Lead Detection & Response Analyst

Posted 5 Hours Ago
Be an Early Applicant
Hiring Remotely in Arlington, VA, USA
Remote or Hybrid
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Take Command of your Career
The Role
Leads complex cybersecurity investigations and incident response across a global 24/7 MDR SOC. Develops investigative methods, directs containment and remediation, identifies detection gaps, improves workflows through automation, produces technical intelligence reports, mentors analysts, and partners with engineering, product, and platform teams to strengthen defense capabilities.
Summary Generated by Built In
Rapid7's Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world. Our SOC operates with an impact-driven mindset focused on identifying meaningful threats and delivering actionable outcomes for our customers.
About the Team
Rapid7's Managed Detection and Response (MDR) Security Operations Center delivers 24/7 continuous monitoring, threat hunting, and sophisticated incident response for global organizations. The team focuses on stopping adversary activity, elevating technical standards, and driving actionable security outcomes.
About the Role
As a Lead Detection & Response Analyst, your primary responsibility will be to serve as a high-level technical lead and driver of technical excellence across global SOC operations. Specifically, your focus will be to:
  • Lead the response to high-impact, novel, or highly complex security threats.
  • Develop new investigative methodologies for emerging attack vectors where established methods do not exist.
  • Serve as the primary technical escalation point for the global SOC, directing containment and remediation strategies.
  • Identify systemic visibility gaps and partner with Detection Engineering to prioritize high-fidelity defense capabilities.
  • Architect and refine investigative workflows to leverage advanced tooling and automation.
  • Author advanced technical intelligence reports and advisories for executive leadership and customers.
  • Mentor and grow the technical bench strength of the SOC through high-level coaching and technical workshops.
  • Influence product and platform direction by providing expert feedback to engineering teams.

The skills and qualities you'll bring include
  • Bring 8+ years of cybersecurity operations, Incident Response, or Digital Forensics experience in a high-maturity SOC/MDR environment.
  • Demonstrate expert-level mastery of the MITRE ATT&CK framework to build behavioral detection strategies.
  • Apply deep forensic expertise across Endpoint, Cloud, Identity, and Network domains, including log analysis and malware triage.
  • Drive complex technical projects from conception to completion across global teams.
  • Direct containment strategies efficiently during high-stakes customer compromises to maintain momentum and resolve challenges.
  • Articulate complex attacker TTPs and long-term security strategies clearly to technical engineers and C-level executives.
  • Build cross-functional alignment with Detection Engineering, Product, and Platform teams to deliver sustainable defense capabilities.
  • Mentor and coach analysts across the global SOC, setting clear expectations for investigative quality.
  • Adapt to evolving adversary techniques by driving forward-looking investigative practices.
  • Hold advanced industry certifications such as GCFA, GCTI, GREM, or OSCP.
  • Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
#LI-TD1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Skills Required

  • 8+ years of cybersecurity operations, incident response, or digital forensics experience in a high-maturity SOC or MDR environment
  • Expert-level mastery of the MITRE ATT&CK framework for behavioral detection strategies
  • Deep forensic expertise across endpoint, cloud, identity, and network domains
  • Experience with log analysis and malware triage
  • Ability to drive complex technical projects from conception to completion across global teams
  • Ability to direct containment strategies during high-stakes customer compromises
  • Ability to communicate attacker tactics, techniques, and procedures and long-term security strategies to technical and executive audiences
  • Ability to build cross-functional alignment with Detection Engineering, Product, and Platform teams
  • Experience mentoring and coaching SOC analysts
  • Advanced industry certification such as GCFA, GCTI, GREM, or OSCP

What the Team is Saying

Cathal
Aparna
Ali
David Boffa
Ronan McKinless
Pete Rubio
Shilan Aliyal
Rohit Sharma
Ronan McKinless
Rajeev Sharma
Corey Thomas
Rajeev Sharma
Prasad Vidhate
Rapid 7
Matthew Cappello
Rajeev Sharma
Wael Mohamed
Rajeev Sharma
Alex Pratt
Maria Loughrey

Rapid7 Compensation & Benefits Highlights

  • Leave & Time Off Breadth Time off is highlighted by unlimited PTO for U.S. employees, plus 12 holidays and 5 global company days off within a hybrid model. These policies emphasize recharge opportunities beyond standard vacation allotments.
  • Equity Value & Accessibility Ownership opportunities include an ESPP at a 15% discount with a lookback, and many roles also receive RSUs. This mix provides accessible paths to equity participation across functions.
  • Healthcare Strength Core coverage includes comprehensive medical, dental, and vision plans alongside mental‑health resources. Competitive paid parental leave complements the health offering for families.

Rapid7 Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
2,400 Employees
Year Founded: 2000

What We Do

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

Why Work With Us

With our products, research, and open source communities, we’re building a secure digital future for everyone. This means constantly learning and evolving in an industry that’s anything but stagnant. You’ll be faced with tough challenges, and given the support to find creative solutions that drive our business, and your career forward.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Rapid7 Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Our default working model is hybrid, with employees working three days per week in the office. This approach underpins our commitment to flexibility and adaptability while supporting our dedication to development, teamwork and customer purpose.

Typical time on-site: 3 days a week
Company Office Image
HQBoston
Company Office Image
Arlington
Company Office Image
Austin, TX
Company Office Image
Belfast, GB
Dublin
Galway
Melbourne
Tokyo
Munich
Company Office Image
Prague
India
Company Office Image
Reding, UK
Singapore - Regional Headquarters
Company Office Image
Tampa, FL
Tel Aviv
Learn more

Similar Jobs

Rapid7 Logo Rapid7

Detection & Response Analyst

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
Arlington, VA, USA
2400 Employees

Rapid7 Logo Rapid7

Operations Analyst

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
United States
2400 Employees
82K-110K Annually

Rapid7 Logo Rapid7

Principal Software Engineer

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
United States
2400 Employees
191K-258K Annually

Rapid7 Logo Rapid7

Analyst, Strategy & Transformation

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
United States
2400 Employees
78K-106K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account