Skip to content

Open nowPosted 2 days agoWe saw it 77 min after it went up

Detection and Response Lead

Jobgether3,933 open roles

Where
India
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDetection and Response LeadJobgether · India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 6 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 2 days ago

Jobgether median: 6 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Detection and Response Lead based in India.

This is a senior individual-contributor role responsible for building and leading a modern detection and response practice within a lean, globally distributed security function. You will own the strategy for security detections across identity, cloud, endpoint, email, and other critical attack surfaces. The role combines detection engineering, incident response, threat hunting, automation, telemetry strategy, and managed security provider oversight. You will lead significant incidents from escalation through containment, investigation, root-cause analysis, evidence handling, and executive-ready reporting. A major focus will be improving signal quality, strengthening threat-model-based coverage, and ensuring that managed SOC escalations meet a consistently high standard. You will also shape the responsible use of AI and automation across detection, enrichment, investigation, and response workflows. This is an opportunity to define how a growing security organization detects, investigates, and responds to real-world threats rather than simply inheriting an existing queue of alerts.

Accountabilities:

  • Own the overall strategy and catalog for security detection use cases across identity and authentication abuse, privileged access, Azure and AWS cloud activity, endpoint and email threats, and relevant internal attack paths.
  • Build, validate, test, version, review, and continuously improve detections using modern SIEM capabilities and real organizational telemetry.
  • Treat detections as engineering assets, documenting the reasoning behind changes and ensuring coverage is measured against a defined threat model rather than simply counting vendor rules.
  • Own signal quality end to end by tuning noisy detections, retiring ineffective rules, identifying coverage gaps, and documenting deliberate detection exclusions.
  • Establish telemetry requirements for incident investigation, including what data should be collected and retained, and advocate for the resources required to meet those standards.
  • Lead incident response from initial escalation through scoping, containment, evidence handling, root-cause analysis, remediation, closure, and executive-quality reporting.
  • Direct the relationship with the managed security provider, defining escalation criteria, quality expectations, response standards, and feedback loops.
  • Review provider escalations and identify missed detections or weaknesses in monitoring, ensuring corrective actions are implemented.
  • Conduct tabletop exercises with engineering and leadership teams and maintain practical incident-response runbooks that support effective decisions during high-pressure events.
  • Own the incident notification process, ensuring contractual and regulatory obligations are identified and that relevant stakeholders understand notification timelines.
  • Collaborate with Product Security when incidents have implications for products or customer-facing security concerns, maintaining appropriate separation between internal response and external disclosure.
  • Determine where AI-assisted and agentic workflows should be used across detection and response, defining appropriate boundaries between autonomous action, recommendations, and human verification.
  • Automate investigation and response workflows, with a focus on completing enrichment, correlation, and first-pass investigation before an analyst begins manual review.
  • Incorporate threat intelligence into operational security by translating adversary behavior into detection use cases, threat hunts, or control improvements.
  • Establish and improve program metrics covering threat-model coverage, provider escalation quality, time to detect, time to respond, and time to close.
  • Conduct structured threat hunts based on defined hypotheses and ensure findings are converted into detections, control improvements, or documented risk decisions.
  • Provide functional direction to SOC analysts while collaborating closely with security and engineering leadership.
  • Produce incident documentation and reports that are clear, technically rigorous, and suitable for executive and audit-level review.
  • 8+ years of experience in security operations, detection engineering, incident response, or a closely related discipline, including significant experience leading security incidents.
  • Strong hands-on detection engineering experience within a modern SIEM environment, including the ability to independently write, query, validate, and troubleshoot detection rules.
  • Experience with Microsoft Sentinel and Microsoft Defender XDR is highly relevant.
  • Strong knowledge of identity security and identity-based attack techniques, including Entra ID, Active Directory, token and session abuse, OAuth consent attacks, and federation-related threats.
  • Recent hands-on experience with AI-assisted detection, triage, or investigation, ideally within the last six months, combined with a thoughtful understanding of where AI-driven automation can and cannot be trusted to act.
  • Experience with cloud detection across Azure and AWS control planes is highly desirable.
  • Strong scripting and automation capabilities using Python, PowerShell, or comparable technologies.
  • Experience managing or directing an MDR provider or managed SOC relationship is preferred.
  • Practical experience with forensic investigation, evidence collection, preservation, and analysis.
  • Strong technical writing skills, with the ability to produce incident documentation suitable for executives, auditors, and other senior stakeholders.
  • Experience conducting structured threat hunts based on defined hypotheses is an advantage.
  • Knowledge of insider-risk detection, container and Kubernetes runtime security, SOAR or workflow automation platforms, and operational threat intelligence is beneficial.
  • Previous experience working closely with engineering teams is an advantage.
  • Strong analytical judgment and the ability to distinguish meaningful security signals from noise.
  • Excellent communication and stakeholder-management skills, particularly during high-severity incidents.
  • Ability to operate independently, establish priorities, and make sound decisions within a lean and distributed security organization.
  • Strong ownership mindset, with a focus on building durable detection and response capabilities rather than simply managing alert volume.
  • Fully remote opportunity based in India.
  • Senior individual-contributor position with ownership of a strategic detection and response practice.
  • Opportunity to shape detection engineering, incident response, threat hunting, and security automation from the ground up.
  • Exposure to modern security technologies spanning SIEM, XDR, cloud security, identity security, automation, and managed SOC operations.
  • Direct interaction with security, engineering, and leadership stakeholders.
  • Opportunity to influence how AI and agentic automation are responsibly applied to security operations.
  • Functional leadership responsibility for SOC analysts without requiring traditional line-management responsibilities.
  • Opportunity to develop security processes, metrics, runbooks, detection standards, and response practices.
  • Global and distributed working environment with exposure to complex security challenges across cloud and corporate environments.
  • Professional growth opportunities within a technology-focused security organization.
  • Collaborative culture that values innovation, continuous improvement, technical ownership, and meaningful security outcomes.
  • Opportunity to work on high-impact security incidents and initiatives with visibility at senior leadership level.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.