Alert, Detection, and Response Engineer, VP - Cybersecurity
Miami, United States
Full Time Executive-level / Director USD 175K - 225K
Blackstone
Blackstone is the world’s largest alternative asset manager, serving institutional and individual investors by building strong businesses positioned to deliver lasting value.Blackstone is the world’s largest alternative asset manager. We seek to create positive economic impact and long-term value for our investors, the companies we invest in, and the communities in which we work. We do this by using extraordinary people and flexible capital to help companies solve problems. Our $1.1 trillion in assets under management include investment vehicles focused on private equity, real estate, public debt and equity, infrastructure, life sciences, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis. Further information is available at www.blackstone.com. Follow @blackstone on LinkedIn, X, and Instagram.
Business Unit Overview:
Blackstone Technology & Innovations (BXTI) is the technology team at the core of each of Blackstone’s businesses and new growth initiatives. Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency and improve transparency within the firm and across our broad community of investors and portfolio companies.
BXTI is nimble and entrepreneurial – our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one. We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence. We collaborate to find the best answers for our customers and for Blackstone. We are critical to the firm maintaining its competitive edge.
The Role:
The Alert, Detection, and Response Engineer in our Cybersecurity Operations team is integral to keeping our team on the forefront of security detection and response maturity efficiency. They are a core member of our SOC strategy with a focus on escalated incident response / investigations, advanced detection engineering, and continuous advancement of our Blue Team capabilities. The ideal candidate will have hands-on experience with conducting investigations with cybersecurity platforms (e.g. email, endpoint, network, and cloud-based threat detection) and developing custom detections to address emerging and advanced cyber threats. This involves staying abreast of the latest threat landscape and ensuring that detection systems are agile and responsive to evolving security challenges. The candidate will work closely across the cybersecurity organization to develop bespoke detections and playbooks to support more advanced investigations and response requirements.
Responsibilities:
Develop advanced threat detection mechanisms to identify and raise alerts for adversarial or high-risk behaviors within the company's systems.
Act as an experienced senior incident responder, leading complex investigations and managing incidents from detection through resolution using tools such as security incident and event management (SIEM) and endpoint detection and response (EDR).
Continuously improve and fine-tune detection portfolio to adapt to new and emerging cyber threats.
Represent the Blue Team on Red and Purple Team efforts to design and build detections.
Provide exceptional Tier 1-3 escalation support including for analysis, investigations, and engineering.
Supervise and monitor the quality of security operations investigations.
Provide reporting and analysis on investigations and trends.
Work with the security engineering team to identify trends in detections and investigations to better inform the engineering process (security by design).
Coach and train junior team members on detection and investigation techniques.
Qualifications:
6+ years in a hands-on technical role in information security.
Experience with cloud-native architectures such as AWS, Azure, Office 365, etc.
Proven experience running investigations and managing incidents through security event detection platforms, SIEM platforms (e.g. Splunk) and EDR (e.g. CrowdStrike).
Hands on experience creating custom detections within event detection and SIEM platforms.
Working knowledge of a wide range of current network security technologies such as firewalls, proxies, network and host-based intrusion prevention, DLP, vulnerability assessment tools, security information/event management, endpoint security, anti-virus/anti-malware, etc.
Digital forensics experience such as network analysis, malware analysis, memory analysis, etc.
Development/scripting experience: Python and/or PowerShell.
Ability to self-Highly organized, prioritize activities independently, create documentation and handle reporting.
Ability to iInteractsface with business and technology stakeholder.
Strong written and oral communication skills; with the ability to effectively explains technical ideas to non-technical individuals at any level.
B.S. in Computer Science or Engineering or similar technical program.
The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position. Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.
Expected annual base salary range:
$175,000 - $225,000Actual base salary within that range will be determined by several components including but not limited to the individual's experience, skills, qualifications and job location. For roles located outside of the US, please disregard the posted salary bands as these roles will follow a separate compensation process based on local market comparables.
Additional compensation: Base salary does not include other forms of compensation or benefits offered in connection with the advertised role.
Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training. All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.
If you need a reasonable accommodation to complete your application, please email Human Resources at HR-Recruiting-Americas@Blackstone.com.
Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and/or if you are engaged in the following:
Attending client meetings where you are discussing Blackstone products and/or and client questions;
Marketing Blackstone funds to new or existing clients;
Supervising or training securities licensed employees;
Structuring or creating Blackstone funds/products; and
Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials.
Note: The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis. Please speak with your Blackstone Recruiting contact with any questions.
To submit your application please complete the form below. Fields marked with a red asterisk * must be completed to be considered for employment (although some can be answered "prefer not to say"). Failure to provide this information may compromise the follow-up of your application. When you have finished click Submit at the bottom of this form.
Tags: Agile AWS Azure Blue team Cloud Computer Science CrowdStrike EDR Endpoint security Firewalls Forensics Incident response Intrusion prevention Malware Network security PowerShell Python Scripting SIEM SOC Splunk Strategy Threat detection
Perks/benefits: Competitive pay Equity / stock options Flex hours Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.