Detection and Response Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in US
Remote
100K-145K Annually
Mid level
eCommerce • Fintech • Payments • Software • Financial Services
Join our mission to build the largest suite of credit card processing and merchant services.
The Role
Design, tune, and maintain detection content across endpoint, network, cloud, and identity sources. Triage and investigate incidents, perform forensics, and run post-incident reviews. Build AI-enabled SOC workflows, pilot LLM tools, and automate response with SOAR and scripts. Partner with cloud, network, and identity teams to close visibility gaps and document policies, playbooks, and detection coverage.
Summary Generated by Built In

Detection and Response Engineer

North - Remote

Applicants located in the East and Central time zones will receive preferred consideration.

North is a US based company and this role is not eligible for current or future sponsorship.

The Detection and Response Engineer is responsible for the day-to-day engineering, tuning, and improvement of North's detection and response capability.

The role covers four core areas: detection engineering, incident response, AI-enabled SOC operations,
and security automation. This role works closely with the SOC, IT, and engineering teams to close visibility gaps, reduce manual analyst effort, and shorten the time between detection and resolution across our payment processing environment.

Essential Duties and Responsibilities

Detection Engineering
• Design, build, and tune detection content (rules, correlation searches, use cases) across endpoint, network, cloud, and identity log sources
• Perform ongoing coverage and gap analysis against the MITRE ATT&CK framework and actual log source volume, prioritizing based on real attack surface
• Validate detection logic against real-world attack techniques from cyber threat intelligence and reduce false- positive rates without sacrificing efficacy
• Maintain and version-control the detection rule repository, including documentation of coverage and known gaps

Incident Response
• Triage, investigate, and contain security incidents and alerts across the environment
• Conduct root cause analysis and structured post-incident reviews, feeding findings back into detection engineering
• Document incident timelines, indicators of compromise, and remediation actions
• Support forensic investigation of compromised hosts, accounts, and applications
• Participate in on-call rotation for critical incident response as needed
 

AI-Enabled SOC
• Evaluate, pilot, and implement AI/LLM-powered tools for alert triage, enrichment, and analyst workflows
• Build and tune AI-assisted investigation and detection workflows to reduce analyst workload and mean time to respond (MTTR)
• Identify high-value use cases for AI and automation while measuring the resulting impact

• Apply sound judgment about where AI-generated output requires human validation, particularly for high-confidence detections and containment actions
 

Automation
• Develop automation and orchestration (SOAR, scripts, APIs) to streamline detection, enrichment, and response workflows
• Automate repetitive SOC and IR tasks, such as evidence gathering, enrichment, and ticketing, to reduce manual toil
• Build and maintain playbooks and runbooks for common incident types
• Write and maintain scripts (Python or similar) that integrate security tooling and data sources

Additional Cross-Functional Responsibilities
• Partner with cloud, network, and identity teams to close visibility and telemetry gaps
• Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment
• Communicate findings, coverage gaps, and recommendations clearly to both technical and non-technical stakeholders
• Develop and maintain procedure and policy documentation supporting detection and response operations

Required Education and Experience
• Bachelor's degree in a technical field, or equivalent professional experience
• 3–5 years of hands-on information security experience, with demonstrated depth in at least two of: detection
engineering, incident response, security automation, or SOC operations
• Hands-on experience writing, tuning, or maintaining detection content in a SIEM or NG-SIEM platform (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel)
• Experience with EDR/XDR platforms and log analysis across diverse sources: endpoint, network, cloud, and identity
• Working knowledge of the MITRE ATT&CK framework and its practical application to detection engineering and gap analysis
• Scripting or automation experience (Python, PowerShell, or similar) applied to security use cases AND/OR experience using LLM coding tools such as Claude Code, Gemini CLI, or Codex.
• Solid understanding of networking, cloud infrastructure (AWS especially, but also Azure and GCP), Windows/Linux systems, and identity platforms
• Working knowledge of PCI-DSS or a comparable compliance framework
• Excellent written and verbal communication skills, including the ability to translate technical findings for non- technical stakeholders

Certifications (nice to have, but not required)
Relevant hands-on experience is weighted more heavily than certifications for this role. Any of the
following are a plus:
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Forensic Analyst (GCFA)

