Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity

Posted 8 Days Ago
Miami, FL, USA
In-Office
110K-170K Annually
Junior
Fintech
The Role
Investigates and responds to Tier 2 cybersecurity incidents across email, endpoints, identity, networks, and cloud. Manages cases from alert through containment and closure, conducts SIEM and EDR investigations, handles phishing and identity compromise, and coordinates third-party breach response. Authors detections, improves playbooks and automation, evaluates AI-assisted investigations, mentors Tier 1 analysts, documents evidence, supports threat hunts and purple-team exercises, and participates in an approximately quarterly SOC on-call rotation.
Summary Generated by Built In

Blackstone is the world’s largest alternative asset manager. Blackstone seeks to deliver compelling returns for institutional and individual investors by strengthening the companies in which the firm invests. Blackstone’s over $1.3 trillion in assets under management include global investment strategies focused on real estate, private equity, credit, infrastructure, life sciences, growth equity, secondaries and hedge funds. Further information is available at www.blackstone.com. Follow @blackstone on LinkedIn, X (Twitter), and Instagram. 

Business Unit Overview: 

Blackstone Technology & Innovations (BXTI) is the technology team at the core of each of Blackstone's businesses and new growth initiatives. Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency and improve transparency within the firm and across our broad community of investors and portfolio companies. 

BXTI is fast paced and entrepreneurial: our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one. We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence. We collaborate to find the best answers for our customers and for Blackstone. We are critical to the firm maintaining its competitive edge. 

Position Overview: 

The Alert, Detection, and Response Associate is a Tier 2 incident responder on the Alert, Detection & Response team, the front line of Blackstone's cyber defense. The Associate is responsible for detecting, investigating, and responding to information security incidents across, but not limited to, email, endpoint, identity, network, and cloud. The Associate must have strong working knowledge of incident response procedures, the technology used to execute them, as well as an understanding of how to leverage AI tools effectively. The Associate manages an incident queue, carrying cases from intake through investigation, containment, and closure, and handles the escalations raised by Tier 1 analysts. Day to day the Associate works alongside the Tier 1 and Tier 2 incident response analysts on the team, taking on the harder cases and bringing in additional responders as an investigation grows. 

The Associate is also expected to turn what each case teaches the team into lasting improvement, feeding findings back into detections, playbooks, and automation so the same problem does not have to be worked twice. Analysts and Associates on this team are expected to play an active role in shaping investigative processes and detection capabilities, with the opportunity to see innovative ideas quickly translated into operational solutions. 


Responsibilities: 

  • Manage an incident queue, carrying cases from intake through investigation, containment, and closure across, but not limited to, email, endpoint, identity, network, and cloud 
  • Handle escalations raised by Tier 1 analysts, taking on the more complex investigations and bringing in additional responders as scope grows 
  • Investigate in the firm's SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry 
  • Conduct endpoint investigation, host containment, and live response in the firm's EDR platform, including process lineage, persistence review, and artifact collection 
  • Investigate email threats end to end, covering phishing, business email compromise, and malicious attachments and links, using header and message trace analysis to scope who was targeted and drive remediation across affected mailboxes 
  • Investigate cloud and identity compromise, covering credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass 
  • Investigate third-party and SaaS provider compromise, questioning the provider's incident response team to establish containment status and what Blackstone data was affected, independently scoping the firm's exposure by hunting provider indicators across endpoint, email, network, and cloud telemetry, and coordinating findings and remediation with legal and compliance, vendor risk, and the business owners of the affected service 
  • Serve as a core member of the incident response team, scoping intrusions, driving containment and eradication, briefing stakeholders, and escalating in line with the firm's severity model 
  • Author and tune detections from investigation findings, developing the logic and validating it against historical and live data, then taking it through review into production and confirming afterward that it fires on real activity without generating unacceptable noise 
  • Work alongside agentic AI investigation tooling on first-pass triage and enrichment, judging its conclusions, escalating what it gets wrong, and feeding corrections back so coverage improves 
  • Help extend detection and response coverage across the firm's growing use of AI, an emerging and fast-moving part of the attack surface 
  • Turn investigation findings into lasting coverage by authoring and tuning detections, reducing false positives on noisy ones, and building automation that removes repetitive steps from triage, enrichment, and response 
  • Mentor Tier 1 analysts on investigation technique, sharing tradecraft through case reviews and hands-on coaching 
  • Document investigations and incidents to a standard that holds up under scrutiny, maintain evidence handling and chain of custody, and communicate findings clearly to technical teams and senior stakeholders 
  • Contribute to threat hunts and purple team exercises, using red team activity and threat intelligence to find gaps before an adversary does 
  • Participate in incident response and the SOC on-call rotation (occasional, roughly quarterly) to respond to escalated security incidents 

