for complex cyber incidents within the Threat Detection & Response (TD&R) function in our New York or Boston office. This is a senior incident response leadership role combining deep investigative expertise with ownership of incident command, containment strategy, stakeholder communication, and response readiness. This is an in-office position, 5 days per week.

KKR operates in a hybrid environment today; however, our operating model is increasingly cloud-first and identity-first, with growing focus on runtime and SaaS as primary investigative surfaces. This role will help shape how we respond in that future state - partnering closely with our MSSP, internal Computer Incident Response Team (CIRT), and engineering counterparts to drive faster, more consistent outcomes.

You will also be a key operational partner to the TDR SOC Engineer (SOC Engineering, Automation & Agentic Workflows) role. The Blue Team Lead defines the incident response requirements, validates that workflows and automation are usable under pressure, and ensures lessons learned translate into durable improvements across people, process, and technology.

RESPONSIBILITIES
Incident Leadership & Command (U.S. Regional Lead)
  • Act as U.S. escalation lead / incident commander for high-severity incidents, owning response strategy, containment decisions, and coordination through resolution.
  • Lead cross-functional response with internal CIRT, infrastructure/platform teams, cloud teams, identity teams, legal/compliance, and business stakeholders.
  • Provide executive-ready briefings and situational updates during active incidents, clearly communicating risk, impact, tradeoffs, and next steps.
  • Ensure post-incident reviews are completed and translated into measurable remediation and program improvements.
Advanced Investigations (Cloud/Identity/Runtime First; Hybrid Aware)
  • Perform and lead advanced investigations across endpoint, network, identity, cloud control plane, SaaS, and (as needed) on-prem telemetry.
  • Drive evidence collection and preservation strategies appropriate for hybrid environments, including cloud-native logging and ephemeral workload considerations.
  • Develop investigative narratives: attacker objectives, sequence of actions, impacted assets, containment efficacy, and residual risk.
Readiness, Playbooks, and Exercising
  • Own and continuously improve incident response playbooks (e.g., ransomware/extortion, BEC, cloud account compromise, token/key theft, data exfiltration, insider risk).
  • Lead and coordinate exercises and simulations; ensure learnings become concrete improvements (process updates, training, tooling enhancements).
  • Establish escalation criteria and decision frameworks (severity, containment triggers, business engagement, recovery prioritization).
AI-Enabled Response & Analyst Acceleration (Operational Owner)
  • Operationalize AI-assisted workflows to improve incident execution (e.g., alert/case summarization, timeline generation, correlation support, case documentation), ensuring strong governance, auditability, and human-in-the-loop controls.
  • Partner with SOC Engineering to define requirements and validate that automation/agentic workflows reduce toil and time-to-contain without increasing operational risk or noise.
Continuous Improvement, Threat-Informed Defense, and Partner Management
  • Convert incident lessons-learned into durable improvements across enrichment, routing/prioritization, response plays, and coverage enhancements in partnership with SOC Engineering and ReliaQuest.
  • Support threat hunting and purple-team efforts by shaping hypotheses and prioritizing validation based on real incident patterns and business risk (enablement and translation to controls - not primary hunt execution).
  • Maintain strong operating rhythm with ReliaQuest and internal teams to ensure smooth escalations, clear responsibilities, and consistent response quality globally.
Metrics & Reporting
  • Help define, track, and improve operational KPIs such as MTTR, MTTC, time-to-triage, containment SLA adherence, repeat-incident drivers, and quality of post-incident actions.
  • Provide insight-driven reporting to TD&R leadership on trends, systemic issues, and targeted investments needed to raise response maturity.
QUALIFICATIONS
  • 6+ years in Incident Response, Security Operations, or Blue Team roles, including leading high-severity incidents end-to-end.
  • Proven ability to serve as an escalation lead and incident commander-calm, decisive leadership in ambiguous, high-pressure situations.
  • Strong communication skills: able to translate complex technical details into clear, actionable updates for executives and stakeholders.
  • Experience operating in cloud-forward enterprises, including hybrid environments spanning SaaS, cloud-native workloads, and on-prem systems.
  • Strong familiarity with identity-centric security models and investigations (federated identity, IAM abuse patterns, token theft, conditional access signals).
  • Working knowledge of cloud-native architectures (containers/Kubernetes, serverless, CI/CD) and the investigative/containment challenges they introduce.
  • Experience partnering with MSSPs and distributed teams; comfortable operating in a hybrid SOC model (internal + ReliaQuest).
  • Familiarity with MITRE ATT&CK and applying it to investigative thinking, readiness planning, and validation priorities.
  • Experience designing, using, or validating automated response workflows (SOAR) and promoting safe automation patterns.
  • Exposure to AI-assisted SOC/IR tooling, including governance considerations (data handling, audit logging, human approval, evaluation).
  • Experience with purple teaming, detection validation, or adversary simulation platforms (e.g., Atomic Red Team, Caldera, Cymulate). (Preferred)
  • Ability to influence engineering roadmaps (telemetry, enrichment, workflow improvements) based on operational pain points and incident learnings. (Preferred)
IDEAL CANDIDATE PROFILE
  • Incident leader: takes ownership, drives clarity, and brings structure to high-severity response.
  • Technically deep and business-aware: understands attacker behavior and business impact equally well.
  • Operationally disciplined: strong instincts for repeatability, playbooks, and learning loops.
  • Collaborative and influential: can align MSSP + internal teams, and partner effectively with SOC Engineering and platform teams.
  • Future-oriented: comfortable modernizing response for cloud-first and AI-enabled operating models.

