AlphaSense Logo

AlphaSense

Senior Detection and Response Engineer

Posted Yesterday
Be an Early Applicant
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
128K-161K Annually
Senior level
Easy Apply
Remote or Hybrid
Hiring Remotely in United States
128K-161K Annually
Senior level
Responsible for enhancing detection engineering, response automation, and threat hunting capabilities. Collaborate on detection rules, automated incident responses, and lead threat hunting initiatives.
The summary above was generated by AI
About AlphaSense: 

The world’s most sophisticated companies rely on AlphaSense to remove uncertainty from decision-making. With market intelligence and search built on proven AI, AlphaSense delivers insights that matter from content you can trust. Our universe of public and private content includes equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

The acquisition of Tegus by AlphaSense in 2024 advances our shared mission to empower professionals to make smarter decisions through AI-driven market intelligence. Together, AlphaSense and Tegus will accelerate growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even more comprehensive insights from thousands of content sets. Our platform is trusted by over 6,000 enterprise customers, including a majority of the S&P 500. Founded in 2011, AlphaSense is headquartered in New York City with more than 2,000 employees across the globe and offices in the U.S., U.K., Finland, India, Singapore, Canada, and Ireland. Come join us!

Location: Remote within USA

About The Role

The Senior Detection and Response Engineer is a critical technical role responsible for driving the organization's defensive security capabilities across detection engineering, security orchestration, automation, and response (SOAR), and co-leading the organization's threat hunting program. This role is crucial for integrating new threat intelligence into high-fidelity detections and automating incident response processes to maximize team efficiency and response speed.

You'll work directly with the Director of Security Monitoring, Detection and Response and collaborate closely with the SOC Manager to co-lead threat hunting initiatives, while partnering with cross-functional security teams to build and scale our security operations capabilities.

About Our Security Team

You'll be joining a fast-paced security organization that emphasizes automation, engineering-driven approaches, and systematic problem-solving. Our team operates at the intersection of security operations, detection engineering, incident response, and infrastructure security. We value practical solutions, measurable outcomes, and continuous improvement.

What You’ll Do:

1. Detection Engineering & Platform Leadership (40%)
  • Design, implement, and maintain advanced detection rules and correlation logic across SIEM , EDR, and Cloud platforms (AWS, GCP)
  • Lead detection strategy and architecture aligned with the Detection Quality frameworks
  • Write high-fidelity detection rules using languages like SIGMA and YARA-L
  • Conduct deep log source analysis, perform threat modeling, adversary emulation, and maintain MITRE ATT&CK mapping coverage
  • Conduct detection gap analysis to identify coverage opportunities across the kill chain
  • Create and maintain detection playbooks, runbooks, and comprehensive documentation
  • Perform detection quality assessments and continuous improvement initiatives
2. Security Automation (SOAR) & Response Leadership (40%)
  • Develop complex automated response playbooks for multi-stage incidents spanning multiple security tools
  • Integrate security tools via APIs (SIEM, EDR, MDM, CASB, ITSM, threat intelligence platforms)
  • Create automated enrichment pipelines incorporating threat intelligence, asset context, and user behavior analytics
  • Develop automated containment actions (account disable, host isolation, firewall rule updates)
  • Measure and report automation ROI, tracking metrics like time saved and incident handling efficiency
  • Handle Incident Response processes and procedures as needed
3. Threat Hunting Co-Leadership & Execution (20%)
  • Co-lead the organization's threat hunting program with the SOC Manager, defining strategy, methodology, and campaign planning
  • Execute proactive threat hunting campaigns by conducting hunt queries across SIEM and EDR platforms
  • Analyze large datasets to identify anomalous behavior patterns including user behavior, process execution, network traffic, and cloud activity
  • Develop hunting automation and tooling using custom Python scripts, Jupyter Notebooks, Osquery, and Velociraptor
  • Collaborate with threat intelligence sources to incorporate latest TTPs into hunting campaigns
What We Are Looking For: 
  • 7+ years in security operations with 3+ years in detection engineering, including deep expertise in creating high-fidelity rules (SIGMA, YARA-L, KQL, SPL).
  • Proven track record of building detection strategies across SIEM, EDR, and Cloud platforms, grounded in the MITRE ATT&CK framework.
  • Expert knowledge of SOAR platforms (e.g., Tines, Splunk SOAR, Cortex XSOAR), architecture, and complex playbook development.
  • Proven experience designing and implementing SOAR platform architecture from concept to production.
  • Advanced scripting and automation development skills in Python (required) for API integrations and security tool orchestration.
  • Strong background in threat hunting methodology, hypothesis development, and campaign execution, with experience leading or co-leading hunting programs.
  • Proficiency with data analysis, anomaly detection, and hands-on experience with hunting tools like Jupyter Notebooks, Osquery, and Velociraptor.
  • Deep understanding of attack techniques, lateral movement, persistence mechanisms, and post-exploitation TTPs across Windows, Linux, and macOS.
  • Familiarity with security frameworks including MITRE ATT&CK, PICERL, NIST CSF, and Detection Maturity Models, and incident response best practices.
  • Proven ability to lead technical initiatives, mentor team members, and communicate complex technical concepts to diverse audiences.
Preferred Qualifications
  • Experience with YARA-L.
  • Deep familiarity with Detection Frameworks and detection engineering quality frameworks.
  • Proven track record implementing SOAR platforms from architecture through operationalization, with experience evaluating multiple platforms.
  • Advanced knowledge of CrowdStrike Falcon platform including custom IOA rules.
  • Background in purple team activities, adversary emulation, or red teaming.
  • Experience with CI/CD practices for detection-as-code and automation-as-code.
  • Contributions to open-source security projects or security certifications (GCDA, GCIH, GCIA, GCFA, OSCP, or equivalent).
  • Knowledge of security data lakes (Snowflake, BigQuery) and experience with threat intelligence platforms (TIP).
  • Published research, blog posts, or conference presentations on detection engineering, automation, or threat hunting topics.
Behavior: 
  • Strategic Thinker: You design solutions that scale, anticipate future needs, and align with organizational security strategy
  • Builder & Architect: You design and build complex systems from the ground up, with focus on maintainability and scalability
  • Quality & Precision Focused: You care deeply about detection accuracy, automation reliability, and operational excellence
  • Proactive Hunter: You don't wait for alerts—you actively seek threats and continuously question assumptions
  • Data-Driven: You use metrics and data analysis to drive decisions, measure impact, and communicate value
Why Join AlphaSense Security
  • High-Impact Leadership Role: Own critical security capabilities (detection, automation, hunting) with direct organizational impact
  • Greenfield Opportunities: Architect and build SOAR platform from the ground up and lead major SIEM migration efforts
  • Technical Depth: Solve complex problems at scale with Modern security stack
  • Scale & Complexity: Protect a critical platform serving enterprise customers with sophisticated threats
  • Autonomy & Influence: Shape security architecture decisions, tool evaluations, and team direction
  • Growing Team: Join a growing team with clear structure, specialized roles, and growth trajectory
  • Balance & Variety: Split time between strategic architecture (detection, SOAR) and hands-on execution (hunting, investigation)
  • Innovation Culture: Implement detection-as-code, automation-as-code, and data-driven security practices

