Alert, Detection, and Response Engineer, Associate
Ai Security
Cloud Threat Detection
Crowdstrike
Detection And Response
Detection Engineering
Endpoint Detection & Response
Endpoint Security
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsoft Defender For Endpoint
Microsoft Sentinel
Mitre Att&ck
Security
Security Analytics
Security Automation
Security Detection Engineering
Security Investigations
Security Operations
Security Threat Detection
Sentinelone
Splunk
Job Description
Blackstone’s front-line cyber defense team is seeking an associate incident responder to detect, investigate, and respond to information security incidents across multiple domains.
Responsibilities
- Manage an incident queue from intake through investigation, containment, and closure across email, endpoint, identity, network, and cloud
- Handle Tier 1 escalations by taking ownership of more complex investigations and bringing in additional responders as scope expands
- Investigate incidents in the firm’s SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry
- Perform endpoint investigation, host containment, and live response in the EDR platform, including process lineage, persistence review, and artifact collection
- Investigate email threats end to end (phishing, business email compromise, malicious attachments and links) using header and message trace analysis to identify targeted users and drive mailbox remediation
- Investigate cloud and identity compromise, including credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass
- Investigate third-party and SaaS provider compromises by coordinating with the provider’s incident response team to confirm containment and determine what Blackstone data was affected
- Independently scope exposure by hunting provider indicators across endpoint, email, network, and cloud telemetry; coordinate findings and remediation with legal and compliance, vendor risk, and business owners
- Serve as a core incident response team member by scoping intrusions, driving containment and eradication, briefing stakeholders, and escalating using the firm’s severity model
- Author and tune detections based on investigation findings, validating logic against historical and live data, moving detections through review into production, and confirming real-world firing without unacceptable noise
- Collaborate with agentic AI investigation tooling for first-pass triage and enrichment, evaluate outputs, escalate inaccuracies, and feed corrections back to improve coverage
- Help expand detection and response coverage for the firm’s increasing use of AI across a fast-moving attack surface
- Turn investigation findings into durable coverage by reducing false positives and building automation to remove repetitive triage, enrichment, and response steps
- Mentor Tier 1 analysts on investigation technique through case reviews and hands-on coaching
- Document investigations and incidents with audit-ready evidence handling and chain of custody; communicate clearly to technical teams and senior stakeholders
- Contribute to threat hunts and purple team exercises using red team activity and threat intelligence to identify gaps
- Participate in incident response and SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents
Requirements
- 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
- Proven ability to run security investigations end to end from alert through root cause and containment in a SOC or IR environment
- Hands-on SIEM experience, including writing and troubleshooting queries; experience with a major enterprise SIEM and native query language (Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)
- Hands-on EDR experience for endpoint investigation and containment; experience with a leading EDR platform (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint)
- Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, SSO, and identity providers such as Okta or Microsoft Entra ID
- Practical understanding of attacker behavior across the intrusion lifecycle, including phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
- Familiarity with security tools involved in investigations: email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data
- Working knowledge of MITRE ATT&CK and experience mapping observed activity to techniques
- Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation of repetitive analysis
- Demonstrated hands-on use of AI tooling in real work, including the ability to explain projects in detail and exercise judgment about when outputs cannot be trusted
- Clear technical writing to explain incident impact to engineers and non-technical stakeholders
- Ability to self-organize, prioritize during time pressure, and remain accurate during live incidents
Technologies
- SIEM (Splunk/SPL, Microsoft Sentinel/KQL, Elastic)
- EDR (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint)
- Okta, Microsoft Entra ID
- MITRE ATT&CK
- Python, PowerShell
- AI tools, agentic AI investigation tooling
- Email security, DLP, MFA bypass
- SIEM queries, SIEM correlation searches
Benefits
- Comprehensive health benefits including medical, dental, vision, and FSA
- Paid time off
- Life insurance
- 401(k) plan
- Discretionary bonuses
- Certain employees may be eligible for equity and other incentive compensation at Blackstone’s sole discretion
Preferred Qualifications
- Detection engineering experience authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and validating whether detections work
- Detection-as-code experience with Git-based workflows, peer review, and CI validation of detection content
- SOAR automation experience (Torq, Splunk SOAR, Tines, or similar)
- Digital forensics capability (memory, disk, or network analysis) or hands-on malware triage and sandboxing
- Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
- Threat hunting experience with hypothesis-driven hunts against endpoint or cloud telemetry
- Working knowledge of at least one major cloud platform (AWS, Azure, or GCP), including investigation use of logging, identity, and access services
- Experience in financial services or another heavily regulated, globally distributed environment
- At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
- B.S. in Computer Science, Cybersecurity, Information Systems, or related technical field
Location: Miami, FL (onsite)
Salary: USD 110,000 - 170,000 per year
Expected annual base salary range: $110,000 - $170,000