Detection and Response Lead

Integrated Specialty Coverages, LLC
$160,000 - $200,000Hybrid

About The Position

ISC Cybersecurity is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across our enterprise and AWS environments. The role will report to the CISO and will partner with internal security engineering, as well as with our managed security services provider (MSSP) and managed detection and response (MDR) provider. The Detection & Response Lead focuses on detection engineering, advanced investigation, incident ownership, threat hunting, and maturing our detection and response capabilities. The role serves as the escalation point for security events, ensuring timely containment, high‑quality analysis, and actionable recommendations for improvement. This position is operational and technically deep, driving defensive execution across our AWS and enterprise environments.

Requirements

  • Bachelors in Computer Science, Cybersecurity or equivalent work experience
  • 7+ years of hands‑on experience in cybersecurity operations, incident response, or threat detection.
  • Demonstrated ability to lead complex investigations involving cloud environments, identity systems, and modern endpoint tooling.
  • Experience building or shaping a detection and response program in partnership with leadership.
  • Strong familiarity with attacker TTPs (e.g., MITRE ATT&CK), log analysis, and correlation techniques.
  • Practical experience with digital forensics fundamentals (artifact analysis, timeline creation, host/network investigation).
  • Ability to interpret MDR escalations and independently drive deeper analysis and containment actions.
  • Experience analyzing AWS and Azure security logs (CloudTrail, CloudWatch, IAM, network telemetry, workload‑level events) and taking containment measures in cloud environments.
  • Excellent written and verbal communication skills, including the ability to produce concise, high‑clarity investigative findings.

Nice To Haves

  • Experience working in environments leveraging a managed SOC/MDR provider and understanding how to integrate internal and external workflows effectively.
  • Prior experience conducting threat hunts in cloud‑first or hybrid environments.
  • Exposure to SIEM/SOAR platforms from an investigative.
  • Incident response or forensics‑related certifications (e.g., GCIH, GCFA, GNFA, GCFE).

Responsibilities

  • Conduct incident response for escalated MSSP/MDR alerts, including scoping, investigation, and containment across cloud and endpoint environments. Emergency-only on-call availability is required for high-severity incidents.
  • Perform forensic review of affected systems, including log correlation, event reconstruction, and identification of attacker techniques. Key tooling includes SIEM, EDR, proxy, WAF, and DLP technologies.
  • Provide clear incident findings, timelines, and recommended remediation steps to technical and non‑technical stakeholders.
  • Conduct hypothesis‑driven and data‑driven hunts to identify malicious or suspicious activity not already surfaced by automated detections or MSSP/MDR workflows.
  • Develop internal hunting methodologies rooted in observed attacker behavior, business‑specific risks, and historical incident patterns.
  • Document and socialize hunt outcomes, including new detection opportunities and defensive insights.
  • Review MSSP/MDR escalations for quality, signal‑to‑noise ratio, and fidelity; drive improvements through structured feedback loops.
  • Identify gaps in log coverage, detection logic, or monitoring effectiveness and coordinate with engineering partners to close them.
  • Drive Mean-Time-To-Detect and Mean-Time-To-Contain metrics as well as detection coverage metrics.
  • Serve as the technical escalation point for security incidents requiring deep analytical expertise.
  • Coordinate cross‑functional responders (IT, cloud, application owners) during active investigations.
  • Maintain tight alignment with MSSP/MDR workflows, ensuring clarity in escalation criteria, response procedures, and incident severity thresholds.
  • Report to CISO and interface with senior leadership during incidents.
  • Maintain operational runbooks, investigation procedures, and response guides.
  • Track recurring attacker patterns and translate them into defensible operational playbooks.

Benefits

  • Bonus pay
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • 401(k) plan with match
  • Paid time off
  • Employee Ownership Program
  • Professional development opportunities
  • Owner Referral Program
  • Work from home reimbursement for remote/hybrid roles
  • Canary emergency financial assistance program
  • Life/AD&D Insurance
  • Confidential, Employee Assistance Program
  • Health Savings Account, includes company contribution
  • Short-term disability
  • Voluntary benefits - supplemental accident, critical illness, hospital insurance
  • Employee discounts
  • Addition Wealth Financial Wellness Program
  • Various Time Off Programs
  • 11 company paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service