Senior Cloud IR Lead: Detection & Response

Idme

McLean (VA)

On-site

USD 161,000 - 227,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) with company match
Unlimited PTO
Wellbeing and childcare discounts

Job summary

ID.me seeks a Staff Cloud Detection & Response Engineer to lead threat detection and incident response across cloud environments. You will act as a defender-first authority, guiding security decisions and advising engineering on secure-by-design practices.

You’ll work with AWS and/or GCP, Kubernetes workloads, and CI/CD surfaces to detect, investigate, and eliminate threats. You bring deep hands-on experience in cloud security, incident response, and forensics, with a focus on detection depth,

Qualifications

  • Eight+ years in information security with hands-on IR, threat hunting, and forensics.
  • Three+ years leading IR in cloud environments (AWS and/or GCP).
  • Proficient in Python/Go/bash for detection tooling.
  • Deep knowledge of IAM least-privilege design and risk controls.
  • Hands-on Kubernetes (EKS/GKE) and container runtime security experience.
  • Experience with immutable cloud forensics workflows and automated evidence capture.
  • Ability to advise on secure-by-design architecture and CI/CD security.

Responsibilities

  • Lead high-severity cloud security incidents with technical authority from detection to recovery.
  • Engineer immutable cloud forensics pipelines to preserve evidence during autoscaling.
  • Advise on secure cloud architecture, IAM, network perimeters, and workload identity.
  • Drive visibility into CI/CD pipelines for security signals without owning pipelines.
  • Conduct deep Kubernetes runtime security investigations across clusters and pods.
  • Perform proactive threat hunting using cloud-native telemetry to detect IOCs and TTPs.
  • Own incident command during major cloud incidents and communicate with leadership.
  • Lead root-cause analyses and convert findings into architectural improvements.
  • Mentor SOC/IR analysts to raise overall cloud threat detection fluency.
  • Stay current on cloud-native security services and advise adoption into playbooks.

Skills

Incident response
Threat hunting
Forensic analysis
Python
Go
Bash
IAM least-privilege design
Kubernetes security
Immutable forensics workflows
CI/CD security
SIEM/EDR/DLP/IDS
Incident command

Tools

Chronicle
Splunk
Terraform
Kubernetes security tooling

Job description

ID.me seeks a Staff Cloud Detection & Response Engineer to lead threat detection and incident response across cloud environments. You will act as a defender-first authority, guiding security decisions and advising engineering on secure-by-design practices.

You’ll work with AWS and/or GCP, Kubernetes workloads, and CI/CD surfaces to detect, investigate, and eliminate threats. You bring deep hands-on experience in cloud security, incident response, and forensics, with a focus on detection depth,

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Cloud Detection & Response Engineer
Staff Cloud Detection & Response Engineer

Aurora • Mountain View (CA)

Hybrid
USD 189,000 - 303,000
Hybrid work model
Bonus and equity
Benefits package
Senior SOC Lead: Cloud-Native Incident Response
Senior SOC Lead: Cloud-Native Incident Response

ID.me • McLean (VA)

On-site
USD 140,000 - 190,000
Staff Cloud Detection & Response Security Engineer
Staff Cloud Detection & Response Security Engineer

Australian Competition and Consumer Commission • Pittsburgh

Hybrid
USD 171,000 - 273,000
Senior Cloud Detection & Response Security Engineer
Senior Cloud Detection & Response Security Engineer

Pittsburgh Robotics Network • Pittsburgh

Hybrid
USD 171,000 - 273,000
Annual bonus
Equity compensation
Hybrid work environment
Senior Cloud Detection & Response Security Engineer
Senior Cloud Detection & Response Security Engineer

Aurora • Seattle (WA)

Hybrid
USD 189,000 - 303,000
Annual bonus
Equity compensation
Benefits
Remote IR Lead: Cloud Security & Incident Response
Remote IR Lead: Cloud Security & Incident Response

FICO • United States

Remote
USD 137,000 - 215,000
Remote-work option
Lead Cloud Detection & Response
Lead Cloud Detection & Response

Jobicy • United States

Remote
USD 180,000 - 240,000
Competitive compensation
Career growth and learning
Flexibility and ownership
+3
Senior Cloud IR & Threat Hunting Lead
Senior Cloud IR & Threat Hunting Lead

CoreWeave • Livingston (NJ)

On-site
USD 139,000 - 204,000
Medical insurance
Life Insurance
Disability insurance
+4
Remote Threat Detection & Response Engineer — IR & SOC
Remote Threat Detection & Response Engineer — IR & SOC

Whatnot • United States

Remote
USD 120,000 - 170,000
Health Insurance
401(k) with employer match
Work From Home Support
+2
Staff Cloud Detection & Response Engineer
Staff Cloud Detection & Response Engineer

Idme • McLean (VA)

On-site
USD 161,000 - 227,000
Medical, dental, vision
401(k) with company match
Unlimited PTO
+1