Detection and Response Lead
ISC (Integrated Specialty Coverages, LLC) - United States
Hiring: Detection and Response Lead Company: ISC (Integrated Specialty Coverages, LLC) Location: United States Job Posted Time: 2026-09-16 14:37:55 Employment Type: Remote Target Skills & Keywords : AWS, Azure, CloudWatch, IAM, SIEM, SOC, User Experience, WAF About the job Experience: •7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection. Required Skills: •Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents. •Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and DLP technologies. •Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders. •Conduct hypothesis‑driven and data‑driven hunts to identify malicious or suspicious activity not already surfaced by automated detections or MSSP/MDR workflows. •Develop internal hunting methodologies rooted in observed attacker behavior, business‑specific risks, and historical incident patterns. •Document and socialize hunt outcomes, including new detection opportunities and defensive insights. •Review MSSP/MDR escalations for quality, signal‑to‑noise ratio, and fidelity; drive improvements through structured feedback loops. •Identify gaps in log coverage, detection logic, or monitoring effectiveness and coordinate with engineering partners to close them. Qualifications: •Bachelors in Computer Science, Cybersecurity or equivalent work experience •Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling. •Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques. •Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation). •Demonstrated capacity to interpret MDR escalations and independently drive deeper analysis and containment actions. •Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings. •Prior experience conducting threat hunts in cloud‑first or hybrid environments. •Exposure to SIEM/SOAR platforms from an investigative. •Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE). •This role also offers bonus pay. Your ISC Talent Acquisition representative will share more details about the bonus component should you advance in the interview process. Compensation: •Flexible work environment (work from home / hybrid options) •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!