Security Engineer � Detection & Response Operations
Posted on July 29, 2026
Job Description
Security Engineer — Detection & Response Operations
Overview
This role owns the operational side of the Vulnerability Detection & Response (VDR) program, focusing on the response discipline that ensures vulnerabilities are evaluated, remediated, and verified within strict SLA timeframes — as little as 12 hours for the most critical exploitable, internet-reachable findings. The Security Engineer will design and implement response playbooks, build on-call and emergency-patch processes, execute them during a parallel-run period, and train internal security and platform teams to operate them post-cutover. The role requires close coordination with engineering teams to drive real findings through the full lifecycle from triage to verified closure, while also establishing SLA telemetry, drift alerting, and operator-quality documentation for long-term program sustainability.
Key Responsibilities
- Develop the runbook library for vulnerability response, including triage and evaluation runbooks, standard remediation workflows per finding type (container image, host, dependency, code), emergency-patch runbooks for PAIN-5 LEV+IRV findings (12h–2d SLAs), and verification/closure procedures.
- Design and implement the on-call and escalation model, including PagerDuty alerting rules tied to PAIN/LEV/IRV thresholds.
- Operate the response process during the parallel-run and cutover period: drive real findings through evaluation → prioritization → remediation → verification, proving SLAs are achievable before the deadline.
- Build the remediation verification step, ensuring fixes are confirmed in the deployed environment — not just in a rebuilt image — before findings close (runtime reconciliation as an operational practice).
- Define SLA telemetry and drift alerting: dashboards and alerts that show when findings are approaching or breaching their timeframe class.
- Coordinate remediation with engineering teams: patching guidance, upgrade paths, compensating controls, and clear acceptance criteria for fixes.
- Run tabletop exercises for the emergency-patch scenario and refine runbooks from lessons learned.
- Train internal security and platform teams on the runbooks and produce operator-quality documentation for handoff.
Required Skills
- 5+ years in security operations, vulnerability management operations, or detection & response roles.
- Hands-on remediation experience: personally driven patching campaigns, container image updates, and dependency upgrades across engineering teams.
- Experience writing operational runbooks and incident/response procedures that other people successfully execute.
- Working knowledge of exploit intelligence and prioritization (CISA KEV, EPSS, vendor advisories) and how it changes urgency.
- Experience with alerting and on-call tooling (PagerDuty or equivalent) and SLA-driven workflows.
- Cloud and container fluency: comfortable reasoning about how a fix reaches production in an EKS/ECS + ECR + CI environment.
Preferred Skills
- Experience in a FedRAMP or other regulated environment where remediation timeframes are compliance obligations.
- Familiarity with DefectDojo or similar platforms as the system of record for response workflows.
- Incident response background, particularly for emergency-patch discipline.
- Experience running tabletop exercises and operational readiness reviews.
Qualifications
- Engagement Mode: contract (6 months)
- Location: Remote
- Experience: 5-7 years
Required Skills
Community Discussion
Login to post comments and feedback visible to the community.
Sign In