EngineerJobs.io
← Back to all jobs

Job Description

Blackstone’s front-line cyber defense team is seeking an associate incident responder to detect, investigate, and respond to information security incidents across multiple domains.

Responsibilities

  • Manage an incident queue from intake through investigation, containment, and closure across email, endpoint, identity, network, and cloud
  • Handle Tier 1 escalations by taking ownership of more complex investigations and bringing in additional responders as scope expands
  • Investigate incidents in the firm’s SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry
  • Perform endpoint investigation, host containment, and live response in the EDR platform, including process lineage, persistence review, and artifact collection
  • Investigate email threats end to end (phishing, business email compromise, malicious attachments and links) using header and message trace analysis to identify targeted users and drive mailbox remediation
  • Investigate cloud and identity compromise, including credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass
  • Investigate third-party and SaaS provider compromises by coordinating with the provider’s incident response team to confirm containment and determine what Blackstone data was affected
  • Independently scope exposure by hunting provider indicators across endpoint, email, network, and cloud telemetry; coordinate findings and remediation with legal and compliance, vendor risk, and business owners
  • Serve as a core incident response team member by scoping intrusions, driving containment and eradication, briefing stakeholders, and escalating using the firm’s severity model
  • Author and tune detections based on investigation findings, validating logic against historical and live data, moving detections through review into production, and confirming real-world firing without unacceptable noise
  • Collaborate with agentic AI investigation tooling for first-pass triage and enrichment, evaluate outputs, escalate inaccuracies, and feed corrections back to improve coverage
  • Help expand detection and response coverage for the firm’s increasing use of AI across a fast-moving attack surface
  • Turn investigation findings into durable coverage by reducing false positives and building automation to remove repetitive triage, enrichment, and response steps
  • Mentor Tier 1 analysts on investigation technique through case reviews and hands-on coaching
  • Document investigations and incidents with audit-ready evidence handling and chain of custody; communicate clearly to technical teams and senior stakeholders
  • Contribute to threat hunts and purple team exercises using red team activity and threat intelligence to identify gaps
  • Participate in incident response and SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents

Requirements

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
  • Proven ability to run security investigations end to end from alert through root cause and containment in a SOC or IR environment
  • Hands-on SIEM experience, including writing and troubleshooting queries; experience with a major enterprise SIEM and native query language (Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)
  • Hands-on EDR experience for endpoint investigation and containment; experience with a leading EDR platform (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint)
  • Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, SSO, and identity providers such as Okta or Microsoft Entra ID
  • Practical understanding of attacker behavior across the intrusion lifecycle, including phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
  • Familiarity with security tools involved in investigations: email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data
  • Working knowledge of MITRE ATT&CK and experience mapping observed activity to techniques
  • Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation of repetitive analysis
  • Demonstrated hands-on use of AI tooling in real work, including the ability to explain projects in detail and exercise judgment about when outputs cannot be trusted
  • Clear technical writing to explain incident impact to engineers and non-technical stakeholders
  • Ability to self-organize, prioritize during time pressure, and remain accurate during live incidents

Technologies

  • SIEM (Splunk/SPL, Microsoft Sentinel/KQL, Elastic)
  • EDR (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint)
  • Okta, Microsoft Entra ID
  • MITRE ATT&CK
  • Python, PowerShell
  • AI tools, agentic AI investigation tooling
  • Email security, DLP, MFA bypass
  • SIEM queries, SIEM correlation searches

Benefits

  • Comprehensive health benefits including medical, dental, vision, and FSA
  • Paid time off
  • Life insurance
  • 401(k) plan
  • Discretionary bonuses
  • Certain employees may be eligible for equity and other incentive compensation at Blackstone’s sole discretion

Preferred Qualifications

  • Detection engineering experience authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and validating whether detections work
  • Detection-as-code experience with Git-based workflows, peer review, and CI validation of detection content
  • SOAR automation experience (Torq, Splunk SOAR, Tines, or similar)
  • Digital forensics capability (memory, disk, or network analysis) or hands-on malware triage and sandboxing
  • Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
  • Threat hunting experience with hypothesis-driven hunts against endpoint or cloud telemetry
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP), including investigation use of logging, identity, and access services
  • Experience in financial services or another heavily regulated, globally distributed environment
  • At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
  • B.S. in Computer Science, Cybersecurity, Information Systems, or related technical field

Location: Miami, FL (onsite)

Salary: USD 110,000 - 170,000 per year

Expected annual base salary range: $110,000 - $170,000

Similar Jobs