About the Team
The Tactical Operations team (TACOPS) handles the most time-critical tasks for all customers, executing the investigation and triage of high-priority security alerts using our cloud-hosted SIEM, InsightIDR. This collaborative team drives business and customer outcomes by combining individual technical skills with collective knowledge to identify threats and deliver robust remediation recommendations.
About the Role
As an Associate Detection & Response (MDR) Analyst, your primary responsibility will be to investigate and triage high-priority security alerts to identify malicious activity in customer environments. Specifically, your focus will be to:
- Review alert data to identify malicious activity and potential security threats across diverse customer environments
- Steer security investigations from initial alert through comprehensive evidence acquisition and root-cause analysis
- Write technical incident reports documenting key findings, analysis methodologies, and actionable remediation recommendations for customers
- Coordinate closely with SOC advisor colleagues to support effective communication of technical findings to the customer
- Partner with Mid, Senior, and Lead Analysts to collaboratively solve complex challenges and share knowledge across the SOC team
- Perform targeted investigation tasks and examine forensic artifacts during critical Remote Incident Response engagements
- Track threat actor actions across an environment by analyzing system and forensic logs during security incidents
- Maintain a flexible operational rhythm, working in the physical SOC two days per week (including Wednesdays) and adhering to the dedicated afternoon shift schedule
The skills and qualities you'll bring include:
- Adaptability to work a fixed shift rotation from Monday to Thursday, 11 AM - 9 PM, following a comprehensive 90-day onboarding period.
- Professional or academic experience spanning 0-2 years within technology, systems administration, or information security environments
- Foundational knowledge of core security concepts including lateral movement, privilege escalation, persistence methods, and command and control
- Working familiarity with Windows and Linux operating systems and their underlying security architectures
- Training in red team/blue team learning tools such as HackTheBox, TryHackMe, and LetsDefend and/or participation in CTF events is a plus
- Scripting/coding ability and/or Security Certifications (GFACT, GSEC, GCIA, GCIH, CySA+, CASP+, Security+, etc.) is a plus
- Creative problem-solving abilities, critical thinking capacity, and technical ingenuity when addressing complex challenges
- Insatiable curiosity and a strong forward focus, demonstrating a passionate commitment to learning and developing your cybersecurity craft
- Eagerness and open communication when navigating change, adapting smoothly to evolving business needs, shift structures, and group dynamics
- Capacity to make efficient, structured choices that resolve challenges and maintain analytical momentum during high-pressure incidents
- Clear accountability for actions and behaviors while driving outcomes that deliver genuine value for the business and our customers
- Core Value Embodiment: Embody our core values to foster a culture of excellence that drives meaningful impact and collective success
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-SIM
#LI-SIM
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
Skills Required
- 0-2 years of experience in technology, systems administration, or information security
- Foundational knowledge of core security concepts
- Familiarity with Windows and Linux operating systems
- Training in red team/blue team learning tools
- Scripting/coding ability and/or relevant security certifications
Rapid7 Compensation & Benefits Highlights
-
Inclusive Benefits Coverage — Health plans and policies explicitly include mental‑health resources, transgender‑inclusive care, abortion‑travel support, neurodiversity coverage, and backup childcare/fertility benefits. These offerings sit alongside core medical, dental, and vision coverage and optional pet insurance.
-
Leave & Time Off Breadth — U.S. employees are offered unlimited PTO, unlimited sick leave, paid volunteer time, company holidays, and additional global recharge days. Wellness days and bereavement leave complement hybrid‑first flexibility.
-
Equity Value & Accessibility — An Employee Stock Purchase Plan is available with semiannual purchase periods, and many roles include company equity/RSUs. This ownership mix is complemented by performance bonuses and stated pay‑transparency practices in benefits listings.
Rapid7 Insights
What We Do
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.
Why Work With Us
With our products, research, and open source communities, we’re building a secure digital future for everyone. This means constantly learning and evolving in an industry that’s anything but stagnant. You’ll be faced with tough challenges, and given the support to find creative solutions that drive our business, and your career forward.
Gallery
Rapid7 Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Our default working model is hybrid, with employees working three days per week in the office. This approach underpins our commitment to flexibility and adaptability while supporting our dedication to development, teamwork and customer purpose.

.jpg)


.jpg)







