Detection & Response Analyst

X4V Rapid7 LLC

Arlington (VA)

On-site

USD 85,000 - 115,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Rapid7 in Virginia is hiring a Detection & Response Analyst to identify, investigate, and respond to security threats across customer environments. You will work within a 24/7 MDR context to safeguard endpoints, identities, cloud, and networks.

Responsibilities include analyzing alerts, following MITRE ATT&CK frameworks, documenting findings, and coordinating with senior analysts to deliver timely remediation actions and insights for customers.

Qualifications

  • 2–4 years in cybersecurity operations, IT security, or related SOC role.
  • Foundational understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with Windows and Linux OS logs and processes.
  • Ability to produce clear investigation reports and timelines.
  • Familiarity with MITRE ATT&CK to classify events.

Responsibilities

  • Identify, investigate, and respond to security threats across endpoint, identity, cloud, and network telemetry.
  • Analyze alerts to identify attacker behavior and determine escalation paths.
  • Investigate standard incidents such as malware infections and unauthorized access attempts.
  • Collaborate with senior analysts and Incident Response Consultants on larger engagements.
  • Document findings with timelines and remediation steps aligned to MITRE ATT&CK.
  • Communicate findings to customers and refine detection logic with the team.
  • Maintain SLAs for alert triage and investigation quality.

Skills

SOC operations
MITRE ATT&CK
SIEM
EDR
NDR
Windows
Linux

Tools

SIEM
EDR
NDR

Job description

Detection & Response Analysts identify, investigate, and respond to security threats across diverse customer environments. They analyze security telemetry across endpoint, identity, cloud, and network vectors to protect global organizations from active cyber threats.

About the Team

Rapid7’s Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world.

About the Role

As a Detection & Response Analyst, your primary responsibility will be to identify, investigate, and respond to security threats across customer environments.

Specifically, your focus will be to:

  • Conduct investigations into suspicious and malicious activity across endpoint, identity, cloud, and network telemetry within customer environments.
  • Analyze security alerts and telemetry to identify attacker behavior and impact, following defined escalation paths for potential compromises.
  • Investigate standard security incidents, including common malware infections, unauthorized access attempts, and credential abuse.
  • Assist senior analysts and Incident Response Consultants during larger engagements to build exposure to complex threat scenarios.
  • Document investigation findings clearly in reports, detailing timelines of activity and recommended remediation steps aligned with the MITRE ATT&CK framework.
  • Collaborate with SOC Advisors to ensure investigation findings and recommended remediation actions are communicated effectively to customers.
  • Identify and report detection gaps or noisy alerts to help the team refine detection logic.
  • Maintain high operational standards by meeting service level objectives for alert triage and investigation quality.

The skills and qualities you'll bring include Bring 2–4 years of experience in cybersecurity operations, IT security, or a related technical role within a SOC or monitoring environment. Demonstrate a foundational understanding of attacker tactics, techniques, and procedures (TTPs), such as persistence, defense evasion, and lateral movement. Utilize security tools (SIEM, EDR, or NDR) to triage alerts, analyze telemetry, and assess potential compromise. Apply knowledge of Windows and Linux operating systems, including system logs and processes, to conduct thorough technical investigations. Leverage investigative frameworks like MITRE ATT&CK to categorize security events and document timelines of activity. Communicate technical findings clearly in written reports and verbal updates to ensure findings are actionable by conveying objectives and rationale to foster commitment. Drive efficient decision-making to resolve challenges and enable momentum during active incident triaging. Hold self accountable for driving outcomes and meeting operational service level objectives for alert triage. Build a network and work across boundaries with senior analysts and advisors to deliver sustainable security improvements. Demonstrate eager interest in understanding why changes occur and act as an active driver in evolving security environments. Express strong attention to detail and continuous curiosity to adapt and grow in a fast-paced environment. Embody our core values to foster a culture of excellence that drives meaningful impact and collective success. We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences.

About Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we’re continuing to push the envelope just like we’ ve been doing for the past 20 years. If you ’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Rapid7 is creating a more secure digital future for all by helping organizations strengthen their security programs in the face of accelerating digital transformation. Our portfolio of best-in-class solutions empowers security professionals to manage risk and eliminate threats across the entire threat landscape from apps to the cloud to traditional infrastructure to the dark web. We foster open source communities and cutting-edge research–using these insights to optimize our products and arm the global security community with the latest in attacker methodology. Trusted by more than 11,000 customers worldwide, our industry-leading solutions and services help businesses stay ahead of attackers, ahead of the competition, and future-ready for what’s next.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Detection & Response Analyst
Lead Detection & Response Analyst

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 140,000 - 210,000
24/7 Threat Detection & Response Analyst
24/7 Threat Detection & Response Analyst

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 85,000 - 115,000
Security Operations Analyst II
Security Operations Analyst II

Divvy Cloud Corp. • Northern (KY)

Hybrid
USD 82,000 - 110,000
Threat Hunter & Incident Response Analyst
Threat Hunter & Incident Response Analyst

Divvy Cloud Corp. • Northern (KY)

Hybrid
USD 82,000 - 110,000
Lead MDR Detection & Response Architect
Lead MDR Detection & Response Architect

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 140,000 - 210,000
Cyber Detection & Response Analyst
Cyber Detection & Response Analyst

Control Risks • San Francisco (CA)

Hybrid
USD 120,000 - 140,000
Medical Benefits
401(k) Retirement
Hybrid work
+1
Senior MDR Analyst
Senior MDR Analyst

Blackpoint Cyber • United States

On-site
USD 110,000 - 170,000
Health insurance
Vision insurance
Dental insurance
+2
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
MEDR Threat Engineer US work hours
MEDR Threat Engineer US work hours

Proficio Inc • United States

On-site
USD 120,000 - 180,000
Meals reimbursement
Gym access
Internet reimbursement
Cybersecurity Detection Engineer 3643279
Cybersecurity Detection Engineer 3643279

Axiom-Path • Charlotte (NC)

Hybrid
USD 110,000 - 150,000