Security Engineer, Detection & Response

Lockton - Kansas City, MO

Hiring: Security Engineer, Detection & Response Company: Lockton Location: Kansas City, MO Job Posted Time: 2026-09-17 04:27:47 Target Skills & Keywords : Azure, Penetration Testing, PowerShell, Python, Root Cause Analysis, SIEM, SOC, SaaS About the job Experience: •5 years of experience in information security, with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing. Required Skills: •The ideal candidate is a hands-on practitioner who is equally comfortable leading a live incident bridge, tracking the threat actors most likely to target Lockton, and emulating those actors to prove our defenses work. •Incident Leadership: Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover. Own incident documentation and ensure communication and escalation processes are followed. •Forensic Analysis: Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence. Preserve the integrity of data and produce detailed forensic and incident reports. •Root Cause and Lessons Learned: Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks. •Readiness: Maintain and improve incident response playbooks and runbooks. Plan and run tabletop exercises with technical and executive audiences across regions. •Intelligence Program: Build and run Lockton's CTI capability. Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships. •Threat Actor Tracking: Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate. Maintain actor profiles and produce regular threat briefings for security leadership and the broader team. •Operationalizing Intelligence: Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns. Qualifications: •Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience. •Minimum of 5 years of experience in information security, with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing. •Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable. •Solid functional working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation. •Applied hands-on capability in EDR and SIEM platforms. Experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR is a strong plus. •In-depth knowledge of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure. •Excellent problem-solving skills and the ability to work under pressure. •Meticulous attention to detail to ensure the accuracy and integrity of forensic investigations and incident reports. •Strong written and verbal communication skills, with the ability to produce intelligence products and incident reports for both technical and executive audiences. •Demonstrated capacity to work effectively in a team environment and collaborate with cross-functional teams. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!