Security Engineer, Detection & Response

LocktonKansas City, MO

About The Position

The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active incident, their time goes toward preventing the next one: running cyber threat intelligence (CTI), executing red team and purple team exercises, hunting for threats in our environment, and strengthening our detections. The role also serves as the senior technical escalation point for the Security Operations Center (SOC). The ideal candidate is a hands-on practitioner who is equally comfortable leading a live incident bridge, tracking the threat actors most likely to target Lockton, and emulating those actors to prove our defenses work.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • Minimum of 5 years of experience in information security, with hands-on experience in at least two of the following: incident response, digital forensics, cyber threat intelligence, threat hunting, red team or penetration testing.
  • Working knowledge of MITRE ATT&CK and experience applying it to threat hunting, detection coverage, and adversary emulation.
  • Hands-on experience with EDR and SIEM platforms.
  • Strong understanding of the Microsoft ecosystem, including Windows internals, Active Directory and Entra ID attack paths, Microsoft 365, and Azure.
  • Experience with scripting and query languages (PowerShell, Python, KQL) for automation, analysis, and detection development.
  • Experience with adversary emulation tooling (for example, Atomic Red Team, MITRE Caldera, or command and control frameworks) and running exercises safely in production environments.
  • Excellent problem-solving skills and the ability to work under pressure.
  • Meticulous attention to detail to ensure the accuracy and integrity of forensic investigations and incident reports.
  • Strong written and verbal communication skills, with the ability to produce intelligence products and incident reports for both technical and executive audiences.
  • Ability to work effectively in a team environment and collaborate with cross-functional teams.
  • Willingness to stay current with attacker tradecraft, cloud security, and emerging threats such as AI-enabled attacks, and continuously enhance skills.

Nice To Haves

  • Relevant certifications such as GCIH, GCFA, GCTI, GREM, OSCP, CRTO, or CISSP are highly desirable.
  • Experience with CrowdStrike Falcon, Microsoft Sentinel, and Microsoft Defender XDR is a strong plus.

Responsibilities

  • Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
  • Own incident documentation and ensure communication and escalation processes are followed.
  • Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
  • Preserve the integrity of data and produce detailed forensic and incident reports.
  • Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks.
  • Maintain and improve incident response playbooks and runbooks.
  • Plan and run tabletop exercises with technical and executive audiences across regions.
  • Build and run Lockton's CTI capability.
  • Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
  • Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate.
  • Maintain actor profiles and produce regular threat briefings for security leadership and the broader team.
  • Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns.
  • Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
  • Convert hunt findings into durable detections.
  • Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement.
  • Emulate the TTPs of the actors identified through CTI.
  • Work side by side with the SOC and detection engineering to measure whether our controls detect and respond as expected.
  • Map coverage and gaps to MITRE ATT&CK.
  • Deliver clear findings with prioritized remediation, then retest to confirm gaps are closed.
  • Serve as the senior technical escalation for the SOC, including our managed detection and response partner, on complex or high-severity alerts.
  • Guide triage decisions and make the call on when an alert becomes an incident.
  • Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results.
  • Reduce false positives and close visibility gaps.
  • Raise the technical bar of the SOC through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
  • Work closely with IT, Legal, and other departments to ensure a coordinated and comprehensive response to security threats.
  • Must be able to respond to security-related emergencies that may arise outside of regular business hours.
  • Participate in security team On-Call rotation.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service