Security Engineer, Detect & Respond
Core
Build and operate detection and response capabilities for a financial services company's security infrastructure, focusing on high-signal alerts, SIEM administration, and incident response.
Role type
Security Engineer (Detect & Respond)
Builds
Detection rules, SIEM integrations, incident response playbooks, and AI security monitoring tools
Domain
Financial Services / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SIEM/SOAR platform experience, incident response triage, scripting/programming, cloud security (AWS), SaaS security tools (CrowdStrike, Okta), MITRE ATT&CK frameworks, AI security awareness
Preferred skills
Experience with AI tooling and governance, building automations for on-call workflows, translating threat behavior into practical detections
Technologies
SIEM, SOAR, AWS, CrowdStrike, Okta, AI tools
Responsibilities
Build and evolve detection capabilities across infrastructure; improve detections using on-call feedback; integrate SaaS logs into SIEM; participate in security on-call cycles; contribute to SIEM administration; build automations to reduce manual toil; develop detection coverage for AI surfaces; support incident response triage and investigation; review new systems for telemetry needs
Seniority
Mid-level, hands-on IC