Securtiy Engineer- Detection & Response Operations

Posted on July 29, 2026

Apply Now

Job Description

Security Engineer- Detection & Response Operations

Overview

This role owns the operational side of the Vulnerability Detection & Response (VDR) program, focusing on the response discipline that ensures vulnerabilities are evaluated, remediated, and verified within strict SLA timeframes — as little as 12 hours for the most critical exploitable, internet-reachable findings. The Security Engineer will design and implement response playbooks, build on-call and emergency-patch processes, execute them during a parallel-run period, and train internal security and platform teams to operate them post-cutover. The role requires close coordination with engineering teams to drive real findings through the full lifecycle from triage to verified closure, while also establishing SLA telemetry, drift alerting, and operator-quality documentation for long-term program sustainability.

Key Responsibilities

  • Develop the runbook library for vulnerability response, including triage and evaluation runbooks, standard remediation workflows per finding type (container image, host, dependency, code), emergency-patch runbooks for PAIN-5 LEV+IRV findings (12h–2d SLAs), and verification/closure procedures
  • Design and implement the on-call and escalation model, including PagerDuty alerting rules tied to PAIN/LEV/IRV thresholds
  • Operate the response process during the parallel-run and cutover period: drive real findings through evaluation → prioritization → remediation → verification, proving SLAs are achievable before the deadline
  • Build the remediation verification step, ensuring fixes are confirmed in the deployed environment — not just in a rebuilt image — before findings close (runtime reconciliation as an operational practice)
  • Define SLA telemetry and drift alerting: dashboards and alerts that show when findings are approaching or breaching their timeframe class
  • Coordinate remediation with engineering teams: patching guidance, upgrade paths, compensating controls, and clear acceptance criteria for fixes
  • Run tabletop exercises for the emergency-patch scenario and refine runbooks from lessons learned
  • Train internal security and platform teams on the runbooks and produce operator-quality documentation for handoff

Required Skills

  • 5+ years in security operations, vulnerability management operations, or detection & response roles
  • Hands-on remediation experience: personally driven patching campaigns, container image updates, and dependency upgrades across engineering teams
  • Experience writing operational runbooks and incident/response procedures that other people successfully execute
  • Working knowledge of exploit intelligence and prioritization (CISA KEV, EPSS, vendor advisories) and how it changes urgency
  • Experience with alerting and on-call tooling (PagerDuty or equivalent) and SLA-driven workflows
  • Cloud and container fluency: comfortable reasoning about how a fix reaches production in an EKS/ECS + ECR + CI environment

Preferred Skills

  • Experience in a FedRAMP or other regulated environment where remediation timeframes are compliance obligations
  • Familiarity with DefectDojo or similar platforms as the system of record for response workflows
  • Incident response background, particularly for emergency-patch discipline
  • Experience running tabletop exercises and operational readiness reviews

Qualifications

  • Experience: 6 Years

Required Skills

No specific skills listed.

Community Discussion

Ask questions, share feedback, or discuss this opportunity. Your comment will be visible to everyone.
Be the first to share your thoughts on this opportunity.

Clarification Board

Your Clarifications
"Send your Job Related Query - you'll get a reply soon."