JobTarget Logo

Detection and Response Lead in Abbeyville, Colorado at Jobgether

NewJob Function: Admin/Clerical/Secretarial
Jobgether
Abbeyville, Colorado, 81210, United States
Posted on
New job! Apply early to increase your chances of getting hired.

Explore Related Opportunities

Job Description

Detection and Response Lead

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Lead based in the United States.

As Detection and Response Lead, you will build and lead a technically deep detection and response capability across enterprise and cloud environments. You will own advanced investigations, incident response, threat hunting, and continuous improvement of defensive security operations. Working closely with security engineering and external MSSP/MDR partners, you will serve as the escalation point for complex security events and drive incidents through investigation, containment, and remediation. The role combines hands-on technical execution with operational leadership and close partnership with the CISO and senior stakeholders. You will strengthen detection quality, improve monitoring coverage, and develop repeatable response processes and playbooks. Your work will directly improve the organization’s ability to detect, understand, and contain sophisticated threats across AWS, Azure, endpoints, identities, and enterprise infrastructure.

Accountabilities:
  • Lead incident response for escalated MSSP and MDR alerts, including scoping, investigation, containment, and remediation across cloud, endpoint, identity, and enterprise environments.
  • Provide emergency-only on-call support for high-severity security incidents when required.
  • Conduct detailed forensic investigations using SIEM, EDR, proxy, WAF, DLP, cloud, endpoint, and network telemetry to reconstruct events and identify attacker activity.
  • Correlate logs and security events to establish accurate incident timelines, determine scope and impact, and identify attacker techniques and behaviors.
  • Produce concise, high-quality investigative reports outlining findings, timelines, root causes, business impact, and recommended remediation actions for both technical and non-technical stakeholders.
  • Conduct hypothesis-driven and data-driven threat hunts to uncover malicious or suspicious activity that has bypassed automated detections and external monitoring workflows.
  • Develop repeatable threat-hunting methodologies based on attacker behavior, business-specific risks, historical incidents, and emerging threat patterns.
  • Document and communicate threat-hunting outcomes, translating discoveries into new detection opportunities and defensive improvements.
  • Review MSSP and MDR escalations for quality, signal-to-noise ratio, accuracy, and detection fidelity, establishing structured feedback loops to improve external security operations.
  • Identify gaps in logging, telemetry, detection logic, monitoring coverage, and investigative capabilities, and partner with security engineering and technology teams to close those gaps.
  • Establish and improve metrics such as Mean Time to Detect, Mean Time to Contain, and detection coverage to measure and strengthen defensive effectiveness.
  • Serve as the primary technical escalation point for security incidents requiring advanced analytical, investigative, or containment expertise.
  • Coordinate cross-functional response efforts involving IT, cloud teams, application owners, security engineering, and other technical stakeholders during active incidents.
  • Maintain strong alignment with MSSP and MDR partners by defining clear escalation criteria, severity thresholds, response procedures, ownership models, and communication expectations.
  • Report significant incidents, detection trends, response performance, and security risks to the CISO and senior leadership.
  • Develop and maintain operational runbooks, investigation procedures, incident response guides, and defensive playbooks.
  • Analyze recurring attacker behaviors and translate lessons learned from investigations and hunts into durable operational processes and detection improvements.
  • Help shape and mature the broader detection and response program, identifying opportunities to improve tools, processes, workflows, and organizational readiness.
Requirements
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related discipline, or equivalent professional experience.
  • 7+ years of hands-on experience in cybersecurity operations, incident response, threat detection, or a closely related security discipline.
  • Demonstrated experience leading complex security investigations involving cloud environments, identity systems, endpoints, networks, and modern security tooling.
  • Proven ability to build, mature, or significantly improve a detection and response program in partnership with security leadership.
  • Strong knowledge of attacker tactics, techniques, and procedures, including practical application of frameworks such as MITRE ATT&CK.
  • Hands-on expertise in log analysis, event correlation, security telemetry, and investigative techniques.
  • Practical knowledge of digital forensics fundamentals, including artifact analysis, timeline creation, host investigation, and network investigation.
  • Experience independently taking ownership of escalated MDR or MSSP alerts and driving investigations through deeper analysis, containment, and remediation.
  • Strong experience analyzing AWS and Azure security telemetry, including CloudTrail, CloudWatch, IAM, network telemetry, and workload-level events.
  • Demonstrated ability to take appropriate containment actions in cloud environments while balancing security, operational continuity, and business requirements.
  • Experience working with SIEM, EDR, proxy, WAF, DLP, or related security technologies from an investigative and incident-response perspective.
  • Strong understanding of how to operate effectively alongside managed SOC, MSSP, or MDR providers and integrate external security operations with internal response capabilities.
  • Prior threat-hunting experience in cloud-first, hybrid, or complex enterprise environments is highly desirable.
  • Incident response or digital forensics certifications such as GCIH, GCFA, GNFA, or GCFE are advantageous.
  • Excellent written and verbal communication skills, with the ability to communicate complex technical findings clearly and concisely to both technical teams and senior leadership.
  • Strong analytical thinking, investigative curiosity, sound judgment, and the ability to remain composed during high-severity incidents.
  • Ability to work independently while collaborating effectively across security engineering, IT, cloud, application, and business teams.
  • Must be legally authorized to work in the United States.
Benefits
  • $160,000–$200,000 USD annual base salary, with actual starting compensation determined by skills, qualifications, training, and experience.
  • Eligibility for bonus compensation.
  • Comprehensive medical, dental, and vision insurance.
  • 401(k) retirement plan with company matching contributions.
  • Employee Ownership Program, allowing eligible employees to share in financial rewards as the organization grows.
  • Professional development opportunities.
  • Owner Referral Program.
  • Work-from-home reimbursement for eligible remote or hybrid roles.
  • Canary emergency financial assistance program.
  • Life and AD&D insurance.
  • Confidential Employee Assistance Program.
  • Health Savings Account with company contribution.
  • Short-term disability coverage.
  • Voluntary accident, critical illness, and hospital insurance options.
  • Employee discounts.
  • Addition Wealth financial wellness program.
  • Various paid time-off programs.
  • 11 company-paid holidays.
  • Collaborative and mutually supportive work environment.
  • Opportunities to work closely with security leadership and help shape a growing detection and response function.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Job Location

Abbeyville, Colorado, 81210, United States

Frequently asked questions about this position

Similar Jobs In Abbeyville, Colorado

`Remote Work From Home - Entry-Level - No Experience Needed - Hiring Immediately

American Income Life AO - Kevin Blomquist
Abbeyville, Colorado
New

SAP Analitycs Cloud Consultant

Jobgether
Abbeyville, Colorado

⭐Immediate Openings – Work from Home | Remote Entry Level | Apply Today

American Income Life AO - Kevin Blomquist
Abbeyville, Colorado

IMMEDIATE HIRING - REMOTE JOB OPEN | NO EXPERIENCE REQUIRED | START ASAP

American Income Life AO - Kevin Blomquist
Abbeyville, Colorado

Hiring Now - Fully Remote Level Role | Start Immediately | No Experience Needed

American Income Life AO - Kevin Blomquist
Abbeyville, Colorado
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.
By clicking Continue, you understand and agree to JobTarget's Terms of Use and Privacy Policy.