WHY JOIN US? This is a pivotal leadership role in a globally scaled Threat Detection & Response function at a leading investment firm. As U.S. Regional Lead, you will shape incident response outcomes for critical enterprise operations and directly influence how KKR modernizes response for a cloud-first, AI-enabled future. You'll partner with a high-performing MSSP and an engineering-driven TDR team to improve readiness, accelerate containment, and raise the bar on response quality across the organization.

This is the expected annual base salary range for this New York-based position. Actual salaries may vary based on factors, such as skill, experience, and qualification for the role. Employees may be eligible for a discretionary bonus, based on factors such as individual and team performance.

Base Salary Range

$150,000-$180,000 USD

KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law.

KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email View email address on click.appcast.io. Emails sent for unrelated issues, such as following up on an application, will not receive a response.

If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access because of your disability. You can request reasonable accommodations by sending an email to View email address on click.appcast.io. Only emails left for this purpose will be returned.

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. This notice applies only to applicants and employees who work or will work in Massachusetts, in accordance with applicable state law.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Threat Detection & Response - Blue Team Lead in New York, NY vacancy
  • $173k - $226.8k

     ...Security Operations Engineering Manager to lead our Security Operations team. In this role, you’ll be leading and...  ...out our security operations and response capabilities. You thrive in a team...  ...of security incidents. Partner with Detection Engineering team to mature detection... 
    Suggested
    Temporary work
    Local area
    Worldwide

    Omaze

    New York, NY
    2 days ago
  • $119k - $145k

     ...professional to perform investigations into detected threats and utilize customers’ security products...  ...products like CrowdStrike and Microsoft Defender. Responsibilities include providing thorough reports to customers, leading team projects, and participating in an on-call... 
    Suggested
    Night shift

    Framework Ventures

    New York, NY
    2 days ago
  • $168k - $195k

     ...Principal Lead Analyst of DART At Corebridge Financial...  ...the company. The team drives technology and digital...  ...defense and incident response. This is a high-impact...  ...the evolution of our threat-hunting program, and...  ...scenarios. Advanced Detection & Hunting Strategy... 
    Suggested
    Work at office
    Local area
    Immediate start
    Remote work
    Shift work

    Corebridge Financial

    Jersey City, NJ
    1 day ago
  • $10k

    About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing...  ...Design and implement automation to detect and respond to threats What You Need 3-4 years of information technology... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    Ramp

    New York, NY
    1 day ago
  • $170k - $290k

     ...Intelligence Leader to oversee their Cyber Threat Intelligence, Detection Engineering, and Cyber Hunt programs....  ...and collaborating with various teams to enhance security measures. Ideal candidates...  ...threat intelligence and incident response, along with excellent communication... 
    Suggested

    The Security Executive Council

    New York, NY
    4 days ago
  • Aegistech is seeking a Cyber Incident Response Analyst to enhance their security program. This role involves detecting and responding to security incidents, collaborating with Security Operations and Threat Intelligence teams to ensure comprehensive incident management.... 

