Blackstone is hiring an Alert, Detection, and Response Associate for onsite incident response and detection engineering work in Miami, FL.
Responsibilities
- Manage an incident queue from intake through investigation, containment, and closure across domains including email, endpoint, identity, network, and cloud
- Own Tier 1 escalations by taking over complex investigations and bringing in additional responders as scope expands
- Investigate security activity in the firm’s SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry
- Perform endpoint investigation and live response in the firm’s EDR, including process lineage review, persistence assessment, and artifact collection
- Investigate email threats end to end, covering phishing, business email compromise, and malicious attachments and links
- Use header and message trace analysis to determine who was targeted and drive remediation across impacted mailboxes
- Investigate cloud and identity compromise, including credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass
- Scope suspected third-party and SaaS provider compromises by coordinating with the provider’s incident response team to confirm containment and affected Blackstone data
- Independently hunt for provider indicators across endpoint, email, network, and cloud telemetry, coordinating findings and remediation with legal and compliance, vendor risk, and business owners
- Serve as a core incident response team member: scope intrusions, drive containment and eradication, brief stakeholders, and upscale per the severity model
- Turn investigation outcomes into detections by authoring and tuning detection logic, validating against historical and live data, moving through review into production, and confirming acceptable signal quality
- Collaborate with agentic AI investigation tooling during first-pass triage and enrichment by evaluating outputs, escalating incorrect conclusions, and feeding back corrections to improve coverage
- Help expand detection and response coverage as the firm increases use of AI across a fast-moving attack surface
- Convert repeatable investigation and response work into durable automation to reduce repetitive steps and reduce false positives
- Mentor Tier 1 analysts on investigation technique via case reviews and hands-on coaching
- Document investigations and incidents with evidence handling and chain of custody practices, communicating clearly to technical teams and senior stakeholders
- Contribute to threat hunts and purple team exercises, using red team activity and threat intelligence to identify gaps
- Participate in incident response and SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents
Requirements
- 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
- Proven ability to run end-to-end security investigations from alert through root cause, containment, and resolution in a SOC or incident response environment
- Hands-on SIEM experience, including writing and troubleshooting queries; experience with a major enterprise SIEM and native query language (Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)
- Hands-on EDR experience performing endpoint investigation and containment using a leading EDR platform (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint)
- Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, and SSO, plus identity providers such as Okta or Microsoft Entra ID
- Practical understanding of attacker behavior across the intrusion lifecycle: phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
- Familiarity with security technologies used in investigations, including email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data
- Working knowledge of MITRE ATT&CK and experience mapping observed activity to techniques
- Experience scripting in Python and/or PowerShell for enrichment, parsing, and automating repetitive analysis
- Hands-on experience using AI tooling in real work, with detailed examples and the judgment to identify untrustworthy outputs
- Clear technical writing skills for explaining incidents and impact to both engineers and non-technical stakeholders
- Ability to self-organize, prioritize under time pressure, and maintain accuracy during live incidents
Technologies
- SIEM: Splunk/SPL, Microsoft Sentinel/KQL, Elastic
- EDR: CrowdStrike, SentinelOne, Microsoft Defender for Endpoint
- Identity: Okta, Microsoft Entra ID
- MITRE ATT&CK, Python, PowerShell
- AI tools and agentic AI investigation tooling
- Email security, DLP, MFA bypass
- SIEM correlation searches
Benefits
- Comprehensive health benefits, including medical, dental, vision, and FSA
- Paid time off
- Life insurance
- 401(k) plan
- Discretionary bonuses
- Certain employees may be eligible for equity and other incentive compensation at Blackstone’s sole discretion
Preferred Qualifications
- Detection engineering experience such as authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and measuring whether detections work
- Detection-as-code experience, including Git-based workflows, peer review, and CI validation of detection content
- SOAR automation experience with tools such as Torq, Splunk SOAR, or Tines
- Digital forensics capability in memory, disk, or network analysis, or hands-on malware triage and sandboxing
- Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
- Threat hunting experience, especially hypothesis-driven hunts against endpoint or cloud telemetry
- Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) and how its logging, identity, and access services support investigations
- Experience in financial services or another heavily regulated, globally distributed environment
- At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
- B.S. in Computer Science, Cybersecurity, Information Systems, or a related technical field
Compensation & Location
- Location: Miami, FL (onsite)
- Expected annual base salary range: $110,000 - $170,000
- Minimum experience: 2 years
Alert, Detection, and Response Engineer, Associate in miami at Unknown Company
This position is listed as full time and onsite.