Incident Detection and Response Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

Total Quality Logistics ยท 3 weeks ago

Incident Detection and Response Engineer

Total Quality Logistics is a company focused on enhancing its incident detection and response capabilities. The Incident Detection & Response Engineer will design, build, and maintain systems and tools to support the Security Operations Center and Incident Response teams in effectively detecting and responding to threats.

Freight ServiceLogisticsTransportation
check
Growth Opportunities
badNo H1Bnote

Responsibilities

Deploy, configure, and maintain SIEM platforms, intrusion detection systems, and other SOC tools
Design and implement scalable detection logic and correlation rules in SIEM, EDR/XDR, and cloud-native security platforms
Build data pipelines and integrations to enrich security telemetry from endpoints, networks, and cloud sources
Ensure security monitoring tools collect accurate, actionable data
Collaborate with incident responders to codify behavioral analytics and detection logic using MITRE ATT&CK and other models
Create APIs, dashboards, and data visualizations to support threat hunting and incident triage
Continuously improve tooling performance, reliability, and usability through feedback from incident responders
Evaluate and integrate open-source and commercial security tools into the detection and response ecosystem
Contribute to red/purple team exercises by building simulation and detection validation tooling
Work with security leadership to define and track metrics for detection coverage, response time, alert fidelity, and tooling effectiveness
Develop and maintain detection-as-code frameworks using version control and CI/CD pipelines

Qualification

SIEM platformsIncident responsePythonCloud-native architecturesDetection engineering principlesAPI integrationsCollaboration skillsProblem-solving skillsCommunication skills

Required

Bachelor's degree in Computer Science, Software Engineering, or related field, or equivalent combination of education and experience
3+ years experience in incident response or security operations
Experience managing and maintaining security solutions, SIEM, log ingestion pipelines, and API integrations
Proficiency in Python, Go, Powershell, or similar languages used in security tooling
Strong understanding of cloud-native architectures (Azure, AWS, GCP) and associated security services
Familiarity with infrastructure-as-code (Terraform, Ansible) and CI/CD pipelines
Solid grasp of detection engineering principles and adversary techniques (MITRE ATT&CK, kill chain)
Knowledge of data streaming/search technologies (e.g., Kafka, Elasticsearch)

Preferred

Certifications such as GCDA, GCTI, or relevant cloud security credentials preferred

Benefits

Health, dental and vision coverage
401(k) with company match
Perks including employee discounts, financial wellness planning, tuition reimbursement and more

Company

Total Quality Logistics

company-logo
The logistics industry is a $500 billion market.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Rob Poulos
Chief Operating Officer
linkedin
leader-logo
Chris Brown
Chief Legal Officer
linkedin
Company data provided by crunchbase