    Aegistech

    New York, NY
    2 days ago
  •  ...A forward-looking tech company is seeking an experienced Security Engineer specialized in detection and response. The role involves designing and implementing security measures to protect sensitive information and ensure compliance with regulations. Candidates should... 

    Cape

    New York, NY
    2 days ago
  •  ...dedicated to transforming how patients receive care is seeking a Sr. Cyber Threat & Response Engineer. In this role, you will identify, analyze, and mitigate cyber threats, collaborate with a security team, and respond to critical alerts post-hours. Ideal candidates will... 
    Remote work
    Flexible hours

    Arcadia

    New York, NY
    2 days ago
  • Job Description The Incident, Threat, and Change Management Team Lead is responsible for overseeing security incident/threat operations and enterprise change...  ...regulators where applicable. Operate and mature threat detection capabilities (SIEM/SOAR, EDR, email security, IDS)... 
    Local area
    Remote work

    Ellkay, Llc

    New York, NY
    4 days ago
  • A cybersecurity firm is seeking a Manager, Offensive Security to lead a team focused on threat detection across diverse technologies. In this role, you'll oversee detection engineering, mentor cybersecurity engineers, and drive security operations' performance. Ideal candidates... 

    Barracuda

    New York, NY
    5 days ago
  • A leading cybersecurity firm is seeking a Manager, Offensive Security to lead a dedicated team focused on threat detection and attack simulations across various technologies. This position involves driving detection innovations and enhancing the Security Operations Center... 

    Barracuda

    New York, NY
    2 days ago
  • $42 per hour

    Triple Canopy is seeking a Security Operations Center Supervisor in New York, NY. This role involves leveraging your expertise to detect and prevent violence against the corporation's Security Operations Center in Manhattan. You will manage shift operations, collaborate... 
    Shift work

    Triple Canopy

    New York, NY
    1 day ago
  •  ...cFocus Software Incorporated is seeking an Insider Threat Program Lead to design and oversee insider threat detection capabilities within a federal enterprise...  ...demonstrated ability to support federal agencies. Responsibilities include developing detection methodologies,... 

    cFocus Software Incorporated

    New York, NY
    2 days ago
  •  ...Software Incorporated is seeking a Cyber Threat Intelligence & Threat Hunting Lead to oversee cyber threat intelligence, detection engineering, and proactive threat...  ...years in CTI or threat hunting programs. Responsibilities include leading operations, developing detection... 

    cFocus Software Incorporated

    New York, NY
    2 days ago
  •  ...cFocus Software Incorporated is seeking a Threat Emulation & Readiness Lead to oversee adversary emulation and red team operations, supporting federal cybersecurity...  ...deep understanding of adversary tradecraft. Responsibilities include leading red team operations,... 

    cFocus Software Incorporated

    New York, NY
    2 days ago
  • $110k - $150k

     ...Job Description : Position - Lead, Cyber Threat Intelligence Location - NYC 1211...  ...want to be part of a cutting edge team, we want to hear from you! Job...  ...Cyber Threat Intelligence who will be responsible for analyzing, detecting, and communicating cyber... 
    Work experience placement
    Work at office
    Local area
    Flexible hours

    News Corp

    New York, NY
    5 days ago
  • $168k - $280k

     ...are reflected in how our team works: we embrace AI as a...  ...for a senior manager to lead the GitLab security incident response team (SIRT) in the Americas...  ...SIRT is responsible for threat hunting, alert triage, security...  ...incident response, AI detection and response capabilities... 
    Remote work
    Home office
    Flexible hours
    Shift work
    Night shift
    Weekend work

    GrabJobs

    New York, NY
    4 days ago
  • $320k - $405k

     ...seeking a Senior Technical Program Manager to lead their incident management program. This role involves owning the end-to-end response lifecycle, analyzing incident trends, and...  ...improvements are implemented across teams. Ideal candidates will have over 7 years in... 

    anthropic

    New York, NY
    4 days ago
  • A leading fitness technology company is seeking a Senior Cyber Analyst. You will support their Security Program, perform in-depth intelligence analysis, and develop incident response protocols. The ideal candidate will have at least 5 years of experience in Information... 

