Threat Detection and Response Engineer

Remote, USA Full-time
## Role Apply comprehensive knowledge and a thorough understanding of Incident Response concepts, principles, and technical capabilities Collaborate across Information Security and business partners to ensure effective, precise, and rapid response Act as the point of escalation from within the Incident Response team to drive all cyber incidents Identify new detection opportunities, create playbooks, and support new technology implementations to defend against evolving threats Maintain awareness and understanding of the current threat landscape. Analyze threat intelligence with the aim to mitigate potential risks Report the overall health of the SOC via metrics, OKRs, and risk indicators to leadership Provide Incident Response (IR) support when analysis suspects security incidents to help contain and eradicate threats; Perform incident triage, incident response, and forensic investigations across endpoints and cloud environments Conduct technical examinations of computer-based evidence including logs, packet captures, SIEM & IDS events, disk forensics, malware analysis, and more Document incidents from initial detection through final resolution, and present the findings Investigate, document, and report on cyber security issues Create and continuously improve standard processes, operating procedures, and incident response playbooks ## You Curious about who thrives at Whatnot? We’ve found that low ego, a growth mindset, and leaning into action and high impact goes a long way here. As our next Threat Detection and Response Engineer, you should have a minimum of 5+ years of relevant experience in security, preferably in a large enterprise environment, plus: Bachelor’s degree in Computer Science, Information Security, a related field, or equivalent work experience. 5+ years’ experience in cyber incident response, or a similar cyber field, including experience with security principles, and defense-in-depth techniques Experience and understanding of security concepts, SOAR(Tines), EDR, NDR and SIEM (Chronicle) technologies Experience with multiple Cloud Service Providers (AWS, GCP) Excellent written communication skills with the ability to document, communicate, and report security incidents, as well as the status of the implementation and effectiveness of cybersecurity controls with product and business leaders Expected to perform on-call duties Apply tot his job
Apply Now

Similar Jobs

Infrastructure Automation Architect

Remote, USA Full-time

Temporary, Part-Time, Remote IEP Writer

Remote, USA Full-time

Coordinator, Advocacy-Temporary-Remote-Washington, DC, Atlanta or East Coast

Remote, USA Full-time

Temporary Remote Medical Imaging Processing Agent (MIPS Agent)

Remote, USA Full-time

Temporary Virtual RN (4 month contract)

Remote, USA Full-time

Temporary IT/Technical Pool

Remote, USA Full-time

Temporary Associate Producer, TED Radio Hour

Remote, USA Full-time

**Temporary Remote Catastrophe (CAT) Customer Service Representative**

Remote, USA Full-time

System Application Operator II - 3 Month Temporary Role

Remote, USA Full-time

Temporary Finance and Gift Accounting Specialist

Remote, USA Full-time

**Experienced Manager, Guest Communications – Strategic Planning and Execution for Disney Cruise Line's Hybrid Guest Experience**

Remote, USA Full-time

US Tax Law Correspondent / Reporter

Remote, USA Full-time

Music Group - Operations Coordinator [Remote]

Remote, USA Full-time

Hiring for Cybersecurity Analyst- Junior

Remote, USA Full-time

[Remote] CFO/ CXO Finance Transformation Strategy Consultant

Remote, USA Full-time

[Remote] Agency and Platform Revenue Development Representative (26_2026.1)

Remote, USA Full-time

Oracle Fusion Cloud Finance Consultant

Remote, USA Full-time

Zillow Lead Team Sales Manager

Remote, USA Full-time

USPS Postal Clerk - Entry Level

Remote, USA Full-time

Beginner Game Reviewer and Tester - Remote Gaming Career Opportunity with Competitive Hourly Rate

Remote, USA Full-time
Back to Home