Cybersecurity Det & Resp Eng

Old National BankPlainfield, IL
$77,900 - $153,000

About The Position

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance. 401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization. We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience.
  • Minimum 4 years of cybersecurity experience, including security monitoring, incident response, or detection engineering.
  • Experience administering Microsoft Sentinel and Microsoft Defender XDR technologies.
  • Strong KQL skills and experience developing detection logic, dashboards, or hunting queries.
  • Experience with scripting or automation such as PowerShell, Python, APIs, Logic Apps, or similar tools.
  • Working knowledge of MITRE ATT&CK, endpoint security, log analysis, and regulated security environments.
  • Interest in responsibly using AI-assisted tools to improve security operations, investigation, automation, and documentation.

Nice To Haves

  • SC-200, AZ-500, CISSP, GCIH, GCIA, GCFA, or equivalent certifications.
  • Experience in banking, financial services, or other regulated industries where security programs must be measured, documented, tested, and audit-defensible.
  • Practical experience using AI-assisted tools to accelerate investigation, summarize security data, generate or refine detection logic, improve documentation, or support automation workflows.
  • Hands-on experience with security automation, orchestration, AI-assisted analysis, or response technologies.

Responsibilities

  • Administers, engineers, and improves ONB’s security monitoring and response platforms, with primary focus on Microsoft Sentinel and Microsoft Defender XDR.
  • Builds and tunes detections.
  • Supports complex investigations.
  • Partners with third-party monitoring providers to receive and triage escalations.
  • Automates repeatable security workflows.
  • Uses modern tools—including AI-assisted analysis—to improve speed, accuracy, and consistency across security operations.
  • Develop and maintain detection use cases based on threat intelligence, emerging attack techniques, and MITRE ATT&CK.
  • Conduct validation testing, threat hunting, and participate in red/purple-team testing to evaluate detection effectiveness.
  • Identify monitoring gaps and implement improvements to coverage, telemetry, and response processes.
  • Partner with SOC analysts, IT teams, and third-party providers to improve investigation quality and operational outcomes.
  • Design and maintain Sentinel playbooks, Logic Apps, APIs, and automation workflows.
  • Automate repetitive SOC processes to improve response speed, consistency, and analyst efficiency.
  • Evaluate and responsibly apply AI-assisted capabilities to support investigation, summarization, triage, detection development, and operational improvement.
  • Serve as an escalation resource for complex security events and investigations.
  • Support incident response through data analysis, evidence collection, and investigative support.
  • Maintain practical playbooks, response procedures, and after-action improvement recommendations.
  • Research emerging threats, vulnerabilities, defensive capabilities, and practical uses of AI in security operations.
  • Support audit, regulatory, and governance needs including FFIEC, NIST, and applicable banking requirements.
  • Continuously improve monitoring, response, automation, and operational processes.

Benefits

  • medical
  • dental
  • vision insurance
  • 401K
  • continuing education opportunities
  • employee assistance program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service