Detection and Response Lead

Integrated Specialty Coverages, LLC

United States

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Integrated Specialty Coverages, LLC (ISC) Cybersecurity is seeking a senior, hands-on defender to build a Detection & Response function across our AWS and enterprise environments. Reporting to the CISO, you will partner with internal security engineering, MSSP, and MDR providers.

This role is highly technical, focused on detection engineering, advanced investigations, incident ownership, and maturing our capabilities.

Qualifications

  • Experience leading incident response for escalated alerts.
  • Proficiency with SIEM, EDR, WAF, and DLP tools.
  • Ability to communicate findings to technical and non-technical stakeholders.

Responsibilities

  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non-technical stakeholders.
  • Threat Hunting – Conduct hypothesis-driven and data-driven hunts to identify malicious or suspicious activity not surfaced by automated detections or MSSP/MDR workflows.
  • Detection Quality & Continuous Improvement – Review MSSP/MDR escalations for quality, signal-to-noise, and fidelity; drive improvements through feedback loops.

Skills

Incident response
Threat hunting
Forensic analysis
SIEM
EDR

Tools

SIEM
EDR
Proxy
WAF
DLP

Job description

Integrated Specialty Coverages, LLC (ISC) is a growth stage technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market.

Backed by one of the leading private equity firms, Onex Partners, and led by a forward-thinking management team, ISC is combining the worlds of insurance and technology to create an Insurtech powerhouse. As a leading online distributor of insurance products for a range of industries and "Main Street USA", we are looking for the right people to help us in our mission of achieving exponential growth. We strive to be the number one place to go for brokers and agents to source insurance. To accomplish this, we’re building a digitally focused team that deeply understands the intersection between user experience, data, and AI/ML to optimize the way we engage with our customers and partners.

Job Summary

ISC Cybersecurity is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across our enterprise and AWS environments. The role will report to the CISO and will partner with internal security engineering, as well as with our managed security services provider (MSSP) and managed detection and response (MDR) provider. The Detection & Response Lead focuses on detection engineering, advanced investigation, incident ownership, threat hunting, and maturing our detection and response capabilities. The role serves as the escalation point for security events, ensuring timely containment, high‑quality analysis, and actionable recommendations for improvement. This position is operational and technically deep, driving defensive execution across our AWS and enterprise environments.

Position Responsibilities

  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency‑only on‑call availability is required for high‑severity incidents.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and DLP technologies.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Threat Hunting
    • Conduct hypothesis‑driven and data‑driven hunts to identify malicious or suspicious activity not already surfaced by automated detections or MSSP/MDR workflows.
    • Develop internal hunting methodologies rooted in observed attacker behavior, business‑specific risks, and historical incident patterns.
    • Document and socialize hunt outcomes, including new detection opportunities and defensive insights.
  • Detection Quality & Continuous Improvement
    • Review MSSP/MDR escalations for quality, signal‑to‑noise ratio, and fidelity; drive improvements through structured feedback loops.
    • Identify gaps in log coverage, detection logic, or monitoring effectiveness and coordinate with engineering partners to close them.
    • Drive Mean‑Time‑To‑Detect and Mean‑Time‑To‑Contain metrics as well as detection coverage metrics.
  • Escalation Ownership & Internal
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and Response Lead
Detection and Response Lead

ISC (Integrated Specialty Coverages, LLC) • United States

Hybrid
USD 160,000 - 200,000
Health insurance
Dental and vision insurance
401(k) with company match
+1
Senior Detection & Response Lead – Cloud & IR
Senior Detection & Response Lead – Cloud & IR

ISC (Integrated Specialty Coverages, LLC) • United States

Hybrid
USD 160,000 - 200,000
Health insurance
Dental and vision insurance
401(k) with company match
+1
Detection & Response Lead - Cloud & IR
Detection & Response Lead - Cloud & IR

Isccareers • United States

On-site
USD 160,000 - 200,000
Employee Ownership Program
Professional development opportunities
Work from home reimbursement forremote
+3
Senior Detection & Response Lead (IR, AWS & Threat Hunting)
Senior Detection & Response Lead (IR, AWS & Threat Hunting)

Integrated Specialty Coverages, LLC • United States

Remote
USD 120,000 - 180,000
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Cyber Security Defense Manager - Incident Response
Cyber Security Defense Manager - Incident Response

Fusion HCR • Las Vegas (NV)

Hybrid
USD 180,000 - 240,000