Detection & Response, Lead
Core
Lead security detection and response initiatives, focusing on maturing alerting capabilities for federal and public sector environments.
Role type
Lead Security Operations Engineer (Detection & Response)
Builds
Security detection and alerting systems, automated remediation workflows, and runbooks for federal/public sector environments.
Domain
Cybersecurity, Information Security Operations, Federal/Public Sector
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
incident response (C/SIRT/CERT/SOC), log management (ELK/Datadog/Panther), automation design, threat pattern identification, triage, runbook creation
Preferred skills
government entity experience, workflow automation tooling (Tines/Swimlane), security certifications (CompTIA Security+/Network+)
Technologies
ELK, Datadog, Panther, Tines, Swimlane
Responsibilities
Respond to and assist with security incidents, review logs and alerts for triage, tune security alerts and runbooks, collaborate on automated remediation, utilize log platforms for threat pattern analysis, design and implement detection automation
Seniority
Senior, hands-on IC with leadership focus