Security Engineer, Detection & Response
Job Description
Join Lockton’s Global Security Operations team and help strengthen detection and response end-to-end. This role focuses on leading technical incident response, building and running a cyber threat intelligence program, and turning threat and hunt insights into durable detections that reduce false positives and improve SOC coverage. The team also supports structured knowledge sharing and mentoring to raise the technical bar across regions.
Responsibilities
- Incident leadership: Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
- Own documentation and escalation: Maintain incident documentation and ensure communication and escalation processes are followed.
- Forensic analysis: Conduct digital forensics across endpoint, identity, email, and cloud to collect and analyze evidence.
- Report and preserve integrity: Preserve data integrity and produce detailed forensic and incident reports.
- Root cause and lessons learned: Perform root cause analysis on significant incidents and convert findings into changes to detections, controls, and playbooks.
- Detection and readiness: Maintain and improve incident response playbooks and runbooks.
- Exercises and intelligence program: Plan and run tabletop exercises with technical and executive audiences across regions. Build and run Lockton’s CTI capability.
- Threat actor tracking: Track relevant threat actors, campaigns, and techniques for Lockton, the insurance and financial services sector, and the regions where the company operates. Maintain actor profiles and produce regular threat briefings.
- Operationalize intelligence: Feed indicators and behaviors into the detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns.
- Threat hunting and outcomes: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry, and convert hunt findings into durable detections.
- Red and purple team: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement. Emulate TTPs identified through CTI.
- Detection validation and improvement: Work with the SOC and detection engineering to validate whether controls detect and respond as expected. Map coverage and gaps to MITRE ATT&CK, deliver prioritized remediation, and retest to confirm gaps are closed.
- SOC escalation: Act as the senior technical escalation point for complex or high-severity alerts, including coordination with the managed detection and response partner. Guide triage decisions and determine when an alert becomes an incident.
- Mentoring and collaboration: Raise the SOC’s technical capability through knowledge sharing, documented escalation procedures, and coaching on investigation techniques. Collaborate closely with IT, Legal, and other departments for coordinated response.
- On-call availability: Must be able to respond to security-related emergencies outside regular business hours and participate in the security team on-call rotation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- Minimum 5 years of experience in information security, with hands-on experience in at least two of: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
- Relevant certifications are highly desirable: GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP.
- Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
- Hands-on experience with EDR and SIEM platforms.
- Strong plus: experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR.
- Understanding of the Microsoft ecosystem: Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
- Experience with scripting and query languages: PowerShell, Python, KQL.
- Experience with adversary emulation tooling (examples: Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments.
- Excellent problem-solving skills and ability to work under pressure.
- Meticulous attention to detail for accurate forensic investigations and incident reports.
- Strong written and verbal communication for intelligence products and incident reports for both technical and executive audiences.
- Ability to collaborate effectively and keep skills current with attacker tradecraft, cloud security, emerging threats, including AI-enabled attacks.
Tech Stack
- MITRE ATT&CK, EDR, SIEM
- CrowdStrike Falcon, Microsoft Sentinel, Microsoft Defender XDR
- PowerShell, Python, KQL
- Atomic Red Team, MITRE Caldera
- Active Directory, Entra ID, Microsoft 365, Azure
Workplace: Hybrid • Location: Kansas City, MO • Schedule: Full-time • Business Unit: Lockton Center Services