Detection and Response Lead
Jobgether
Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.
Got this interview? Our apps help you get the job.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
139 open detection roles across 61 companies are on ApplySarthi right now, most of them in Bengaluru (10), Hyderabad (2), Pune (1).
- Sr Detection EngineerMicron · hyderabad
- Senior Product Manager – German Speaking - Managed Detection and Incident Response (m/f/x)Eye Security
- Incident Management Engineer (Spanish/English bilingual), Incident Detection and Response Amazon
- Incident Management Engineer (Spanish/English bilingual), Incident Detection and ResponseAmazon Web Services
- Sr. Cyber Threat Detection and Response AnalystMckesson
What detection roles keep asking for: SIEM (52%), Python (50%), AWS (40%), Azure (23%), GCP (23%), LLMs (22%), Kubernetes (19%), Linux (19%) — counted across their open postings here.
AWS jobs · Azure jobs · Kubernetes jobs · Python jobs
Jobgether has 4,308 open roles listed here.
- Account Operations & Farming Specialist
- .NET Backend Developer Pleno
- .Net Developer
- .Net Developer
- .Net Developer
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for detection roles keep coming back to SIEM, Python, AWS, Azure. Practise those questions before you sit with Jobgether.
Questions you are likely to be asked
- Why do you want to join Jobgether?
- What is your experience with SIEM? Tell me one thing you learned the hard way.
- Tell me about yourself, and why this role is the right next step.
- Tell me about a problem you solved at work that you are proud of.
- Tell me about a time you disagreed with your manager. What happened?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Detection and Response Lead at Jobgether interview free →Accountabilities:: Own the overall strategy and catalog for security detection use cases across identity and authentication abuse, privileged access, Azure and AWS cloud activity, endpoint and email threats, and relevant internal attack paths. Build, validate, test, version, review, and continuously improve detections using modern SIEM capabilities and real organizational telemetry. Treat detections as engineering assets, documenting the reasoning behind changes and ensuring coverage is measured against a defined threat model rather than simply counting vendor rules. Own signal quality end to end by tuning noisy detections, retiring ineffective rules, identifying coverage gaps, and documenting deliberate detection exclusions. Establish telemetry requirements for incident investigation, including what data should be collected and retained, and advocate for the resources required to meet those standards. Lead incident response from initial escalation through scoping, containment, evidence handling, root-cause analysis, remediation, closure, and executive-quality reporting. Direct the relationship with the managed security provider, defining escalation criteria, quality expectations, response standards, and feedback loops. Review provider escalations and identify missed detections or weaknesses in monitoring, ensuring corrective actions are implemented. Conduct tabletop exercises with engineering and leadership teams and maintain practical incident-response runbooks that support effective decisions during high-pressure events. Own the incident notification process, ensuring contractual and regulatory obligations are identified and that relevant stakeholders understand notification timelines. Collaborate with Product Security when incidents have implications for products or customer-facing security concerns, maintaining appropriate separation between internal response and external disclosure. Determine where AI-assisted and agentic workflows should be used across detection and response, defining appropriate boundaries between autonomous action, recommendations, and human verification. Automate investigation and response workflows, with a focus on completing enrichment, correlation, and first-pass investigation before an analyst begins manual review. Incorporate threat intelligence into operational security by translating adversary behavior into detection use cases, threat hunts, or control improvements. Establish and improve program metrics covering threat-model coverage, provider escalation quality, time to detect, time to respond, and time to close. Conduct structured threat hunts based on defined hypotheses and ensure findings are converted into detections, control improvements, or documented risk decisions. Provide functional direction to SOC analysts while collaborating closely with security and engineering leadership. Produce incident documentation and reports that are clear, technically rigorous, and suitable for executive and audit-level review. Requirements: 8+ years of experience in security operations, detection engineering, incident response, or a closely related discipline, including significant experience leading security incidents. Strong hands-on detection engineering experience within a modern SIEM environment, including the ability to independently write, query, validate, and troubleshoot detection rules. Experience with Microsoft Sentinel and Microsoft Defender XDR is highly relevant. Strong knowledge of identity security and identity-based attack techniques, including Entra ID, Active Directory, token and session abuse, OAuth consent attacks, and federation-related threats. Recent hands-on experience with AI-assisted detection, triage, or investigation, ideally within the last six months, combined with a thoughtful understanding of where AI-driven automation can and cannot be trusted to act. Experience with cloud detection across Azure and AWS control planes is highly desirable. Strong scripting and automation capabilities using Python, PowerShell, or comparable technologies. Experience managing or directing an MDR provider or managed SOC relationship is preferred. Practical experience with forensic investigation, evidence collection, preservation, and analysis. Strong technical writing skills, with the ability to produce incident documentation suitable for executives, auditors, and other senior stakeholders. Experience conducting structured threat hunts based on defined hypotheses is an advantage. Knowledge of insider-risk detection, container and Kubernetes runtime security, SOAR or workflow automation platforms, and operational threat intelligence is beneficial. Previous experience working closely with engineering teams is an advantage. Strong analytical judgment and the ability to distinguish meaningful security signals from noise. Excellent communication and stakeholder-management skills, particularly during high-severity incidents. Ability to operate independently, establish priorities, and make sound decisions within a lean and distributed security organization. Strong ownership mindset, with a focus on building durable detection and response capabilities rather than simply managing alert volume. Benefits: Fully remote opportunity based in India. Senior individual-contributor position with ownership of a strategic detection and response practice. Opportunity to shape detection engineering, incident response, threat hunting, and security automation from the ground up. Exposure to modern security technologies spanning SIEM, XDR, cloud security, identity security, automation, and managed SOC operations. Direct interaction with security, engineering, and leadership stakeholders. Opportunity to influence how AI and agentic automation are responsibly applied to security operations. Functional leadership responsibility for SOC analysts without requiring traditional line-management responsibilities. Opportunity to develop security processes, metrics, runbooks, detection standards, and response practices. Global and distributed working environment with exposure to complex security challenges across cloud and corporate environments. Professional growth opportunities within a technology-focused security organization. Collaborative culture that values innovation, continuous improvement, technical ownership, and meaningful security outcomes. Opportunity to work on high-impact security incidents and initiatives with visibility at senior leadership level.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- AI Research Engineer (Kernel & Inference Optimization)Jobgether
- Account Manager (Email Marketing)Jobgether
- Advogado(a) | BancárioJobgether
- Agentic Workforce Adoption ManagerJobgether
- AI EngineerJobgether
- AI Marketing Project ManagerJobgether
- Analista de Testes Automatizados / Sistemas SêniorJobgether
- Analista Suporte Jr N1Jobgether
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on lever · posted 2026-10-08. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.