Detection and Response Lead

ISC (Integrated Specialty Coverages, LLC)

United States

Hybrid

USD 160,000 - 200,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental and vision insurance
401(k) with company match
Work from home stipend

Job summary

Integrated Specialty Coverages, LLC (ISC) is seeking a senior, hands-on defender to build a detection and response function across AWS and enterprise environments. You will report to the CISO and partner with MSSP and MDR partners to mature detection and response capabilities.

The role emphasizes detection engineering, advanced investigation, threat hunting, and ownership of incident response. On-call availability for high‑severity incidents is required.

Qualifications

  • 7+ years of hands-on cybersecurity operations experience.
  • Experience leading complex investigations in cloud and on‑premise environments.
  • Strong knowledge of attacker TTPs and log correlation.
  • Ability to interpret MDR escalations and drive containment actions.
  • Experience with AWS and Azure security logs and containment measures.
  • Excellent written and verbal communication for technical and non‑technical audiences.

Responsibilities

  • Lead incident response for escalated MSSP/MDR alerts across cloud and endpoint environments.
  • Perform forensic review, log correlation, and attacker technique identification.
  • Provide clear incident findings, timelines and remediation steps to stakeholders.
  • Conduct hypothesis-driven and data-driven threat hunts to find hidden activity.
  • Drive improvements in detection coverage and reduce mean‑time‑to‑detect.

Skills

Cybersecurity operations
Incident response
Threat detection
Cloud security
MITRE ATT&CK
Digital forensics
AWS/Azure logs
MDR/MSSP collaboration
Log analysis
Team leadership

Education

Bachelor's in Computer Science or Cybersecurity

Tools

SIEM
EDR
Proxy
WAF
DLP
CloudTrail
CloudWatch
IAM

Job description

Integrated Specialty Coverages, LLC (ISC) is a growth stage technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market.

Backed by one of the leading private equity firms, Onex Partners, and led by a forward-thinking management team, ISC is combining the worlds of insurance and technology to create an Insurtech powerhouse. As a leading online distributor of insurance products for a range of industries and “Main Street USA”, we are looking for the right people to help us in our mission of achieving exponential growth. We strive to be the number one place to go for brokers and agents to source insurance. To accomplish this, we’re building a digitally focused team that deeply understands the intersection between user experience, data, and AI/ML to optimize the way we engage with our customers and partners.

Job Summary

ISC Cybersecurity is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across our enterprise and AWS environments. The role will report to the CISO and will partner with internal security engineering, as well as with our managed security services provider (MSSP) and managed detection and response (MDR) provider. The Detection & Response Lead focuses on detection engineering, advanced investigation, incident ownership, threat hunting, and maturing our detection and response capabilities. The role serves as the escalation point for security events, ensuring timely containment, high‑quality analysis, and actionable recommendations for improvement. This position is operational and technically deep, driving defensive execution across our AWS and enterprise environments.

Position Responsibilities
  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency‑only on‑call availability is required for high‑severity incidents.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and DLP technologies.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Threat Hunting
    • Conduct hypothesis‑driven and data‑driven hunts to identify malicious or suspicious activity not already surfaced by automated detections or MSSP/MDR workflows.
    • Develop internal hunting methodologies rooted in observed attacker behavior, business‑specific risks, and historical incident patterns.
    • Document and socialize hunt outcomes, including new detection opportunities and defensive insights.
  • Detection Quality & Continuous Improvement
    • Review MSSP/MDR escalations for quality, signal‑to‑noise ratio, and fidelity; drive improvements through structured feedback loops.
    • Identify gaps in log coverage, detection logic, or monitoring effectiveness and coordinate with engineering partners to close them.
    • Drive Mean‑Time‑To‑Detect and Mean‑Time‑To‑Contain metrics as well as detection coverage metrics.
  • Escalation Ownership & Internal Coordination
    • Serve as the technical escalation point for security incidents requiring deep analytical expertise.
    • Coordinate cross‑functional responders (IT, cloud, application owners) during active investigations.
    • Maintain tight alignment with MSSP/MDR workflows, ensuring clarity in escalation criteria, response procedures, and incident severity thresholds.
  • Operational Security Leadership
    • Report to CISO and interface with senior leadership during incidents.
    • Maintain operational runbooks, investigation procedures, and response guides.
    • Track recurring attacker patterns and translate them into defensible operational playbooks.
Minimum Qualifications
  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload‑level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings.
Preferred Qualifications
  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting threat hunts in cloud‑first or hybrid environments.
  • Exposure to SIEM/SOAR platforms from an investigative.
  • Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE).