Important notice: We are an AI-driven company and actively use AI tools in our day-to-day work. However, the use of AI tools during the interview process is not permitted. Interviews are designed to assess your individual skills and thinking. If we determine that a candidate is using AI assistance to answer interview questions, this may result in disqualification from the hiring process.

For base compensation, we set standard ranges for all roles based on function and level benchmarked against similar stage growth companies and internal comparables. In order to be compliant with local legislation, as well as to provide greater transparency to candidates, we share salary ranges on all job postings regardless of desired hiring location. Final offer amounts are determined by multiple factors including candidate experience/expertise and may vary from the amounts listed below.

You may also be offered a performance-based bonus, equity, and a generous benefits program.

Base Compensation Range
$128,000$161,000 USD

AlphaSense is an equal-opportunity employer. We are committed to a work environment that supports, inspires, and respects all individuals. All employees share in the responsibility for fulfilling AlphaSense’s commitment to equal employment opportunity. AlphaSense does not discriminate against any employee or applicant on the basis of race, color, sex (including pregnancy), national origin, age, religion, marital status, sexual orientation, gender identity, gender expression, military or veteran status, disability, or any other non-merit factor. This policy applies to every aspect of employment at AlphaSense, including recruitment, hiring, training, advancement, and termination.

In addition, it is the policy of AlphaSense to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations, and ordinances where a particular employee works.

Recruiting Scams and Fraud

We at AlphaSense have been made aware of fraudulent job postings and individuals impersonating AlphaSense recruiters. These scams may involve fake job offers, requests for sensitive personal information, or demands for payment. Please note:

  • AlphaSense never asks candidates to pay for job applications, equipment, or training.
  • All official communications will come from an @alpha-sense.com email address.
  • If you’re unsure about a job posting or recruiter, verify it on our Careers page.

If you believe you’ve been targeted by a scam or have any doubts regarding the authenticity of any job listing purportedly from or on behalf of AlphaSense please contact us. Your security and trust matter to us.

Top Skills

AWS
Edr
GCP
Jupyter Notebooks
Osquery
Python
SIEM
Sigma
Soar
Velociraptor
Yara-L
HQ

AlphaSense New York, New York, USA Office

We are in the center of everything! We have a green market, restaurants, shops and more! Subways: N, Q, R W, L, 4, 5, 6 are within a block!

Similar Jobs

16 Days Ago
Remote
USA
180K-220K Annually
Senior level
180K-220K Annually
Senior level
Mobile • Social Media
Lead threat detection and incident response, optimize security tools, handle security incidents, oversee vSOC, and manage security awareness initiatives.
Top Skills: AWSAzureCnappEdrGCPGoKubernetesNdrOpenshiftPythonSIEM
49 Minutes Ago
Remote or Hybrid
Texas, USA
165K-235K Annually
Senior level
165K-235K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
The Senior Value Advisor engages with clients to demonstrate the economic impact of Zscaler solutions through financial modeling, TCO/ROI analysis, and business case presentations.
Top Skills: Cloud SolutionsCybersecurityExcelSaaS
49 Minutes Ago
Remote or Hybrid
Los Angeles, CA, USA
50K-58K Annually
Mid level
50K-58K Annually
Mid level
Fintech • Payments • Software
The Senior Client Experience Associate at Flywire will provide support to clients across various products and services through inbound inquiries, focusing on problem resolution and client education while collaborating with other teams.
Top Skills: Google SuiteLookerZendesk

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account