Post a job

Detection and Response Lead

One Identity · India · posted today ago

Apply for this role

engineeringremote jobs in india
Listing supplied by Himalayas. 101 Careers did not originate this post and applications are handled by the employer.

About this role

Overview

Detection and Response Lead

One Identity · Information Security, Cyber Defense

Senior individual contributor, practice lead · India · Reports to the Director of Information Security

Why this role exists

One Identity builds the software that decides who gets into everything else our customers run, and the ground this practice defends is our own: the corporate environment and the hosted services we operate in the cloud. Coverage spans external attacks and insider threats across everything we run, and the detection work is shaped around that full range.

Twenty-four seven monitoring is handled by a managed provider, which means this is not a shift-rotation job. The provider covers first-line triage and escalates when needed. This role owns everything above the provider: what gets detected in the first place, whether the coverage matches how we're actually attacked, how good the escalations are, and what happens once something real lands on the desk. Directing that relationship well is a large part of the work.

We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role leads the detection and response practice inside it. Scope comes from what you build and from the standard you set for what a real incident response looks like here.

What you'll do

Own what gets detected

Own the response

Make it scale

What we're looking for

Required

Eight or more years in security operations, detection engineering, or incident response, with time spent leading incidents rather than only working them. Equivalent depth counts.

The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us.

Also matters: cloud detection across Azure and AWS control planes; scripting and automation in Python or PowerShell; managing or directing an MDR or managed SOC relationship; forensic investigation and evidence handling; writing that holds up when an executive or an auditor reads it.

Helpful: threat hunting from structured hypotheses; insider risk detection, container and Kubernetes runtime detection, SOAR or workflow automation platforms, threat intelligence work with an operational output, prior time on the engineering side.

What you should know going in

This is a practice to build, not a queue to work. The managed tier handles the volume, which leaves you the engineering and the judgment: what we detect, how well, and what happens next. You'll have functional direction of the SOC analysts, with people leadership held by the director, and direct access to engineering leadership. Your incident write-ups will be read at the executive level. If you want to own a detection and response practice rather than inherit someone else's rules, this is that seat.

Company Description

One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward.

With team members around the globe, we intend to continue to grow revenues and add value to customers.

When you join our team, you will have the opportunity to build and develop products at a scale few others can provide.

Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses.

Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment.

Why work with us?

Life at One Identity means collaborating with dedicated professionals with a passion for technology.

When we see something that could be improved, we get to work inventing the solution.

Our people demonstrate our winning culture through positive and meaningful relationships.

We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential.

Our team members’ health and wellness is our priority as well as rewarding them for their hard work.

One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.

All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.

One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages.

Come join us.

Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com.

Originally posted on Himalayas

Similar remote engineering jobs

Browse all remote engineering jobs →

Detection and Response Lead at One Identity — Remote | 101 Careers