This role also offers bonus pay. Your ISC Talent Acquisition representative will share more details about the bonus component should you advance in the interview process.

The starting annual pay scale for this position is listed below. Actual starting pay will be based on factors such as skills, qualifications, training, and experience. In addition, the company offers comprehensive benefits including medical, dental and vision insurance, 401(k) plan with match, paid time off, and other benefits.ISC's salary ranges are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job‑related skills, experience, and relevant education or training.

National Pay Range: $160,000 USD - $200,000 USD

Benefits of Working at ISC
  • Employee Ownership Program - every eligible employee shares in the financial rewards that grow when the company grows
  • Owner Referral Program
  • Work from home reimbursement for remote/hybrid roles
  • Canary emergency financial assistance program
  • Life/AD&D Insurance
  • Confidential, Employee Assistance Program
  • Health Savings Account, includes company contribution
  • Short‑term disability
  • Voluntary benefits - supplemental accident, critical illness, hospital insurance
  • 401(k) Plan with company match contribution
  • Addition Wealth Financial Wellness Program

Applicants may contact the ISC HR department via e‑mail or phone to request and arrange for an accommodation that will allow the applicant to successfully complete the application process. Applicants needing assistance may request accommodation at any time. Please contact ISC at HR@ISCMGA.com or 760-599-7242.

ISC believes in creating long‑term relationships by being responsive and relevant and by consistently delivering value to our community of customers. Specifically, we focus on attracting, developing, and retaining the best talent for our business, challenging our people, demonstrating a “can‑do” attitude, and fostering a collaborative and mutually supportive environment.

Diversity creates a healthier atmosphere: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, gender, gender identity, sexual orientation, marital status, medical condition, genetic information, mental or physical disability, military or veteran status, or any other characteristic protected by local, state, or Federal law.

**Must be legally authorized to work in the United States.**

**ISC participates in the Federal E-Verify program**

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and Response Lead
Detection and Response Lead

Integrated Specialty Coverages, LLC • United States

Remote
USD 120,000 - 180,000
Senior Underwriter Mid-Market (Workers Compensation)
Senior Underwriter Mid-Market (Workers Compensation)

ISC (Integrated Specialty Coverages, LLC) • United States

Hybrid
USD 101,000 - 127,000
Work from home reimbursement forremote
Medical, dental, vision insurance
401(k) plan with match
+3
Loss Control Consultant (Workers Comp)
Loss Control Consultant (Workers Comp)

ISC (Integrated Specialty Coverages, LLC) • United States

On-site
USD 84,000 - 130,000
Employee Ownership Program
Owner Referral Program
Work from home reimbursement
Complex Loss Specialist
Complex Loss Specialist

Socket.dev • United States

Hybrid
USD 87,000 - 109,000
Employee Ownership Program
Professional development opportunities
Work from home reimbursement forremote
+1
Underwriting Assistant Mid-Market
Underwriting Assistant Mid-Market

ISC (Integrated Specialty Coverages, LLC) • Buffalo (NY)

Hybrid
Employee Ownership Program
Work from home reimbursement
Health Savings Account
Customer Service Specialist I
Customer Service Specialist I

ISC (Integrated Specialty Coverages, LLC) • Carlsbad (CA)

On-site
Employee Ownership Program
Work from home reimbursement
401(k) Plan with company match
Complex Loss Specialist
Complex Loss Specialist

Integrated Specialty Coverages, LLC • San Diego (CA)

Hybrid
USD 87,000 - 109,000
Employee Ownership Program
Owner Referral Program
Work from home reimbursement
+6
Senior Detection & Response Lead (IR, AWS & Threat Hunting)
Senior Detection & Response Lead (IR, AWS & Threat Hunting)

Integrated Specialty Coverages, LLC • United States

Remote
USD 120,000 - 180,000
Product Manager -(P&C Business Product)
Product Manager -(P&C Business Product)

ISC (Integrated Specialty Coverages, LLC) • San Diego (CA)

Hybrid
USD 125,000 - 150,000
Health insurance
401(k) plan with match
Paid time off
+1
Senior Detection & Response Lead – Cloud & IR
Senior Detection & Response Lead – Cloud & IR

ISC (Integrated Specialty Coverages, LLC) • United States

Hybrid
USD 160,000 - 200,000
Health insurance
Dental and vision insurance
401(k) with company match
+1