Insight Global logo

Staff Level - Detection & Response Engineer

Insight Global

San Francisco, CA · HybridContractSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
San Francisco, CAHybrid
Schedule
Contract
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Insight Global seeks a Staff-level Detection & Response Engineer to mature detection engineering and incident response capabilities, develop custom detections, assess telemetry, lead investigations, act as Incident Commander, and shape security operations across cloud, endpoint, identity and application environments.

Skills & qualifications

RequiredNice to have

Skills

Security OperationsDetection EngineeringIncident ResponseThreat HuntingCrowdStrike FalconCortex XDRSentinelOneMicrosoft DefenderPalo Alto CortexCustom DetectionsTelemetry Coverage AssessmentAlert Fidelity TuningSIEM PlatformsIncident CommanderPlaybook CreationSecurity Telemetry ArchitectureMITRE ATT&CK FrameworkStakeholder CommunicationExecutive‑Facing CommunicationMDR ManagementSecurity AutomationPythonThreat Intelligence ProgramsTabletop Exercise LeadershipCloud Telemetry ArchitectureDetection Coverage Modeling

Qualifications

8-12 Years Security Operations Experience

Full job description

Job Description

TITLE: Staff level - Detection & Response Engineer TEAM: Cybersecurity LOCATION: San Francisco, CA SCHEDULE: Hybrid (Target 3 days onsite per week) WORK HOURS: Primarily 9:00 AM - 5:00 PM PT with occasional incident response coverage DURATION: 6+ Month Contract 2 Hire START DATE: ASAP

ABOUT THIS ROLE:

Insight Global is seeking a Detection & Response Engineer to help mature the client's detection engineering and incident response capabilities.

The ideal candidate is equally comfortable building custom detections as they are leading complex cybersecurity incidents. This role requires someone who can assess telemetry coverage, improve detection quality, build response playbooks, tune alerting logic, manage MDR relationships, and confidently act as incident commander during security events.

This is a Staff-level security engineering role. The team is looking for someone who can help define detection strategy, determine what threats matter most to the organization, evaluate whether telemetry exists to detect those threats, and build a sustainable detection and response program. Candidates should understand why a detection is being written and what attack behavior it is intended to identify, rather than simply creating alerts.

This is also the highest visibility role across the security organization. The individual will regularly engage with Engineering, Security, IT, leadership teams, and executive stakeholders during highly sensitive security incidents.

DAY-TO-DAY

  • Develop and tune detections across a cloud-first technology stack
  • Assess logging and telemetry coverage across endpoint, cloud, identity, and application environments
  • Improve detection fidelity and reduce false positives
  • Build threat-informed detection strategies
  • Lead incident investigations from detection through remediation
  • Act as Incident Commander during security events
  • Create and improve response playbooks and operating procedures
  • Conduct threat hunting activities
  • Partner with MDR vendors including Red Canary
  • Run tabletop exercises and incident simulations
  • Help shape and scale the organization's security operations program

Skills and Requirements

Required Skills & Experience

  • 8-12 years of Security Operations, Detection Engineering, Incident Response, Threat Hunting, or related experience
  • Strong experience with EDR platforms such as CrowdStrike Falcon, Cortex XDR, SentinelOne, Microsoft Defender, Palo Alto Cortex, or similar
  • Experience building and tuning custom detections
  • Experience assessing telemetry coverage and detection gaps
  • Experience tuning alert fidelity and reducing false positives
  • Experience with SIEM environments and detection engineering workflows
  • Strong threat hunting experience
  • Strong incident response leadership experience
  • Experience acting as Incident Commander or Incident Lead during security incidents
  • Experience creating and improving incident response playbooks
  • Experience with security telemetry architecture and logging strategy
  • Understanding of MITRE ATT&CK Framework and threat-informed defense
  • Strong stakeholder communication and executive-facing communication skills

Tech Stack

  • CrowdStrike Falcon (Preferred) or SentinelOne or Cortex XDR or Palo Alto Cortex or Microsoft Defender

  • Red Canary

  • AWS

  • Okta

  • SIEM Platforms

  • SOAR Platforms

  • Threat Intelligence Platforms Nice to Have Skills & Experience

  • MDR management experience

  • Security Automation

  • Python scripting

  • Threat Intelligence Programs

  • Tabletop Exercise Leadership

  • Cloud telemetry architecture experience

  • Detection coverage modeling experience

LOOKING FOR:

  • Detection engineering ownership, not alert monitoring experience
  • Incident leadership and incident response expertise
  • Ability to determine what should be detected and why
  • Telemetry strategy experience
  • Strong stakeholder management and executive communication skills
  • Program-level ownership and Staff/Principal-level thinking

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.