Lead Detection & Response Analyst

Rapid7Arlington, VA

About The Position

Rapid7’s Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world. Our SOC operates with an impact-driven mindset focused on identifying meaningful threats and delivering actionable outcomes for our customers. Rapid7’s Managed Detection and Response (MDR) Security Operations Center delivers 24/7 continuous monitoring, threat hunting, and sophisticated incident response for global organizations. The team focuses on stopping adversary activity, elevating technical standards, and driving actionable security outcomes. As a Lead Detection & Response Analyst, your primary responsibility will be to serve as a high-level technical lead and driver of technical excellence across global SOC operations. Specifically, your focus will be to lead the response to high-impact, novel, or highly complex security threats, develop new investigative methodologies for emerging attack vectors where established methods do not exist, serve as the primary technical escalation point for the global SOC, directing containment and remediation strategies, identify systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities, architect and refine investigative workflows to leverage advanced tooling and automation, author advanced technical intelligence reports and advisories for executive leadership and customers, mentor and grow the technical bench strength of the SOC through high-level coaching and technical workshops, and influence product and platform direction by providing expert feedback to engineering teams.

Requirements

  • 8+ years of cybersecurity operations, Incident Response, or Digital Forensics experience in a high-maturity SOC/MDR environment.
  • Expert-level mastery of the MITRE ATT&CK framework to build behavioral detection strategies.
  • Deep forensic expertise across Endpoint, Cloud, Identity, and Network domains, including log analysis and malware triage.
  • Ability to drive complex technical projects from conception to completion across global teams.
  • Ability to direct containment strategies efficiently during high-stakes customer compromises to maintain momentum and resolve challenges.
  • Ability to articulate complex attacker TTPs and long-term security strategies clearly to technical engineers and C-level executives.
  • Ability to build cross-functional alignment with Detection Engineering, Product, and Platform teams to deliver sustainable defense capabilities.
  • Ability to mentor and coach analysts across the global SOC, setting clear expectations for investigative quality.
  • Ability to adapt to evolving adversary techniques by driving forward-looking investigative practices.
  • Hold advanced industry certifications such as GCFA, GCTI, GREM, or OSCP.
  • Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

Responsibilities

  • Lead the response to high-impact, novel, or highly complex security threats.
  • Develop new investigative methodologies for emerging attack vectors where established methods do not exist.
  • Serve as the primary technical escalation point for the global SOC, directing containment and remediation strategies.
  • Identify systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities.
  • Architect and refine investigative workflows to leverage advanced tooling and automation.
  • Author advanced technical intelligence reports and advisories for executive leadership and customers.
  • Mentor and grow the technical bench strength of the SOC through high-level coaching and technical workshops.
  • Influence product and platform direction by providing expert feedback to engineering teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service