Investigate and respond to security threats across endpoint, identity, cloud, and network environments. Triage alerts, analyze telemetry, investigate malware and unauthorized access incidents, document findings using MITRE ATT&CK, recommend remediation, identify detection gaps, and collaborate with senior analysts and customer advisors while meeting service-level objectives.
Detection & Response Analysts identify, investigate, and respond to security threats across diverse customer environments. They analyze security telemetry across endpoint, identity, cloud, and network vectors to protect global organizations from active cyber threats.
About the Team
Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world.
About the Role
As a Detection & Response Analyst, your primary responsibility will be to identify, investigate, and respond to security threats across customer environments. Specifically, your focus will be to:
The skills and qualities you'll bring include
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
About the Team
Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world.
About the Role
As a Detection & Response Analyst, your primary responsibility will be to identify, investigate, and respond to security threats across customer environments. Specifically, your focus will be to:
- Conduct investigations into suspicious and malicious activity across endpoint, identity, cloud, and network telemetry within customer environments.
- Analyze security alerts and telemetry to identify attacker behavior and impact, following defined escalation paths for potential compromises.
- Investigate standard security incidents, including common malware infections, unauthorized access attempts, and credential abuse.
- Assist senior analysts and Incident Response Consultants during larger engagements to build exposure to complex threat scenarios.
- Document investigation findings clearly in reports, detailing timelines of activity and recommended remediation steps aligned with the MITRE ATT&CK framework.
- Collaborate with SOC Advisors to ensure investigation findings and recommended remediation actions are communicated effectively to customers.
- Identify and report detection gaps or noisy alerts to help the team refine detection logic.
- Maintain high operational standards by meeting service level objectives for alert triage and investigation quality.
The skills and qualities you'll bring include
- Bring 2-4 years of experience in cybersecurity operations, IT security, or a related technical role within a SOC or monitoring environment.
- Demonstrate a foundational understanding of attacker tactics, techniques, and procedures (TTPs), such as persistence, defense evasion, and lateral movement.
- Utilize security tools (SIEM, EDR, or NDR) to triage alerts, analyze telemetry, and assess potential compromise.
- Apply knowledge of Windows and Linux operating systems, including system logs and processes, to conduct thorough technical investigations.
- Leverage investigative frameworks like MITRE ATT&CK to categorize security events and document timelines of activity.
- Communicate technical findings clearly in written reports and verbal updates to ensure findings are actionable by conveying objectives and rationale to foster commitment.
- Drive efficient decision-making to resolve challenges and enable momentum during active incident triaging.
- Hold self accountable for driving outcomes and meeting operational service level objectives for alert triage.
- Build a network and work across boundaries with senior analysts and advisors to deliver sustainable security improvements.
- Demonstrate eager interest in understanding why changes occur and act as an active driver in evolving security environments.
- Express strong attention to detail and continuous curiosity to adapt and grow in a fast-paced environment.
- Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
Similar Jobs at Rapid7
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Leads complex cybersecurity investigations and incident response across a global 24/7 MDR SOC. Develops investigative methods, directs containment and remediation, identifies detection gaps, improves workflows through automation, produces technical intelligence reports, mentors analysts, and partners with engineering, product, and platform teams to strengthen defense capabilities.
Top Skills:
Cloud SecurityDigital ForensicsEndpoint SecurityIdentity SecurityLog AnalysisMalware TriageMitre Att&CkNetwork SecuritySecurity Automation
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Leads complex cybersecurity investigations and incident response across a global 24/7 MDR SOC. Develops investigative methods, directs containment and remediation, identifies detection gaps, improves workflows through automation, produces technical intelligence reports, mentors analysts, and partners with engineering, product, and platform teams to strengthen defense capabilities.
Top Skills:
Cloud SecurityDigital ForensicsEndpoint SecurityIdentity SecurityLog AnalysisMalware TriageMitre Att&CkNetwork SecuritySecurity Automation
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Investigate security alerts and incidents by collecting and analyzing evidence, identifying intrusion vectors and malicious activity, documenting findings, tracking remediation, and conducting threat hunting. The role also analyzes forensic artifacts, researches attack methodologies, improves detection capabilities, collaborates with product development teams, and provides technical feedback to strengthen organizational security.
Top Skills:
LinuxmacOSRapid7 Command PlatformSIEMSplunkWindows
What you need to know about the NYC Tech Scene
As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

