Detection and Response Engineer
Jobgether
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
123 open detection roles across 62 companies are on ApplySarthi right now, most of them in Bengaluru (11), Hyderabad (2), Pune (1).
- Senior Detection & Response EngineerExpel
- Senior Data Modeler, Fraud Risk DetectionExperian
- Staff Security Engineer, Detection & ResponseMaven Clinic
- Lead Threat Detection & Threat Hunting EngineerThomsonreuters
- DIGITAL SECURITY - Threat Detection and Huntingfa-etvl-saasfaprod1 · hyderabad
What detection roles keep asking for: SIEM (44%), Python (43%), AWS (29%), SaaS (20%), LLMs (20%), Linux (18%), Azure (17%), GCP (17%) — counted across their open postings here.
AWS jobs · Azure jobs · GCP jobs · LLMs jobs
Jobgether has 3,935 open roles listed here.
- AI Researcher — Distillation
- AI Researcher — Distillation
- Accounting & Regulatory Reporting
- Accounts Receivable Coordinator
- AI Security Analyst
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for detection roles keep coming back to SIEM, Python, AWS, SaaS. Practise those questions before you sit with Jobgether.
Questions you are likely to be asked
- Why do you want to join Jobgether?
- What is your experience with LLMs? Tell me one thing you learned the hard way.
- Describe a time a deadline forced a trade-off in quality. What did you choose and why?
- How would you design an API for a feature you have worked on?
- What do you do when a production issue happens on your code?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Detection and Response Engineer at Jobgether interview free →Accountabilities: Design, build, tune, and maintain detection content, including rules, correlation searches, and security use cases across endpoint, network, cloud, and identity data sources. Perform detection coverage and gap analysis using the MITRE ATT&CK framework, actual telemetry, and the organization's attack surface to prioritize improvements. Validate detection logic against real-world adversary techniques and threat intelligence while reducing false positives without compromising detection effectiveness. Maintain and version-control detection rules, associated documentation, coverage information, and known gaps. Triage, investigate, and contain security incidents and alerts across the environment. Conduct root-cause analysis and structured post-incident reviews, incorporating lessons learned into detection and response improvements. Document incident timelines, indicators of compromise, remediation activities, and investigative findings. Support forensic investigations involving compromised hosts, user accounts, and applications, and participate in an on-call rotation for critical incidents when required. Evaluate, pilot, and implement AI- and LLM-powered solutions for alert triage, enrichment, investigation, and analyst workflows. Build and optimize AI-assisted security workflows that reduce analyst workload and improve mean time to respond. Identify high-value opportunities for AI and automation while measuring their operational impact and applying appropriate human validation. Develop security automation and orchestration using SOAR platforms, scripts, APIs, and integrations. Automate repetitive detection and incident response activities such as evidence collection, enrichment, and ticketing. Build and maintain incident response playbooks, runbooks, and supporting procedures. Develop and maintain Python, PowerShell, or similar scripts that integrate security tools and data sources. Partner with cloud, network, identity, and engineering teams to address telemetry and visibility gaps. Monitor threat intelligence, adversary tactics, techniques, procedures, and vulnerabilities relevant to payment and financial technology environments. Communicate security findings, coverage gaps, recommendations, and incident information effectively to technical and non-technical stakeholders. Maintain procedures and policy documentation supporting detection and response operations. Requirements Bachelor’s degree in a technical field or equivalent professional experience. 3–5 years of hands-on information security experience, with demonstrated depth in at least two areas such as detection engineering, incident response, security automation, or SOC operations. Hands-on experience creating, tuning, or maintaining detection content within a SIEM or NG-SIEM platform such as CrowdStrike NG-SIEM, Splunk, or Microsoft Sentinel. Experience with EDR/XDR platforms and security log analysis across endpoint, network, cloud, and identity sources. Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and coverage analysis. Experience with security scripting or automation using Python, PowerShell, or similar technologies, and/or experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex. Solid understanding of networking, cloud infrastructure—particularly AWS, with exposure to Azure and GCP—as well as Windows, Linux, and identity platforms. Working knowledge of PCI-DSS or a comparable security and compliance framework. Strong written and verbal communication skills, including the ability to translate complex technical findings for non-technical audiences. Experience with SOAR platforms such as n8n or Tines is a plus. Experience integrating or building with LLM and AI APIs for security use cases is beneficial. Familiarity with cloud-native security tools such as AWS GuardDuty, Microsoft Sentinel, or Google Security Command Center is advantageous. Experience with threat intelligence platforms, digital forensics, purple teaming, or adversary emulation is a plus. Familiarity with payment or fintech regulatory environments is beneficial. Relevant certifications such as GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, or CompTIA CASP+ are welcome but not required; practical hands-on experience is prioritized. Benefits Salary: $100,000–$145,000 annually. Compensation within the range varies based on work location, job-related knowledge, skills, and experience. Full-time, fully remote position within the United States. Opportunity to work across detection engineering, incident response, security automation, and AI-enabled SOC operations. Opportunity to work with emerging AI and LLM technologies applied to cybersecurity. Cross-functional collaboration with security, cloud, network, identity, IT, and engineering teams. Opportunity to contribute to security capabilities within a payment technology environment. Benefits and total rewards offerings are discussed throughout the interview process. Inclusive work environment with a focus on employee well-being and professional development. No current or future visa sponsorship is available for this position.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- .Net Software DeveloperJobgether
- Account DirectorJobgether
- Account Director, Renewals & GrowthJobgether
- Advisor, BMO SmartFolio WFHJobgether
- Agentic AI DeveloperJobgether
- AI Graphic Designer + Video EditorJobgether
- AI/ML Data ScientistJobgether
- Analista de Automação e IA com N8NJobgether
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on lever · posted 2026-09-21. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.