    Peloton Interactive

    New York, NY
    5 days ago
  • $145k - $195k

    Service Delivery Manager, Managed Detection and Response, United States WHO WE ARE S-RM is a global...  ...demand than ever. We’re building a team to meet this challenge. We’re quick to...  ...service quality with clients. This includes leading QSRs, managing escalations,... 
    Full time
    Immediate start
    Flexible hours
    Shift work

    S-RM

    New York, NY
    1 day ago
  • A leading restaurant technology provider is seeking a Staff Security Engineer to lead the Security Blue Team. This position involves guiding a team in information protection, overseeing incident detection and response, and implementing security measures across all platforms... 
    Remote job

    Olo

    New York, NY
    3 days ago
  • $125k - $135k

    Evrhire is seeking a full-time Cyber Threat Intelligence Specialist in New York. This role involves performing specialist Threat Intelligence...  ...from collection to dissemination, and supporting incident response efforts. Candidates should have 5-7 years of experience in... 
    Full time

    Evrhire

    New York, NY
    3 days ago
  •  ...Cyber Security division for an Incident Response Engagement Lead in the United States. S-RM is a global...  ...demand than ever. We’re building a team to meet this challenge. We’re quick to...  ...Advising strategies for responding to cyber threat actors. Providing crisis management... 
    Immediate start
    Flexible hours

    S-RM Intelligence and Risk Consulting

    New York, NY
    1 day ago
  • $115.4k - $192.3k

    About the role As an Analytics Team Lead, you will provide technical...  ...largest, real‑time fraud detection platform to craft solutions...  ...needs and project demand. Responsibilities Lead analytics workstreams...  ...fight emerging and dormant threats. Inspire the wider team to do... 
    Local area
    Immediate start
    Remote work

    RELX INC

    New York, NY
    3 days ago
  •  ...and airspace solutions sector. This remote position, which requires travel to Dallas, TX, involves leading a team to manage technical support operations. Responsibilities include overseeing hardware and SaaS support, improving processes, and ensuring high-quality service... 
    Remote work

    Peskind Executive Search, Inc.

    New York, NY
    2 days ago
  • $100k - $130k

     ...A leading cybersecurity firm is seeking a proactive Security Analyst to join their team in the United States. This role involves monitoring security alerts, responding to incidents, and developing threat detection capabilities. The ideal candidate will have 4-6 years of... 
    Remote work

    BLACKCLOAK

    New York, NY
    2 days ago
  • $130k - $165k

     ...redefining the incident response model by delivering a...  ...data theft, and other threats. Our client‑centric approach...  ...: Principal Engagement Lead- Digital Forensic and...  ...with cross‑functional teams, and external stakeholders...  ...lifecycle from detection to recovery. Conduct scoping... 
    Full time
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours
    Weekend work

    Surefire Cyber, LLC.

    New York, NY
    12 hours ago
  •  ...AI Security Lead / Architect New York, NY (Hybrid, 3 days in office) Highly...  ...complex problems in any industry. Their teams are composed of passionate problem-...  ...innovative security tools to automate threat detection and response within our AI infrastructure. Champion... 
    Work at office

    Elliot Partnership

    New York, NY
    24 days ago
  • $130k - $200k

     ...unmet medical needs. As a leading innovator of Digital...  ...inspire a high-performing team, while strategically collaborating...  ...in office each week. Responsibilities: Maintain, and...  ...capabilities, including threat intelligence, monitoring, detection, and analysis.... 
    Permanent employment
    Temporary work
    Work at office
    Local area
    Visa sponsorship
    Flexible hours

    Click Therapeutics, Inc.

    New York, NY
    4 days ago
  • $112k - $140k

     ...Quantinuum is hiring a Senior Insider Threat Analyst to lead advanced insider threat analysis and investigations. This role involves reviewing and prioritizing complex alerts, conducting behavioral analysis, and partnering closely with Legal and HR. Candidates should... 
    Flexible hours

    Quantinuum

    New York, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Threat Detection & Response - Blue Team Lead. Be the first to apply!