Detection and Response Engineer
Core
Engineer detection capabilities, investigate incidents, and automate security operations using AI/LLMs across endpoint, network, cloud, and identity environments.
Role type
Senior IC detection and response engineer
Builds
Security detection rules, automated response playbooks, and AI-assisted SOC workflows
Domain
Cybersecurity, fintech/payment technology
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM/NG-SIEM tuning, EDR/XDR analysis, MITRE ATT&CK framework, Python/PowerShell scripting, cloud infrastructure (AWS), incident triage, forensic investigation, SOAR platform usage, threat intelligence analysis
Preferred skills
LLM/AI API integration, SOAR (n8n/Tines), cloud-native security tools (GuardDuty/Sentinel/SCC), digital forensics, purple teaming, payment/fintech regulatory knowledge
Technologies
CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel, AWS, Azure, GCP, Python, PowerShell, n8n, Tines, LLM APIs
Responsibilities
Design and maintain detection content (rules, correlation searches, use cases); Perform detection coverage and gap analysis using MITRE ATT&CK; Triage, investigate, and contain security incidents; Conduct root-cause analysis and post-incident reviews; Develop security automation and orchestration using SOAR and scripts; Evaluate and implement AI/LLM-powered solutions for alert triage and analyst workflows; Partner with cross-functional teams to address telemetry gaps; Monitor threat intelligence relevant to payment environments
Seniority
Mid-Senior, hands-on IC