Rapid7 Logo

Rapid7

Lead Detection & Response Analyst

Posted 2 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in Arlington, VA
Senior level
Remote or Hybrid
Hiring Remotely in Arlington, VA
Senior level
Leads complex cybersecurity investigations and incident response across a global 24/7 MDR SOC. Develops investigative methods, directs containment and remediation, identifies detection gaps, improves workflows through automation, produces technical intelligence reports, mentors analysts, and partners with engineering, product, and platform teams to strengthen defense capabilities.
The summary above was generated by AI
Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world. Our SOC operates with an impact-driven mindset focused on identifying meaningful threats and delivering actionable outcomes for our customers.
About the Team
Rapid7's Managed Detection and Response (MDR) Security Operations Center delivers 24/7 continuous monitoring, threat hunting, and sophisticated incident response for global organizations. The team focuses on stopping adversary activity, elevating technical standards, and driving actionable security outcomes.
About the Role
As a Lead Detection & Response Analyst, your primary responsibility will be to serve as a high-level technical lead and driver of technical excellence across global SOC operations. Specifically, your focus will be to:
  • Lead the response to high-impact, novel, or highly complex security threats.
  • Develop new investigative methodologies for emerging attack vectors where established methods do not exist.
  • Serve as the primary technical escalation point for the global SOC, directing containment and remediation strategies.
  • Identify systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities.
  • Architect and refine investigative workflows to leverage advanced tooling and automation.
  • Author advanced technical intelligence reports and advisories for executive leadership and customers.
  • Mentor and grow the technical bench strength of the SOC through high-level coaching and technical workshops.
  • Influence product and platform direction by providing expert feedback to engineering teams.

The skills and qualities you'll bring include
  • Bring 8+ years of cybersecurity operations, Incident Response, or Digital Forensics experience in a high-maturity SOC/MDR environment.
  • Demonstrate expert-level mastery of the MITRE ATT&CK framework to build behavioral detection strategies.
  • Apply deep forensic expertise across Endpoint, Cloud, Identity, and Network domains, including log analysis and malware triage.
  • Drive complex technical projects from conception to completion across global teams.
  • Direct containment strategies efficiently during high-stakes customer compromises to maintain momentum and resolve challenges.
  • Articulate complex attacker TTPs and long-term security strategies clearly to technical engineers and C-level executives.
  • Build cross-functional alignment with Detection Engineering, Product, and Platform teams to deliver sustainable defense capabilities.
  • Mentor and coach analysts across the global SOC, setting clear expectations for investigative quality.
  • Adapt to evolving adversary techniques by driving forward-looking investigative practices.
  • Hold advanced industry certifications such as GCFA, GCTI, GREM, or OSCP.
  • Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Similar Jobs at Rapid7

2 Hours Ago
Remote or Hybrid
Mid level
Mid level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Investigate and respond to security threats across endpoint, identity, cloud, and network environments. Triage alerts, analyze telemetry, investigate malware and unauthorized access incidents, document findings using MITRE ATT&CK, recommend remediation, identify detection gaps, and collaborate with senior analysts and customer advisors while meeting service-level objectives.
Top Skills: EdrLinuxMitre Att&CkNdrSIEMWindows
2 Hours Ago
Remote or Hybrid
United States
82K-110K Annually
Entry level
82K-110K Annually
Entry level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Investigate security alerts and incidents by collecting and analyzing evidence, identifying intrusion vectors and malicious activity, documenting findings, tracking remediation, and conducting threat hunting. The role also analyzes forensic artifacts, researches attack methodologies, improves detection capabilities, collaborates with product development teams, and provides technical feedback to strengthen organizational security.
Top Skills: LinuxmacOSRapid7 Command PlatformSIEMSplunkWindows
Yesterday
Remote or Hybrid
United States
191K-258K Annually
Expert/Leader
191K-258K Annually
Expert/Leader
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Architects and delivers foundational systems for an autonomous security investigation platform supporting MDR. Responsibilities include distributed data pipelines, query engines, orchestration, ML model infrastructure, scalability, reliability, observability, technical standards, design reviews, mentorship, and cross-team architecture. The role partners with ML, product, data science, and platform teams to solve complex technical problems across real-time security operations.
Top Skills: Amazon S3AWSData MeshDistributed Query EnginesDynamoDBEmbedding SystemsFlinkKafkaLlmsMl/Ai

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account