• Offensive Security Certified Professional (OSCP)
• Offensive Security Incident Response (OSIR)
• CompTIA CySA+
• CompTIA CASP+

Additional Preferred Beneficial Skills
• SOAR platform experience (e.g., N8N, Tines)
• Experience integrating or building with LLM/AI APIs for security use cases
• Cloud-native security tooling (AWS GuardDuty, Microsoft Sentinel, Google Security Command Center)
• Threat intelligence platform experience
• Digital forensics tooling and methodology
• Purple team or adversary emulation experience
• Familiarity with the payments/fintech regulatory environment

Salary range: $100,000-$145,000

Pay within this range varies by work location and on job-related knowledge, skills, and experience. We look forward to discussing your salary expectations and our full total rewards offerings throughout the interview process.

Please note: North is a US based company and no sponsorship is available for this position at this time.

Who we are: 

North, and our family of companies, are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else.

Let’s go North, together! Our most important resource is our people. Join our diverse team of innovators and do-ers and make your mark on the future of payments technology. We're proud to offer benefits that help our team members further their overall well-being through unique initiatives that are both personally and professionally fulfilling. 

At North, we celebrate diversity and create an inclusive environment for everyone. We are an equal opportunity employer.

To learn more about North, and our family of companies, visit our website: north.com

Skills Required

  • Bachelor's degree in a technical field or equivalent experience
  • 3-5 years hands-on information security experience with depth in detection engineering, incident response, security automation, or SOC operations
  • Hands-on experience writing, tuning, or maintaining detection content in a SIEM or NG-SIEM (e.g., CrowdStrike NG-SIEM, Splunk, Microsoft Sentinel)
  • Experience with EDR/XDR platforms and log analysis across endpoint, network, cloud, and identity sources
  • Working knowledge and practical application of the MITRE ATT&CK framework
  • Scripting or automation experience (Python, PowerShell, or similar) and/or experience using LLM coding tools (Claude Code, Gemini CLI, Codex) applied to security use cases
  • Solid understanding of networking, cloud infrastructure (AWS, Azure, GCP), Windows/Linux systems, and identity platforms
  • Working knowledge of PCI-DSS or comparable compliance framework
  • Excellent written and verbal communication skills, able to explain technical findings to non-technical stakeholders
  • GIAC GCIH, GCFA, OSCP, OSIR, CompTIA CySA+, CompTIA CASP+ (certifications listed as a plus)
  • SOAR platform experience (e.g., N8N, Tines)
  • Experience integrating or building with LLM/AI APIs for security use cases
  • Cloud-native security tooling experience (AWS GuardDuty, Microsoft Sentinel, Google Security Command Center)
  • Threat intelligence platform and digital forensics tooling experience
  • Purple team or adversary emulation experience and familiarity with payments/fintech regulatory environment
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Troy, MI
1,300 Employees
Year Founded: 1992

What We Do

NorthAB, LLC (North) and its subsidiaries are committed to helping entrepreneurs grow their businesses. As an end-to-end payment solutions company, we provide everything business owners need to get paid, whether they serve customers in a physical storefront, online, or both. We pride ourselves on being large enough to offer customized solutions to our enterprise-level clients while remaining agile enough to take an award-winning, hands-on approach to personal service that our merchants won’t find anywhere else. At North, we point the way to smarter, faster, and just plain better payment solutions. Let’s go North, together!

Why Work With Us

At North, we put a clear focus on team member well-being, both personally and professionally. We offer Flexible PTO and Work by Choice policies (i.e. work remotely, in office, or hybrid) that create the flexibility our team members need to do their best work.

Gallery

Gallery

Similar Jobs

Coalfire Logo Coalfire

Detection and Response Engineer

Cloud • Security • Cybersecurity
Remote
United States
1062 Employees
80K-134K Annually

Circle Logo Circle

Security Engineer

Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
In-Office or Remote
7 Locations
1050 Employees
123K-165K Annually

Liftoff Logo Liftoff

Security Engineer

AdTech • Artificial Intelligence • Big Data • Machine Learning • Marketing Tech • Mobile • Software
Easy Apply
Remote
United States
645 Employees
172K-240K Annually

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account