Detection and Response Lead @One Identity
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted Today

[Hiring] Detection and Response Lead @One Identity

Today - One Identity is hiring a remote Detection and Response Lead. πŸ’Έ Salary: unspecified πŸ“Location: India

Role Description

One Identity builds the software that decides who gets into everything else our customers run, and the ground this practice defends is our own: the corporate environment and the hosted services we operate in the cloud. Coverage spans external attacks and insider threats across everything we run, and the detection work is shaped around that full range.

Twenty-four seven monitoring is handled by a managed provider, which means this is not a shift-rotation job. The provider covers first-line triage and escalates when needed. This role owns everything above the provider:

  • What gets detected in the first place
  • Whether the coverage matches how we're actually attacked
  • How good the escalations are
  • What happens once something real lands on the desk

Directing that relationship well is a large part of the work. We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role leads the detection and response practice inside it. Scope comes from what you build and from the standard you set for what a real incident response looks like here.

What you'll do

  • Own what gets detected
  • Set the strategy for detection use cases and own the catalog built from it:
    • Identity and authentication abuse
    • Privileged access misuse
    • Cloud control plane activity across Azure and AWS
    • Endpoint and email vectors
    • Paths specific to how our own products are deployed internally
  • Treat detections as code. Version them, review them, test them against real telemetry, and track coverage against a threat model rather than a vendor's rule count.
  • Own the signal quality problem end to end. Tune what's noisy, retire what's dead, and know which gaps are deliberate.
  • Set the telemetry standard. Decide what we need to collect and retain to investigate an incident properly, and make the case for it when that costs something.
  • Own the response
  • Lead incident response from escalation through closure:
    • Scoping
    • Containment
    • Evidence handling
    • Root cause
    • The write-up that survives a customer or auditor reading it
  • Direct the managed provider. Set escalation criteria, hold the quality bar on what comes through, and close the loop when something should have been caught and wasn't.
  • Run the exercises that make a response work under pressure:
    • Tabletops with engineering and leadership
    • The runbooks that make an on-call decision obvious at two in the morning
  • Own the notification path. Know which obligations attach to which kinds of incident, contractual and regulatory, and make sure the clock is understood before it's running.
  • Work with product security when an incident touches what we ship. Internal detection and customer-facing disclosure are different disciplines that occasionally share a root cause.
  • Make it scale
  • Decide where agentic workflows belong in detection and response. Enrichment, correlation, and first-pass investigation are tractable now; containment actions are a harder call.
  • Automate the response path itself, not just the alerting. The measure is how much of an investigation is already done by the time a person opens it.
  • Bring threat intelligence into the practice with an output attached:
    • Adversary tradecraft translated into detection use cases
    • Hunts
    • Control changes
  • Advance the program's metrics:
    • Coverage against the threat model
    • Escalation quality from the provider
    • Time to detect and time to close
  • Hunt on a schedule. Structured hypotheses against our own telemetry, and every finding either becomes a detection or gets written down as a deliberate gap.

Qualifications

  • Eight or more years in security operations, detection engineering, or incident response, with time spent leading incidents rather than only working them. Equivalent depth counts.
  • Detection engineering in a modern SIEM, with the query fluency to build and validate rules yourself. We run Microsoft Sentinel and Defender XDR.
  • Identity attack fluency. Entra ID and Active Directory attack paths, token and session abuse, OAuth consent, and federation.
  • Hands-on work with AI-assisted detection, triage, or investigation within the last six months, and a considered view on where automation should and shouldn't be trusted to act.

Requirements

  • Cloud detection across Azure and AWS control planes
  • Scripting and automation in Python or PowerShell
  • Managing or directing an MDR or managed SOC relationship
  • Forensic investigation and evidence handling
  • Writing that holds up when an executive or an auditor reads it

Helpful

  • Threat hunting from structured hypotheses
  • Insider risk detection
  • Container and Kubernetes runtime detection
  • SOAR or workflow automation platforms
  • Threat intelligence work with an operational output
  • Prior time on the engineering side

Company Description

One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.

  • With team members around the globe, we intend to continue to grow revenues and add value to customers.
  • When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.
  • Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.
  • Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.

Life at One Identity means collaborating with dedicated professionals with a passion for technology. When we see something that could be improved, we get to work inventing the solution. Our people demonstrate our winning culture through positive and meaningful relationships. We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential. Our team members’ health and wellness is our priority as well as rewarding them for their hard work.

One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.

Before You Apply
️
remote Be aware of the location restriction for this remote position: India
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Detection and Response Lead @One Identity
Information Technology
Salary unspecified
Remote Location
Employment Type full-time
Posted Today
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: India
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,118+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later