Detection & Case Management Lead
Tasks
- Build automated alerting frameworks
- Coordinate incident response and remediation tracking
- Create runbooks and SOPs for detection tuning
- Define detection architecture standards
- Design case management triage and enrichment
- Govern detection rule lifecycle
- Implement dashboards for detection metrics
- Improve telemetry ingestion and normalization
- Maintain continuous improvement for detection coverage
- Mentor SOC and NOSC analysts
- Translate threat intelligence into detection use cases
- Tune detections to reduce false positives
- Validate detections using telemetry analysis
Perks/Benefits
- N/A
Skills/Tech-stack
Case management | Cloud Security | Dashboarding | Detection engineering | EDR | IDS | IPS | MTTD | MTTR | Mitre Attack | Network Monitoring | OT monitoring | Red Teaming | SIEM | SOAR | Telemetry normalization | Threat Emulation | Threat Intelligence | Vulnerability Management | XDR
Education
Related jobs
-
Chief Information Security Officer (CISO) USD 175K-290K800-171 | 800-53 | AWS | Access Management | Application SecurityExecutive-level Full TimeRemote, United States R12h ago
-
Senior Security Engineer USD 166K-220KCloud Security | Go | ICS Security | Incident Response | LinuxSenior-level Full TimeWashington, District of Columbia, United States12h ago
-
Senior Security Engineer USD 166K-220KCloud Security | Go | ICS Security | Incident Response | LinuxTravel opportunity | U S Top Secret Security Clearance SponsorshipSenior-level Full TimeSeattle, Washington, United States12h ago
-
Incident Response Engineer USD 70K-136KCyber Investigations | Digital forensics | Incident Response | Malware analysis | SIEMMid-level Full TimeArlington, VA12h ago
-
Lead Product Security Engineer USD 165K-205K800-171 | 800-53 | Application Security | Bash | Build provenance401k | Dental insurance | Health insurance | Hybrid remote/in-office | Inclusive cultureSenior-level Full TimeRemote (United States) R12h ago
-
Manager, Threat Detection and Response USD 187K-253KAWS | Alert triage | Antivirus | Cloud Security | Detection engineeringAI adoption guidance | Occasional off hours incident response supportMid-level Full TimeNew York, New York, United States13h ago
-
Amazon ECS | Amazon EKS | Automation | Chef | Cloud SecurityEquity compensation | Health benefits | Onsite days schedule | Optional remote days N/ASenior-level Full TimeSan Mateo, CA, United States R13h ago
-
Vice President, Information Security USD 200K-250KAI Security | API Security | AWS Security | Access Management | Active DirectoryExecutive-level Full TimeDenver, CO15h ago
-
Senior Security Engineer, Detection Engineering USD 181K-217KAWS | Cloud Security | Cloud platform | Data Pipelines | Detection engineering401k match | Accident insurance | Dental insurance | Disability insurance | Employee assistance programSenior-level Full TimeDenver, CO; New York City, NY; … R15h ago
-
Senior Information Security Engineer USD 150K-180KAWS | Access Management | Agentic Frameworks | CI/CD | CNAPP401k | Disability benefits | Life insurance | Low cost health care | Mental health resourcesSenior-level Full TimeDenver, CO, United States15h ago
-
Cybersecurity Engineer USD 120K-160KAccess Control | Access Management | Alert Tuning | CI/CD | CIS BenchmarksFree dog walking services for office pets | Free parking | Free parking and gym | Free pet medical insurance | Full medical, dental, and vision benefitsMid-level Full TimeSeattle, United States15h ago
-
Systems Engineer USD 95K-95K800-53 | AWS | Active Directory | Azure | CIS Hardening401k retirement plan | Dental insurance | Employee assistance program | Enhanced PTO | Flexible spending accountsMid-level Full TimeRemote, United States R16h ago
-
Network Security Administrator/Security Net V USD 119K-145KAccess Control | Business Continuity | Capacity Planning | Cybersecurity compliance | Detection SystemsMid-level Full TimeVirginia Beach, Va17h ago
-
AWS | Access Management | Adversarial Simulation | Application Security | AzureExecutive-level Full TimeUS-WA-Bellevue17h ago
-
Information Systems Security Engineer USD 104K-154KAccess Management | Application whitelisting | Artificial Intelligence | Awareness Training | Certificate management401k plan | Dental insurance | Disability insurance | Firm paid holidays | Flexible spending accountsSenior-level Full TimePhoenix, Arizona, United States; Denver, Colorado, …17h ago
-
800-171 | 800-53 | API Gateway | AWS | AWS Lambda401k | Paid leaveSenior-level Full TimeWashington, DC18h ago
-
Cloud Support Engineer - Security USD 104K-199KAWS | AWS Config | AWS IAM | Access Management | Access reviews401k match | Employee assistance program | Family building benefits | Flexible spending accounts | Learning and mentoring opportunitiesMid-level Full TimeDallas, Texas, United States18h ago
-
Sr. SIEM Engineering Consultant USD 140K-180KAccess Management | Ansible | Azure | Azure Monitor | BashRemote work | Security clearance eligibility | Support for on site engagementsSenior-level Full TimeWork from home, VA, United States R19h ago
-
Sr. TORQ/SOAR Engineer USD 140K-190KAgentic Automation | Ansible | Automation workflows | CI/CD | Context ManagementRemote work | Travel for client visits | U S passport requirementSenior-level Full TimeWork from home, VA, United States R19h ago
-
Senior-level Full TimeWork from home, VA, United States R19h ago
-
Software Engineer SME (TS/SCI with Poly Required) USD 187K-318KAWS | Apache Airflow | Apache Hive | Apache NiFi | Apache SparkTS SCI Clearance with Polygraph | US citizenship requiredMid-level Full TimeTysons Corner, Virginia, United States19h ago
-
Senior Application Security Engineer USD 121K-230KAWS | Application Security | Application Security Posture Management | Application Security Testing | Azure401k | Long-term incentive program | Medical/Dental/Vision insurance | Paid time offSenior-level Full TimeButler, PA, United States19h ago
-
Endace Platform Engineer USD 50K-150KAnsible | Bash | DNS | Deep Packet Inspection | EDRCorporate holidays | Flexible time off | Group dental insurance | Group medical insurance | Home internet allowanceMid-level Full TimeReston, VA19h ago
-
Security Engineer, Insider Threat USD 130K-192KAutomation | Cloud Computing | DLP | Data Pipelines | Git401k employer matching | Basic life insurance | Commuter benefits match | Disability insurance | Family-forming assistanceMid-level Full TimeUnited States - Remote R20h ago
-
Manager, Security Engineering & Operations USD 123K-175KAI | AWS | Automation | CNAPP | Detection engineeringHybrid work | Remote workSenior-level Full TimeUnited States, Remote R21h ago