Incident Response Engineer, Tier 2 — Detection & IR

Blackstone

Miami (FL)

Hybrid

USD 110,000 - 170,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Blackstone seeks an Alert, Detection, and Response Associate to serve as a Tier 2 incident responder. You will detect, investigate, and respond to security incidents across email, endpoint, identity, network, and cloud, and help turn findings into improved detections and playbooks.

You will mentor Tier 1 analysts, write detections, and work with AI investigation tooling to accelerate triage while maintaining rigorous evidence handling and coordination with stakeholders.

Qualifications

  • 2+ years hands‑on experience in security operations or incident response.

Responsibilities

  • Manage an incident queue from intake to closure across email, endpoint, identity, network and cloud.
  • Handle escalations from Tier 1 analysts for complex investigations.
  • Investigate in the firm''s SIEM; write and refine searches for telemetry.
  • Conduct endpoint investigation, host containment, and live response in the EDR platform.
  • Investigate email threats end to end, including phishing and BEC, using header analysis.
  • Investigate cloud/identity compromise, including IAM and MFA bypass scenarios.
  • Coordinate with legal, compliance, vendor risk and business owners for remediation.
  • Author and tune detections from findings; validate against historical data.
  • Work with AI investigation tooling for triage and enrichment; improve coverage.
  • Mentor Tier 1 analysts on investigation techniques and case reviews.
  • Document investigations to a standard that supports chain of custody.

Skills

Incident response
SIEM querying
EDR containment
Cloud/Identity
Python/PowerShell
AI tooling in IR
MITRE ATT&CK
Technical writing
Threat hunting
Cross-team collaboration

Education

BS in CS/Cybersecurity/IS

Tools

Splunk/SPL
Microsoft Sentinel/KQL
Elastic
CrowdStrike
SentinelOne
Defender for Endpoint

Job description

Blackstone seeks an Alert, Detection, and Response Associate to serve as a Tier 2 incident responder. You will detect, investigate, and respond to security incidents across email, endpoint, identity, network, and cloud, and help turn findings into improved detections and playbooks.

You will mentor Tier 1 analysts, write detections, and work with AI investigation tooling to accelerate triage while maintaining rigorous evidence handling and coordination with stakeholders.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection & Incident Response Associate
Threat Detection & Incident Response Associate

The Blackstone Group L.P. • Miami (FL)

On-site
USD 110,000 - 170,000
Medical benefits
Dental benefits
Vision benefits
+2
Incident Response & Detection Engineer — Onsite Miami
Incident Response & Detection Engineer — Onsite Miami

Cybersecurity Jobs • Miami (FL)

On-site
USD 110,000 - 170,000
Comprehensive health benefits
Paid time off
Life insurance
+3
Senior Tier 2 Cybersecurity Engineer - Incident Response
Senior Tier 2 Cybersecurity Engineer - Incident Response

On Call Computer Solutions, LLC • Tallahassee (FL)

On-site
USD 110,000 - 150,000
Health insurance
Life insurance
128 Hours PTO
+1
Incident Responder - Tier 2
Incident Responder - Tier 2

Evans & Chambers • Fort Meade (MD)

On-site
USD 115,000 - 147,000
Senior IT Security Incident Responder – Tier 2, Remote
Senior IT Security Incident Responder – Tier 2, Remote

Gravity IT Resources • Salem (OR)

Remote
USD 109,000 - 116,000
Cybersecurity Analyst II - Incident Response
Cybersecurity Analyst II - Incident Response

Revolutional • Martinsburg (WV)

On-site
USD 90,000 - 130,000
Medical insurance
Dental and vision insurance
401(k) company matching
+1
Threat Detection & Response Engineer: Incident Leader
Threat Detection & Response Engineer: Incident Leader

Whatnot • San Francisco (CA)

Hybrid
USD 175,000 - 260,000
Health Insurance (Medical, Dental, Vis
Work From Home Support
Home office setup allowance
+5
Senior SOC Analyst — AI-Driven Incident Response
Senior SOC Analyst — AI-Driven Incident Response

BeyondTrust • United States

On-site
USD 90,000 - 130,000
Remote Threat Detection & Response Engineer — IR & SOC
Remote Threat Detection & Response Engineer — IR & SOC

Whatnot • United States

Remote
USD 120,000 - 170,000
Health Insurance
401(k) with employer match
Work From Home Support
+2
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1