Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity
Core
Tier 2 incident responder managing detection, investigation, and response to security incidents across email, endpoint, identity, network, and cloud environments.
Role type
Tier 2 SOC Analyst / Incident Responder
Builds
Production SIEM detections, automated response playbooks, and threat hunting capabilities
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Incident response procedures, SIEM query writing (SPL/KQL), EDR investigation, cloud/identity forensics, Python/PowerShell scripting, MITRE ATT&CK mapping, AI tool evaluation
Preferred skills
Detection engineering (Sigma/SIEM rules), Purple teaming, Threat hunting
Technologies
Splunk, Microsoft Sentinel, Elastic, CrowdStrike, SentinelOne, Microsoft Defender, Okta, Microsoft Entra ID
Responsibilities
Manage incident queue from intake to closure; Handle Tier 1 escalations and complex investigations; Author and tune SIEM detections; Conduct endpoint and cloud forensics; Mentor Tier 1 analysts; Participate in threat hunts and purple team exercises
Seniority
Mid-level, hands-on IC