×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security Engineer, Detection & Response

Job in Kansas City, Jackson County, Missouri, 64101, USA
Listing for: Lockton Companies
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 110000 - 160000 USD Yearly USD 110000.00 160000.00 YEAR
Job Description & How to Apply Below

Kansas City, Missouri, United States of America

At Lockton, we’re passionate about helping our people achieve their ultimate potential. Our people are curious, action-oriented and always striving to make ourselves and those around us better. We’re active listeners working to ensure understanding and problem solvers developing innovative solutions. If you can see yourself delivering excellent service to clients, giving back to our communities and being a part of our caring culture,
you belong here.

The Security Engineer - Detection & Response is a key member of the Lockton Global Security Operations team. This is a dual-purpose role. During an incident, this person leads the technical response from detection through recovery. When there is no active incident, their time goes toward preventing the next one: running cyber threat intelligence (CTI), executing red team and purple team exercises, hunting for threats in our environment, and strengthening our detections.

The role also serves as the senior technical escalation point for the Security Operations Center (SOC). The ideal candidate is a hands‑on practitioner who is equally comfortable leading a live incident bridge, tracking the threat actors most likely to target Lockton, and emulating those actors to prove our defenses work.

Key Responsibilities:

Incident Response
  • Incident Leadership:
    Lead the technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover. Own incident documentation and ensure communication and escalation processes are followed.
  • Forensic Analysis:
    Conduct digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence. Preserve the integrity of data and produce detailed forensic and incident reports.
  • Root Cause and Lessons Learned:
    Conduct root cause analysis on every significant incident and turn findings into concrete changes to detections, controls, and playbooks.
  • Readiness:
    Maintain and improve incident response playbooks and runbooks. Plan and run tabletop exercises with technical and executive audiences across regions.
Cyber Threat Intelligence
  • Intelligence Program:
    Build and run Lockton's CTI capability. Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
  • Threat Actor Tracking:
    Track the threat actors, campaigns, and techniques most relevant to Lockton, the insurance and financial services sector, and the regions where we operate. Maintain actor profiles and produce regular threat briefings for security leadership and the broader team.
  • Operationalizing Intelligence:
    Turn intelligence into action. Feed indicators and behaviors into our detection stack, generate hunt hypotheses, inform vulnerability prioritization, and support security awareness content on active phishing, vishing, and social engineering campaigns.
  • Threat Hunting:
    Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry. Convert hunt findings into durable detections.
Red Team and Purple Team Exercises
  • Adversary Emulation:
    Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement. Emulate the TTPs of the actors identified through CTI.
  • Detection Validation:
    Work side by side with the SOC and detection engineering to measure whether our controls detect and respond as expected. Map coverage and gaps to MITRE ATT&CK.
  • Remediation:
    Deliver clear findings with prioritized remediation, then retest to confirm gaps are closed.
SOC Escalation
  • Escalation Point:
    Serve…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary