Security Engineer, Detection & Response

Lockton Companies

Kansas City (MO)

On-site

USD 110,000 - 160,000

Full time

11 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Lockton Companies seeks a Security Engineer - Detection & Response in Kansas City to lead security incidents from detection to recovery and to prevent future incidents through threat intelligence and hunting. The role also acts as the senior escalation point for the SOC and collaborates with cross-functional teams across regions.

The ideal candidate will be hands-on, with experience in MITRE ATT&CK, red/purple team exercises, and cloud security, and will help strengthen detections and runbooks

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum 5 years of experience in information security with hands-on incident response, forensics, threat intelligence, hunting, or red team/pen testing.
  • Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are desirable.
  • Strong knowledge of MITRE ATT&CK and applying it to threat hunting and detection.
  • Hands-on experience with EDR and SIEM platforms (CrowdStrike, MS Defender XDR, MS Sentinel).
  • Experience with scripting (PowerShell, Python, KQL) for automation and detection development.

Responsibilities

  • Lead technical response to security incidents, coordinating with IT and business stakeholders.
  • Perform digital forensics across endpoints, identity, email, and cloud environments.
  • Conduct root cause analysis and update detections, controls, and playbooks.
  • Plan and run tabletop exercises with technical and executive teams.

Skills

Incident response
Digital forensics
Threat intelligence
Threat hunting
Red team
Cloud security
Scripting
MITRE ATT&CK
EDR
SIEM
PowerShell
Python
KQL

Education

Bachelor's degree in CS/InfoSec

Tools

CrowdStrike Falcon
Microsoft Sentinel
Microsoft Defender XDR
SIEM platforms

Job description

Kansas City, Missouri, United States of America

At Lockton, we’re passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We’re active listeners working to ensure understanding and problem solvers developing innovative solutions. If you can see yourself delivering excellent service to clients, giving back to our communities and being a part of our caring culture, you belong here.

The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active incident, their time goes toward preventing the next one: running cyber threat intelligence (CTI), executing red team and purple team exercises, hunting for threats in our environment, and strengthening our detections. The role also serves as the senior technical escalation point for the Security Operations Center (SOC). The ideal candidate is a hands‑on practitioner who is equally comfortable leading a live incident bridge, tracking the threat actors most likely to target Lockton, and emulating those actors to prove our defenses work.

Key Responsibilities:
Incident Response
  • Incident Leadership: Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover. Own incident documentation and ensure communication and escalation processes are followed.
  • Forensic Analysis: Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence. Preserve the integrity of data and produce detailed forensic and incident reports.
  • Root Cause and Lessons Learned: Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks.
  • Readiness: Maintain and improve incident response playbooks and runbooks. Plan and run tabletop exercises with technical and executive audiences across regions.
Cyber Threat Intelligence
  • Intelligence Program: Build and run Lockton's CTI capability. Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
  • Threat Actor Tracking: Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate. Maintain actor profiles and produce regular threat briefings for security leadership and the broader team.
  • Operationalizing Intelligence: Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns.
  • Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry. Convert hunt findings into durable detections.
Red Team and Purple Team Exercises
  • Adversary Emulation: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement. Emulate the TTPs of the actors identified through CTI.
  • Detection Validation: Work side by side with the SOC and detection engineering to measure whether our controls detect and respond as expected. Map coverage and gaps to MITRE ATT&CK.
  • Remediation: Deliver clear findings with prioritized remediation, then retest to confirm gaps are closed.
SOC Escalation
  • Escalation Point: Serve as the senior technical escalation for the SOC, including our managed detection and response partner, on complex or high‑severity alerts. Guide triage decisions and make the call on when an alert becomes an incident.
  • Detection Improvement: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results. Reduce false positives and close visibility gaps.
  • Mentoring: Raise the technical bar of the SOC through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
General
  • Collaboration: Work closely with IT, Legal, and other departments to ensure a coordinated and comprehensive response to security threats.
  • Must be able to respond to security-related emergencies that may arise outside of regular business hours.
  • Participate in security team On-Call rotation.
Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 5 years of experience in information security, with hands‑on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
  • Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable.
  • Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
  • Hands‑on experience with EDR and SIEM platforms. Experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR is a strong plus.
  • Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
  • Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development.
  • Experience with adversary emulation tooling (for example, Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments.
  • Excellent problem‑solving skills and the ability to work under pressure.
  • Meticulous attention to detail to ensure the accuracy and integrity of forensic investigations and incident reports.
  • Strong written and verbal communication skills, with the ability to produce intelligence products and incident reports for both technical and executive audiences.
  • Ability to work effectively in a team environment and collaborate with cross‑functional teams.
  • Willingness to stay current with attacker tradecraft, cloud security, and emerging threats such as AI‑enabled attacks, and continuously enhance skills.
Equal Opportunity Statement

Lockton Companies is proud to provide everyone anequal opportunity to grow and advance. We are committed to an inclusive culture and environment where our people, clients and communities are treated with respect and dignity.

At Lockton, supporting diversity, equity and inclusion is ingrained in our values, and we believe that we are at our best when we fully embrace everyone. We strive to cultivate a caring culture that learnsfrom, celebrates and thrives because of ourbreadth of differences. As such, we recognize that recruiting, developing and retaining people with diverse backgrounds and experiences is vital and enabling our people to thrive personally and professionally is critical to our long‑term success.

About Lockton

Lockton is the largest privately held independent insurance brokerage in the world. Since 1966, our independence has allowed us to serve our clients, take care of our people and give back to our communities. As such, our 13,100+ Associates doing business in over 155 countries are empowered to do what’s right every day.

At Lockton, we believe in the power of all people. You belong at Lockton.

How We Will Support You

At Lockton, we empower you to be true to yourself in all that you do. Your success is our success, and we provide opportunities to help you grow and create a rewarding career path, however you envision it.

We are ready to meet you where you are today, and as your needs change over time. In addition to industry-leading health insurance, we offer additional options to support your overall health and wellbeing.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • Kansas City (MO)

On-site
USD 120,000 - 180,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Lockton • North Kansas City (MO)

On-site
USD 110,000 - 160,000
SVP, Senior Cyber Claims Advocate
SVP, Senior Cyber Claims Advocate

Lockton Companies • New York (NY)

On-site
USD 130,000 - 190,000
Rolex after 10 years
International Client Executive
International Client Executive

Lockton Companies • Chicago (IL)

On-site
USD 130,000 - 200,000
Lead Analytics Engineer
Lead Analytics Engineer

Lockton Companies • Kansas City (MO), Northern (KY)

Hybrid
USD 120,000 - 180,000
Health insurance
Wellbeing program
Project Coordinator
Project Coordinator

Lockton Companies • Kansas City (MO)

On-site
USD 42,000 - 62,000
Account Manager - Cyber
Account Manager - Cyber

Lockton Companies • Minneapolis (MN)

On-site
USD 55,000 - 90,000
12-week paid parental leave
Community involvement
Wellness events
+1
Account Manager
Account Manager

Lockton Companies • Kansas City (MO), Northern (KY)

Hybrid
USD 65,000 - 95,000
12 weeks parental leave
Rolex 10-year anniversary reward
Wellness events
+1
Claims Counsel
Claims Counsel

Lockton Companies • Kansas City (MO)

On-site
USD 120,000 - 180,000
Paid training and professional dev el
12-week parental leave
Community involvement
+1
Risk Manager
Risk Manager

Lockton Companies • Denver (CO)

On-site
USD 120,000 - 170,000
Health insurance