×
Register Here to Apply for Jobs or Post Jobs. X

Security Engineer, Detection & Response

Job in Kansas City, Jackson County, Missouri, 64101, USA
Listing for: Cybersecurity Jobs
Full Time position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 190000 USD Yearly USD 120000.00 190000.00 YEAR
Job Description & How to Apply Below

The Security Engineer, Detection & Response will be an essential member of the Lockton Global Security Operations team, driving technical incident response from detection through recovery while also strengthening detections when there is no active incident. The role also leads cyber threat intelligence, threat hunting, and red and purple team activities, serving as the senior SOC technical escalation point.

Key Responsibilities
  • Incident Leadership: Lead technical response to security incidents, coordinating with IT, Legal, HR, Communications, and business stakeholders to scope, contain, eradicate, and recover.
  • Incident Documentation and Process Adherence: Own incident documentation and ensure required communication and escalation processes are followed.
  • Forensic Analysis: Perform digital forensic investigations across endpoint, identity, email, and cloud to collect and analyze evidence.
  • Evidence Integrity and Reporting: Preserve data integrity and produce detailed forensic and incident reports.
  • Root Cause and Lessons Learned: Conduct root cause analysis for significant incidents and convert findings into concrete improvements to detections, controls, and playbooks.
  • Readiness: Maintain and improve incident response playbooks and runbooks.
  • Exercises and Coordination: Plan and run tabletop exercises with both technical and executive audiences across regions.
  • Cyber Threat Intelligence Program: Build and run Lockton’s CTI capability.
  • Intelligence Collection and Prioritization: Collect, analyze, and prioritize intelligence from commercial feeds, open sources, information sharing communities, vendor partners, and peer relationships.
  • Threat Actor Tracking: Track threat actors, campaigns, and techniques relevant to Lockton, the insurance and financial services sector, and the regions where Lockton operates.
  • Threat Briefings: Maintain actor profiles and deliver regular threat briefings to security leadership and the broader team.
  • Operationalizing Intelligence: Convert intelligence into action by feeding indicators and behaviors into the detection stack, generating hunt hypotheses, informing vulnerability prioritization, and supporting security awareness content for active phishing, vishing, and social engineering campaigns.
  • Threat Hunting: Lead intelligence-driven threat hunts across endpoint, identity, cloud, email, and SaaS telemetry.
  • Detection Improvement from Hunt Outcomes: Convert hunt findings into durable detections.
  • Red Team and Purple Team Exercises: Plan and execute red team and purple team exercises, including assumed breach, identity and cloud attack paths, and social engineering scenarios, under approved rules of engagement; emulate actor TTPs identified through CTI.
  • Detection Validation: Partner with the SOC and detection engineering to measure whether controls detect and respond as expected, mapping coverage and gaps to MITRE ATT&CK
    .
  • Remediation Workflow: Deliver prioritized remediation recommendations based on findings, then retest to confirm gaps are closed.
  • SOC Escalation: Serve as the senior technical escalation point for complex or high-severity alerts, including those involving Lockton’s managed detection and response partner.
  • Triage and Incident Determination: Guide triage decisions and determine when an alert escalates to an incident.
  • Reduce False Positives: Tune and improve detection content and SOC playbooks based on escalations, incidents, hunts, and exercise results to reduce false positives and close visibility gaps.
  • Mentoring and Knowledge Sharing: Improve SOC capability through knowledge sharing, documented escalation procedures, and coaching on investigation techniques.
  • Cross-Functional Collaboration: Coordinate with IT, Legal, and other departments to support a comprehensive…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary