Alert, Detection, and Response Engineer, Associate
Ai Security
Cloud Threat Detection
Crowdstrike
Detection And Response
Detection Engineering
Endpoint Detection & Response
Endpoint Security
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsoft Defender For Endpoint
Microsoft Sentinel
Mitre Att&ck
Security
Security Analytics
Security Automation
Security Detection Engineering
Security Investigations
Security Operations
Security Threat Detection
Sentinelone
Splunk
Job Description
Blackstone is hiring an Alert, Detection, and Response Associate for onsite incident response and detection engineering work in Miami, FL.
Responsibilities
- Manage an incident queue from intake through investigation, containment, and closure across domains including email, endpoint, identity, network, and cloud
- Own Tier 1 escalations by taking over complex investigations and bringing in additional responders as scope expands
- Investigate security activity in the firm’s SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry
- Perform endpoint investigation and live response in the firm’s EDR, including process lineage review, persistence assessment, and artifact collection
- Investigate email threats end to end, covering phishing, business email compromise, and malicious attachments and links
- Use header and message trace analysis to determine who was targeted and drive remediation across impacted mailboxes
- Investigate cloud and identity compromise, including credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass
- Scope suspected third-party and SaaS provider compromises by coordinating with the provider’s incident response team to confirm containment and affected Blackstone data
- Independently hunt for provider indicators across endpoint, email, network, and cloud telemetry, coordinating findings and remediation with legal and compliance, vendor risk, and business owners
- Serve as a core incident response team member: scope intrusions, drive containment and eradication, brief stakeholders, and escalate per the severity model
- Turn investigation outcomes into detections by authoring and tuning detection logic, validating against historical and live data, moving through review into production, and confirming acceptable signal quality
- Collaborate with agentic AI investigation tooling during first-pass triage and enrichment by evaluating outputs, escalating incorrect conclusions, and feeding back corrections to improve coverage
- Help expand detection and response coverage as the firm increases use of AI across a fast-moving attack surface
- Convert repeatable investigation and response work into durable automation to reduce repetitive steps and reduce false positives
- Mentor Tier 1 analysts on investigation technique via case reviews and hands-on coaching
- Document investigations and incidents with evidence handling and chain of custody practices, communicating clearly to technical teams and senior stakeholders
- Contribute to threat hunts and purple team exercises, using red team activity and threat intelligence to identify gaps
- Participate in incident response and SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents
Requirements
- 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
- Proven ability to run end-to-end security investigations from alert through root cause, containment, and resolution in a SOC or incident response environment
- Hands-on SIEM experience, including writing and troubleshooting queries; experience with a major enterprise SIEM and native query language (Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)
- Hands-on EDR experience performing endpoint investigation and containment using a leading EDR platform (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint)
- Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, and SSO, plus identity providers such as Okta or Microsoft Entra ID
- Practical understanding of attacker behavior across the intrusion lifecycle: phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
- Familiarity with security technologies used in investigations, including email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data
- Working knowledge of MITRE ATT&CK and experience mapping observed activity to techniques
- Experience scripting in Python and/or PowerShell for enrichment, parsing, and automating repetitive analysis
- Hands-on experience using AI tooling in real work, with detailed examples and the judgment to identify untrustworthy outputs
- Clear technical writing skills for explaining incidents and impact to both engineers and non-technical stakeholders
- Ability to self-organize, prioritize under time pressure, and maintain accuracy during live incidents
Technologies
- SIEM: Splunk/SPL, Microsoft Sentinel/KQL, Elastic
- EDR: CrowdStrike, SentinelOne, Microsoft Defender for Endpoint
- Identity: Okta, Microsoft Entra ID
- MITRE ATT&CK, Python, PowerShell
- AI tools and agentic AI investigation tooling
- Email security, DLP, MFA bypass
- SIEM correlation searches
Benefits
- Comprehensive health benefits, including medical, dental, vision, and FSA
- Paid time off
- Life insurance
- 401(k) plan
- Discretionary bonuses
- Certain employees may be eligible for equity and other incentive compensation at Blackstone’s sole discretion
Preferred Qualifications
- Detection engineering experience such as authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and measuring whether detections work
- Detection-as-code experience, including Git-based workflows, peer review, and CI validation of detection content
- SOAR automation experience with tools such as Torq, Splunk SOAR, or Tines
- Digital forensics capability in memory, disk, or network analysis, or hands-on malware triage and sandboxing
- Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
- Threat hunting experience, especially hypothesis-driven hunts against endpoint or cloud telemetry
- Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and how its logging, identity, and access services support investigations
- Experience in financial services or another heavily regulated, globally distributed environment
- At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
- B.S. in Computer Science, Cybersecurity, Information Systems, or a related technical field
Compensation & Location
- Location: Miami, FL (onsite)
- Expected annual base salary range: $110,000 - $170,000
- Minimum experience: 2 years