Leading investigations end-to-end, the full-time remote Incident Responder will manage security incidents, conduct threat hunts, and enhance detection capabilities while collaborating with cross-functional teams and external partners. Key responsibilities Own security incidents by validating MSSP escalations, leading investigations, and coordinating response efforts Conduct proactive threat hunts across cloud and endpoint telemetry to improve detection coverage and fidelity Build and tune detection content in Microsoft Sentinel, collaborating closely with the Detection Engineering team Required qualifications Proven experience in incident response and security operations in cloud-native environments, particularly with Azure and AWS Experience with Microsoft Sentinel or a comparable SIEM for investigation and detection engineering Experience managing escalations with an MSSP and providing quality feedback to improve coverage Strong understanding of attacker tactics, techniques, and procedures, including familiarity with the MITRE ATT&CK framework Commitment to continuous improvement in operational processes and security tooling