CybersecurityJobs.io
← Back to all jobs

Job Description

Blackstone is hiring an Alert, Detection, and Response Associate for onsite incident response and detection engineering work in Miami, FL.

Responsibilities

  • Manage an incident queue from intake through investigation, containment, and closure across domains including email, endpoint, identity, network, and cloud
  • Own Tier 1 escalations by taking over complex investigations and bringing in additional responders as scope expands
  • Investigate security activity in the firm’s SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry
  • Perform endpoint investigation and live response in the firm’s EDR, including process lineage review, persistence assessment, and artifact collection
  • Investigate email threats end to end, covering phishing, business email compromise, and malicious attachments and links
  • Use header and message trace analysis to determine who was targeted and drive remediation across impacted mailboxes
  • Investigate cloud and identity compromise, including credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass
  • Scope suspected third-party and SaaS provider compromises by coordinating with the provider’s incident response team to confirm containment and affected Blackstone data
  • Independently hunt for provider indicators across endpoint, email, network, and cloud telemetry, coordinating findings and remediation with legal and compliance, vendor risk, and business owners
  • Serve as a core incident response team member: scope intrusions, drive containment and eradication, brief stakeholders, and escalate per the severity model
  • Turn investigation outcomes into detections by authoring and tuning detection logic, validating against historical and live data, moving through review into production, and confirming acceptable signal quality
  • Collaborate with agentic AI investigation tooling during first-pass triage and enrichment by evaluating outputs, escalating incorrect conclusions, and feeding back corrections to improve coverage
  • Help expand detection and response coverage as the firm increases use of AI across a fast-moving attack surface
  • Convert repeatable investigation and response work into durable automation to reduce repetitive steps and reduce false positives
  • Mentor Tier 1 analysts on investigation technique via case reviews and hands-on coaching
  • Document investigations and incidents with evidence handling and chain of custody practices, communicating clearly to technical teams and senior stakeholders
  • Contribute to threat hunts and purple team exercises, using red team activity and threat intelligence to identify gaps
  • Participate in incident response and SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents

Requirements

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
  • Proven ability to run end-to-end security investigations from alert through root cause, containment, and resolution in a SOC or incident response environment
  • Hands-on SIEM experience, including writing and troubleshooting queries; experience with a major enterprise SIEM and native query language (Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)
  • Hands-on EDR experience performing endpoint investigation and containment using a leading EDR platform (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint)
  • Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, and SSO, plus identity providers such as Okta or Microsoft Entra ID
  • Practical understanding of attacker behavior across the intrusion lifecycle: phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
  • Familiarity with security technologies used in investigations, including email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data
  • Working knowledge of MITRE ATT&CK and experience mapping observed activity to techniques
  • Experience scripting in Python and/or PowerShell for enrichment, parsing, and automating repetitive analysis
  • Hands-on experience using AI tooling in real work, with detailed examples and the judgment to identify untrustworthy outputs
  • Clear technical writing skills for explaining incidents and impact to both engineers and non-technical stakeholders
  • Ability to self-organize, prioritize under time pressure, and maintain accuracy during live incidents

Technologies

  • SIEM: Splunk/SPL, Microsoft Sentinel/KQL, Elastic
  • EDR: CrowdStrike, SentinelOne, Microsoft Defender for Endpoint
  • Identity: Okta, Microsoft Entra ID
  • MITRE ATT&CK, Python, PowerShell
  • AI tools and agentic AI investigation tooling
  • Email security, DLP, MFA bypass
  • SIEM correlation searches

Benefits

  • Comprehensive health benefits, including medical, dental, vision, and FSA
  • Paid time off
  • Life insurance
  • 401(k) plan
  • Discretionary bonuses
  • Certain employees may be eligible for equity and other incentive compensation at Blackstone’s sole discretion

Preferred Qualifications

  • Detection engineering experience such as authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and measuring whether detections work
  • Detection-as-code experience, including Git-based workflows, peer review, and CI validation of detection content
  • SOAR automation experience with tools such as Torq, Splunk SOAR, or Tines
  • Digital forensics capability in memory, disk, or network analysis, or hands-on malware triage and sandboxing
  • Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
  • Threat hunting experience, especially hypothesis-driven hunts against endpoint or cloud telemetry
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and how its logging, identity, and access services support investigations
  • Experience in financial services or another heavily regulated, globally distributed environment
  • At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
  • B.S. in Computer Science, Cybersecurity, Information Systems, or a related technical field

Compensation & Location

  • Location: Miami, FL (onsite)
  • Expected annual base salary range: $110,000 - $170,000
  • Minimum experience: 2 years

Similar Jobs