Security Engineer, Detection & Response
Job Description
The Security Engineer, Detection & Response will be an essential member of the Lockton Global Security Operations team, driving technical incident response from detection through recovery while also strengthening detections when there is no active incident. The role also leads cyber threat intelligence, threat hunting, and red and purple team activities, serving as the senior SOC technical escalation point.
Key Responsibilities
- Incident Leadership: Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
- Incident Documentation and Process Adherence: Own incident documentation and ensure required communication and escalation processes are followed.
- Forensic Analysis: Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
- Evidence Integrity and Reporting: Preserve data integrity and produce detailed forensic and incident reports.
- Root Cause and Lessons Learned: Conduct root cause analysis for significant incidents and convert findings into concrete improvements to detections, controls, and playbooks.
- Readiness: Maintain and improve incident response playbooks and runbooks.
- Exercises and Coordination: Plan and run tabletop exercises with both technical and executive audiences across regions.
- Cyber Threat Intelligence Program: Build and run Lockton’s CTI capability.
- Intelligence Collection and Prioritization: Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
- Threat Actor Tracking: Track threat actors, campaigns, and techniques relevant to Lockton, the insurance and financial services sector, and the regions where Lockton operates.
- Threat Briefings: Maintain actor profiles and deliver regular threat briefings to security leadership and the broader team.
- Operationalizing Intelligence: Convert intelligence into action by feeding indicators and behaviors into the detection stack, generating hunt hypotheses, informing vulnerability prioritization, and supporting security awareness content for active phishing, vishing, and social engineering campaigns.
- Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
- Detection Improvement from Hunt Outcomes: Convert hunt findings into durable detections.
- Red Team and Purple Team Exercises: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement; emulate actor TTPs identified through CTI.
- Detection Validation: Partner with the SOC and detection engineering to measure whether controls detect and respond as expected, mapping coverage and gaps to MITRE ATT&CK.
- Remediation Workflow: Deliver prioritized remediation recommendations based on findings, then retest to confirm gaps are closed.
- SOC Escalation: Serve as the senior technical escalation point for complex or high-severity alerts, including those involving Lockton’s managed detection and response partner.
- Triage and Incident Determination: Guide triage decisions and determine when an alert escalates to an incident.
- Reduce False Positives: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results to reduce false positives and close visibility gaps.
- Mentoring and Knowledge Sharing: Improve SOC capability through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
- Cross-Functional Collaboration: Coordinate with IT, Legal, and other departments to support a comprehensive response to security threats.
- On-Call Coverage: Respond to security-related emergencies that may occur outside regular business hours and participate in the security team On-Call rotation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Minimum 5 years of information security experience with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
- Relevant certifications are highly desirable, such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP.
- Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
- Hands-on experience with EDR and SIEM platforms.
- Strong plus: experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR.
- Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
- Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development.
- Experience with adversary emulation tooling (examples include Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments.
- Excellent problem-solving skills, including the ability to work under pressure.
- Meticulous attention to detail to ensure accuracy and integrity of forensic investigations and incident reports.
- Strong written and verbal communication skills, including the ability to produce intelligence products and incident reports for technical and executive audiences.
- Ability to collaborate effectively in a team environment with cross-functional stakeholders.
- Willingness to stay current with attacker tradecraft, cloud security, and emerging threats, including AI-enabled attacks, and continuously enhance skills.
Relevant Technologies
- MITRE ATT&CK
- EDR
- SIEM
- CrowdStrike Falcon
- Microsoft Sentinel
- Microsoft Defender XDR
- PowerShell
- Python
- KQL
- Atomic Red Team
- MITRE Caldera
- Active Directory
- Entra ID
- Microsoft 365
- Azure
Role Details
- Business Unit: Lockton Center Services
- Schedule: Full-time
- Workplace: Hybrid
- Location: Kansas City, MO
Minimum Experience
Minimum 5 years of experience in information security.