Nabancard

Detection and Response Engineer

US - RemoteFull timePosted 13 days ago
Apply on Nabancard →

Sign into see who you know at Nabancard.

Detection and Response EngineerNorth - RemoteApplicants located in the East and Central time zones will receive preferred consideration.North is a US based company and this role is not eligible for current or future sponsorship.The Detection and Response Engineer is responsible for the day-to-day engineering, tuning, and improvement of North's detection and response capability.The role covers four core areas: detection engineering, incident response, AI-enabled SOC operations,and security automation. This role works closely with the SOC, IT, and engineering teams to close visibility gaps, reduce manual analyst effort, and shorten the time between detection and resolution across our payment processing environment.Essential Duties and ResponsibilitiesDetection Engineering• Design, build, and tune detection content (rules, correlation searches, use cases) across endpoint, network, cloud, and identity log sources• Perform ongoing coverage and gap analysis against the MITRE ATT&CK framework and actual log source volume, prioritizing based on real attack surface• Validate detection logic against real-world attack techniques from cyber threat intelligence and reduce false- positive rates without sacrificing efficacy• Maintain and version-control the detection rule repository, including documentation of coverage and known gapsIncident Response• Triage, investigate, and contain security incidents and alerts across the environment• Conduct root cause analysis and structured post-incident reviews, feeding findings back into detection engineering• Document incident timelines, indicators of compromise, and remediation actions• Support forensic investigation of compromised hosts, accounts, and applications• Participate in on-call rotation for critical incident response as needed AI-Enabled SOC• Evaluate, pilot, and implement AI/LLM-powered tools for alert triage, enrichment, and analyst workflows• Build and tune AI-assisted investigation and detection workflows to reduce analyst workload and mean time to respond (MTTR)• Identify high-value use cases for AI and automation while measuring the resulting impact• Apply sound judgment about where AI-generated output requires human validation, particularly for high-confidence detections and containment actions Automation• Develop automation and orchestration (SOAR, scripts, APIs) to streamline detection, enrichment, and response workflows• Automate repetitive SOC and IR tasks, such as evidence gathering, enrichment, and ticketing, to reduce manual toil• Build and maintain playbooks and runbooks for common incident types• Write and maintain scripts (Python or similar) that integrate security tooling and data sourcesAdditional Cross-Functional Responsibilities• Partner with cloud, network, and identity teams to close visibility and telemetry gaps• Stay current on threat intelligence, adversary TTPs, and vulnerabilities relevant to a payments/fintech environment• Communicate findings, coverage gaps, and...