Lead Security Detection & Response Engineer

Cybersecurity Jobs

Kansas City (MO)

Hybrid

USD 120,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lockton is seeking a Security Engineer, Detection & Response to lead technical incident response and strengthen detections across endpoints, cloud, and identity. You will manage digital forensics, threat intelligence, and threat hunting, while mentoring the SOC team and coordinating with regional stakeholders.

The role requires hands-on experience with EDR, SIEM, and modern MITRE ATT&CK-based detection development, plus strong scripting in PowerShell, Python, and KQL.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience.
  • 5+ years of information security experience with hands-on incident response, forensics, threat intel, threat hunting, or red/purple team work.
  • Certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable.

Responsibilities

  • Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
  • Own incident documentation and ensure required communication and escalation processes are followed.
  • Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
  • Preserve data integrity and produce detailed forensic and incident reports.
  • Conduct root cause analysis for significant incidents and translate findings into improvements to detections, controls, and playbooks.
  • Maintain and improve incident response playbooks and runbooks.
  • Plan and run tabletop exercises with technical and executive audiences across regions.
  • Build and run Lockton’s CTI capability; collect, analyze, and prioritize intelligence from diverse sources.
  • Track threat actors, campaigns, and techniques relevant to Lockton and the insurance/financial services sector.
  • Deliver threat briefings to security leadership and the broader team; operationalize intelligence into detections and hunt hypotheses.
  • Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
  • Turn hunt outcomes into durable detections and remediation guidance.
  • Plan and execute red/purple team exercises under approved rules of engagement; emulate actor TTPs.

Skills

Incident response
Digital forensics
Threat intelligence
Threat hunting
Red team
Purple team
MITRE ATT&CK

Education

Bachelor's degree in Computer Science or Information Security
Equivalent experience
Relevant certifications (see list)

Tools

EDR
SIEM
CrowdStrike Falcon
Microsoft Sentinel
Microsoft Defender XDR
PowerShell
Python
KQL
Atomic Red Team
MITRE Caldera
Active Directory
Entra ID
Microsoft 365
Azure

Job description

Lockton is seeking a Security Engineer, Detection & Response to lead technical incident response and strengthen detections across endpoints, cloud, and identity. You will manage digital forensics, threat intelligence, and threat hunting, while mentoring the SOC team and coordinating with regional stakeholders.

The role requires hands-on experience with EDR, SIEM, and modern MITRE ATT&CK-based detection development, plus strong scripting in PowerShell, Python, and KQL.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Security Engineer - Detection & Response
Lead Security Engineer - Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
Senior Security Detection & Response Engineer
Senior Security Detection & Response Engineer

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Lead Security Engineer - Detection & Response
Lead Security Engineer - Detection & Response

Lockton Companies • Kansas City (MO)

On-site
USD 110,000 - 160,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Cybersecurity Jobs • Kansas City (MO)

Hybrid
USD 120,000 - 190,000
Detection and Response Engineer
Detection and Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Lead Security Analyst, Incident Response & Threat Hunting
Lead Security Analyst, Incident Response & Threat Hunting

2K • Austin (TX)

On-site
USD 120,000 - 180,000
Detection & Response Engineering Lead
Detection & Response Engineering Lead

InfraTech Solutions LLC • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health, dental, and vision insurance
Paid time off and holidays
Parental leave
+2