Security Engineer, Detection & Response

Cybersecurity Jobs

Kansas City (MO)

Hybrid

USD 120,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Lockton is seeking a Security Engineer, Detection & Response to lead technical incident response and strengthen detections across endpoints, cloud, and identity. You will manage digital forensics, threat intelligence, and threat hunting, while mentoring the SOC team and coordinating with regional stakeholders.

The role requires hands-on experience with EDR, SIEM, and modern MITRE ATT&CK-based detection development, plus strong scripting in PowerShell, Python, and KQL.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience.
  • 5+ years of information security experience with hands-on incident response, forensics, threat intel, threat hunting, or red/purple team work.
  • Certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable.

Responsibilities

  • Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
  • Own incident documentation and ensure required communication and escalation processes are followed.
  • Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
  • Preserve data integrity and produce detailed forensic and incident reports.
  • Conduct root cause analysis for significant incidents and translate findings into improvements to detections, controls, and playbooks.
  • Maintain and improve incident response playbooks and runbooks.
  • Plan and run tabletop exercises with technical and executive audiences across regions.
  • Build and run Lockton’s CTI capability; collect, analyze, and prioritize intelligence from diverse sources.
  • Track threat actors, campaigns, and techniques relevant to Lockton and the insurance/financial services sector.
  • Deliver threat briefings to security leadership and the broader team; operationalize intelligence into detections and hunt hypotheses.
  • Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
  • Turn hunt outcomes into durable detections and remediation guidance.
  • Plan and execute red/purple team exercises under approved rules of engagement; emulate actor TTPs.

Skills

Incident response
Digital forensics
Threat intelligence
Threat hunting
Red team
Purple team
MITRE ATT&CK

Education

Bachelor's degree in Computer Science or Information Security
Equivalent experience
Relevant certifications (see list)

Tools

EDR
SIEM
CrowdStrike Falcon
Microsoft Sentinel
Microsoft Defender XDR
PowerShell
Python
KQL
Atomic Red Team
MITRE Caldera
Active Directory
Entra ID
Microsoft 365
Azure

Job description

The Security Engineer, Detection & Response will be an essential member of the Lockton Global Security Operations team, driving technical incident response from detection through recovery while also strengthening detections when there is no active incident. The role also leads cyber threat intelligence, threat hunting, and red and purple team activities, serving as the senior SOC technical escalation point.

Key Responsibilities
  • Incident Leadership: Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
  • Incident Documentation and Process Adherence: Own incident documentation and ensure required communication and escalation processes are followed.
  • Forensic Analysis: Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
  • Evidence Integrity and Reporting: Preserve data integrity and produce detailed forensic and incident reports.
  • Root Cause and Lessons Learned: Conduct root cause analysis for significant incidents and convert findings into concrete improvements to detections, controls, and playbooks.
  • Readiness: Maintain and improve incident response playbooks and runbooks.
  • Exercises and Coordination: Plan and run tabletop exercises with both technical and executive audiences across regions.
  • Cyber Threat Intelligence Program: Build and run Lockton’s CTI capability.
  • Intelligence Collection and Prioritization: Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
  • Threat Actor Tracking: Track threat actors, campaigns, and techniques relevant to Lockton, the insurance and financial services sector, and the regions where Lockton operates.
  • Threat Briefings: Maintain actor profiles and deliver regular threat briefings to security leadership and the broader team.
  • Operationalizing Intelligence: Convert intelligence into action by feeding indicators and behaviors into the detection stack, generating hunt hypotheses, informing vulnerability prioritization, and supporting security awareness content for active phishing, vishing, and social engineering campaigns.
  • Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
  • Detection Improvement from Hunt Outcomes: Convert hunt findings into durable detections.
  • Red Team and Purple Team Exercises: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement; emulate actor TTPs identified through CTI.
  • Detection Validation: Partner with the SOC and detection engineering to measure whether controls detect and respond as expected, mapping coverage and gaps to MITRE ATT&CK.
  • Remediation Workflow: Deliver prioritized remediation recommendations based on findings, then retest to confirm gaps are closed.
  • SOC Escalation: Serve as the senior technical escalation point for complex or high-severity alerts, including those involving Lockton’s managed detection and response partner.
  • Triage and Incident Determination: Guide triage decisions and determine when an alert escalates to an incident.
  • Reduce False Positives: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results to reduce false positives and close visibility gaps.
  • Mentoring and Knowledge Sharing: Improve SOC capability through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
  • Cross-Functional Collaboration: Coordinate with IT, Legal, and other departments to support a comprehensive response to security threats.
  • On-Call Coverage: Respond to security-related emergencies that may occur outside regular business hours and participate in the security team On-Call rotation.
Requirements
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum 5 years of information security experience with hands‑on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
  • Relevant certifications are highly desirable, such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP.
  • Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
  • Hands‑on experience with EDR and SIEM platforms.
  • Strong plus: experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR.
  • Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
  • Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development.
  • Experience with adversary emulation tooling (examples include Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments.
  • Excellent problem‑solving skills, including the ability to work under pressure.
  • Meticulous attention to detail to ensure accuracy and integrity of forensic investigations and incident reports.
  • Strong written and verbal communication skills, including the ability to produce intelligence products and incident reports for technical and executive audiences.
  • Ability to collaborate effectively in a team environment with cross‑functional stakeholders.
  • Willingness to stay current with attacker tradecraft, cloud security, and emerging threats, including AI‑enabled attacks, and continuously enhance skills.
Relevant Technologies
  • MITRE ATT&CK
  • EDR
  • SIEM
  • CrowdStrike Falcon
  • Microsoft Sentinel
  • Microsoft Defender XDR
  • PowerShell
  • Python
  • KQL
  • Atomic Red Team
  • MITRE Caldera
  • Active Directory
  • Entra ID
  • Microsoft 365
  • Azure
Role Details
  • Business Unit: Lockton Center Services
  • Schedule: Full‑time
  • Workplace: Hybrid
  • Location: Kansas City, MO
Minimum Experience

Minimum 5 years of experience in information security.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton Companies • Kansas City (MO)

On-site
USD 110,000 - 160,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Security Detection & Response Engineer
Senior Security Detection & Response Engineer

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000