Lead Detection & Response Analyst

X4V Rapid7 LLC

Arlington (VA)

On-site

USD 140,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Rapid7 is seeking a Lead Detection & Response Analyst to drive technical excellence across our global SOC operations. You will lead response to high-impact threats, refine investigative workflows, and mentor the SOC team to advance detection capabilities.

You will partner with Detection Engineering and Platform teams to close visibility gaps, architect advanced workflows, and produce actionable intelligence for executives and customers while shaping platform direction.

Qualifications

  • 8+ years in cybersecurity operations, IR, or forensics in a high-maturity SOC/MDR environment.
  • Expert-level mastery of MITRE ATT&CK to build detection strategies.
  • Deep forensic expertise across Endpoint, Cloud, Identity, and Network domains.

Responsibilities

  • Lead response to high-impact, novel or complex threats.
  • Develop new investigative methodologies for emerging attack vectors.
  • Serve as primary technical escalation point for global SOC operations.

Skills

MITRE ATT&CK
Incident response
Digital forensics
Technical leadership
GCFA
GCTI
GREM
OSCP

Job description

Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world. Our SOC operates with an impact-driven mindset focused on identifying meaningful threats and delivering actionable outcomes for our customers.

About the Team

Rapid7's Managed Detection and Response (MDR) Security Operations Center delivers 24/7 continuous monitoring, threat hunting, and sophisticated incident response for global organizations. The team focuses on stopping adversary activity, elevating technical standards, and driving actionable security outcomes.

About the Role

As a Lead Detection & Response Analyst, your primary responsibility will be to serve as a high-level technical lead and driver of technical excellence across global SOC operations.

Key Responsibilities
  • Lead the response to high-impact, novel, or highly complex security threats.
  • Develop new investigative methodologies for emerging attack vectors where established methods do not exist.
  • Serve as the primary technical escalation point for the global SOC, directing containment and remediation strategies.
  • Identify systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities.
  • Architect and refine investigative workflows to leverage advanced tooling and automation.
  • Author advanced technical intelligence reports and advisories for executive leadership and customers.
  • Mentor and grow the technical bench strength of the SOC through high-level coaching and technical workshops.
  • Influence product and platform direction by providing expert feedback to engineering teams.
Required Skills & Qualifications
  • 8+ years of cybersecurity operations, Incident Response, or Digital Forensics experience in a high-maturity SOC/MDR environment.
  • Demonstrate expert-level mastery of the MITRE ATT&CK framework to build behavioral detection strategies.
  • Apply deep forensic expertise across Endpoint, Cloud, Identity, and Network domains, including log analysis and malware triage.
  • Drive complex technical projects from conception to completion across global teams.
  • Direct containment strategies efficiently during high-stakes customer compromises to maintain momentum and resolve challenges.
  • Articulate complex attacker TTPs and long-term security strategies clearly to technical engineers and C-level executives.
  • Build cross-functional alignment with Detection Engineering, Product, and Platform teams to deliver sustainable defense capabilities.
  • Mentor and coach analysts across the global SOC, setting clear expectations for investigative quality.
  • Adapt to evolving adversary techniques by driving forward-looking investigative practices.
  • Hold advanced industry certifications such as GCFA, GCTI, GREM, or OSCP.
About Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we've been doing for the past 20 years. If you're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Rapid7 is creating a more secure digital future for all by helping organizations strengthen their security programs in the face of accelerating digital transformation. Our portfolio of best-in-class solutions empowers security professionals to manage risk and eliminate threats across the entire threat landscape from apps to the cloud to traditional infrastructure to the dark web. We foster open source communities and cutting-edge research-using these insights to optimize our products and arm the global security community with the latest in attacker methodology. Trusted by more than 11,000 customers worldwide, our industry-leading solutions and services help businesses stay ahead of attackers, ahead of the competition, and future-ready for what's next.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection & Response Analyst
Detection & Response Analyst

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 85,000 - 115,000
Lead MDR Detection & Response Architect
Lead MDR Detection & Response Architect

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 140,000 - 210,000
Security Operations Analyst II
Security Operations Analyst II

Divvy Cloud Corp. • Northern (KY)

Hybrid
USD 82,000 - 110,000
24/7 Threat Detection & Response Analyst
24/7 Threat Detection & Response Analyst

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 85,000 - 115,000
Senior MDR Analyst
Senior MDR Analyst

Blackpoint Cyber • United States

On-site
USD 110,000 - 170,000
Health insurance
Vision insurance
Dental insurance
+2
Threat Hunter & Incident Response Analyst
Threat Hunter & Incident Response Analyst

Divvy Cloud Corp. • Northern (KY)

Hybrid
USD 82,000 - 110,000
Senior Engineering Manager, Rapid Response
Senior Engineering Manager, Rapid Response

AI Chopping Block • Northern (KY)

Hybrid
USD 170,000 - 250,000
MEDR Threat Engineer US work hours
MEDR Threat Engineer US work hours

Proficio Inc • United States

On-site
USD 120,000 - 180,000
Meals reimbursement
Gym access
Internet reimbursement
Senior Incident Responder
Senior Incident Responder

TENEX.AI • United States

On-site
USD 120,000 - 180,000
Senior Engineering Manager, Rapid Response
Senior Engineering Manager, Rapid Response

NightDragon Acquisition Corp. • Washington

On-site
USD 180,000 - 240,000