Qualifications: 

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role 
  • Demonstrated experience running security investigations end to end, from alert through root cause and containment, in a SOC or IR setting 
  • Hands-on SIEM experience with experience writing and troubleshoot your own queries; experience with a major enterprise SIEM and its native query language (for example Splunk/SPL, Microsoft Sentinel/KQL, or Elastic)  
  • Hands-on EDR experience conducting endpoint investigation and containment; experience with a leading EDR platform (for example CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint) 
  • Working knowledge of cloud and identity investigation, including cloud audit logging, IAM, and SSO, and identity providers such as Okta or Microsoft Entra ID 
  • Practical understanding of attacker behavior across the intrusion lifecycle, including phishing and business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration 
  • Familiarity with the security technologies an investigation touches: email security, endpoint protection, proxies and firewalls, DLP, and vulnerability data 
  • Working knowledge of MITRE ATT&CK and experience mapping observed activity to technique 
  • Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation of repetitive analysis 
  • Demonstrated hands-on use of AI tooling in real work, with experience speaking in detail about several projects, professional or otherwise, where you used AI to automate or accelerate a task, and sound judgment about where its output cannot be trusted 
  • Clear technical writing, with experience explaining an incident and its impact to both engineers and non-technical stakeholders 
  • Experience self-organizing, prioritizing under time pressure, and staying accurate during a live incident 

Preferred Qualifications:

  • Detection engineering experience: authoring or tuning SIEM correlation searches, EDR custom rules, or Sigma content, and measuring whether a detection actually works
  • Experience with detection-as-code practices, including Git-based workflows, peer review, and CI validation of detection content
  • SOAR automation experience (Torq, Splunk SOAR, Tines, or similar)
  • Digital forensics capability in memory, disk, or network analysis, or hands-on malware triage and sandboxing
  • Experience with agentic AI or LLM-assisted security tooling, and with AI security monitoring platforms
  • Threat hunting experience, particularly hypothesis-driven hunts against endpoint or cloud telemetry
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP), including how its logging, identity, and access services are used to investigate activity in the environment
  • Experience in financial services or another heavily regulated, globally distributed environment
  • At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
  • B.S. in Computer Science, Cybersecurity, Information Systems, or a related technical field


The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position.  Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.

Expected annual base salary range:

$110,000 - $170,000

Actual base salary within that range will be determined by several components including but not limited to the individual's experience, skills, qualifications and job location. For roles located outside of the US, please disregard the posted salary bands as these roles will follow a separate compensation process based on local market comparables.
Additional compensation and benefits offered in connection with the role consist of comprehensive health benefits, including but not limited to medical, dental, vision, and FSA benefits; paid time off; life insurance; 401(k) plan; and discretionary bonuses. Certain employees may also be eligible for equity and other incentive compensation at Blackstone’s sole discretion.

Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws. This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training.  All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.

If you need a reasonable accommodation to complete your application, please contact Human Resources at 212-583-5000 (US), +44 (0)20 7451 4000 (EMEA) or +852 3656 8600 (APAC).

Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and/or if you are engaged in the following:

  • Attending client meetings where you are discussing Blackstone products and/or and client questions;

  • Marketing Blackstone funds to new or existing clients;

  • Supervising or training securities licensed employees;

  • Structuring or creating Blackstone funds/products; and

  • Advising on marketing plans prepared by a sales team or developing and/or contributing information for marketing materials.

Note: The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis.  Please speak with your Blackstone Recruiting contact with any questions.
To submit your application please complete the form below. Fields marked with a red asterisk * must be completed to be considered for employment (although some can be answered "prefer not to say"). Failure to provide this information may compromise the follow-up of your application. When you have finished click Submit at the bottom of this form.

Skills Required

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role
  • Experience running security investigations end to end, from alert through root cause and containment, in a SOC or incident response setting
  • Hands-on SIEM experience writing and troubleshooting queries using an enterprise SIEM and native query language such as Splunk SPL, Microsoft Sentinel KQL, or Elastic
  • Hands-on EDR experience conducting endpoint investigation and containment
  • Working knowledge of cloud and identity investigations, cloud audit logging, IAM, SSO, Okta, or Microsoft Entra ID
  • Understanding of attacker behavior including phishing, business email compromise, credential theft, privilege escalation, lateral movement, persistence, and exfiltration
  • Familiarity with email security, endpoint protection, proxies, firewalls, DLP, and vulnerability data
  • Working knowledge of MITRE ATT&CK and experience mapping activity to techniques
  • Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation
  • Hands-on use of AI tooling in real work and judgment about where AI output cannot be trusted
  • Clear technical writing and ability to explain incidents and impacts to technical and non-technical stakeholders
  • Ability to self-organize, prioritize under time pressure, and remain accurate during live incidents
  • Detection engineering experience authoring or tuning SIEM correlation searches, EDR rules, or Sigma content
  • Experience measuring detection effectiveness
  • Experience with detection-as-code, Git workflows, peer review, and CI validation
  • SOAR automation experience with Torq, Splunk SOAR, Tines, or similar
  • Digital forensics experience in memory, disk, or network analysis, or malware triage and sandboxing
  • Experience with agentic AI or LLM-assisted security tooling and AI security monitoring platforms
  • Threat hunting experience, particularly hypothesis-driven hunts using endpoint or cloud telemetry
  • Working knowledge of AWS, Azure, or GCP logging, identity, and access services
  • Experience in financial services or another heavily regulated, globally distributed environment
  • An active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related technical field

Blackstone Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Blackstone and has not been reviewed or approved by Blackstone.

  • Parental & Family Support — Primary‑caregiver leave is described at roughly 20 weeks with secondary‑caregiver and adoption options, alongside fertility and family‑planning resources. Backup care, nursing support, and phased return programs are also highlighted.
  • Wellbeing & Lifestyle Benefits — Day‑to‑day perks include free or subsidized meals and wellness resources such as fitness partnerships and meditation apps. Employee networks and structured learning programs are emphasized as part of the overall benefits experience.
  • Career-Linked Recognition & Rewards — Pay is considered competitive with meaningful performance‑linked bonuses in investing and select tech roles. Market positioning for investment talent and role‑aligned upside (including potential carry) are noted as important drivers.

Blackstone Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
4,671 Employees
Year Founded: 1985

What We Do

Blackstone is one of the world’s leading investment firms. We seek to create positive economic impact and long-term value for our investors, the companies we invest in and the communities in which we work. We do this by using extraordinary people and flexible capital to help companies solve problems. Our asset management businesses include investment vehicles focused on private equity, real estate, public debt and equity, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis. Further information is available at www.blackstone.com. Follow Blackstone on Twitter @Blackstone.

Similar Jobs

Comcast Logo Comcast

Sales Representative

Digital Media • Information Technology • News + Entertainment
Hybrid
Tampa, FL, USA
115000 Employees
100K-250K Annually
In-Office or Remote
2 Locations
175633 Employees
133K-284K Annually

PwC Logo PwC

Salesforce Marketing Cloud Consulting Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
63 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

Delina Privileged Access Management - Sr Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
22 Locations
370000 Employees
77K-202K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account