Demo

Security Detection & Response Lead

Saige Partners
San Jose, CA Contractor
POSTED ON 5/1/2026
AVAILABLE BEFORE 5/31/2026

NO Third Parties/NO C2C/NO HIB VIsas

What You’ll Do

Lead enterprise-wide security monitoring and threat detection across SIEM, EDR, network, endpoint, and cloud security platforms.

• Design, implement, validate, tune, and optimize detection rules, correlation logic, dashboards, and alerting use cases.

• Continuously improve detection quality and reduce false positives to strengthen operational efficiency and signal-to-noise ratio.

• Ensure effective log ingestion, parsing, normalization, field extraction, and telemetry coverage across critical systems and infrastructure.

• Support onboarding and integration of new log sources, security tools, and telemetry pipelines into the security monitoring environment.

• Lead investigation and response activities for security incidents across enterprise systems.

• Serve as the technical lead during high-severity incidents, coordinating containment, eradication, recovery, and cross-functional response efforts with IT, cloud, and infrastructure teams.

• Perform advanced analysis to determine incident scope, root cause, impact, and recommended remediation actions.

• Conduct post-incident reviews and drive improvements to detections, playbooks, and response procedures based on lessons learned.

• Lead proactive threat hunting efforts using SIEM, NDR, EDR, CASB, and cloud telemetry to identify advanced or evasive threats.

• Investigate suspicious behaviors including lateral movement, privilege escalation, persistence, and data exfiltration attempts.

• Map detections, investigations, and threat hunting activities to the MITRE ATT&CK framework.

• Mentor and guide SOC analysts and incident responders in threat analysis, investigation techniques, and response workflows.

• Develop, maintain, and improve incident response runbooks, threat models, triage procedures, and detection documentation.

• Track and report on security operations metrics such as MTTD, MTTR, detection coverage, and recurring incident trends.

• Partner with IT, infrastructure, engineering, and vulnerability management teams to prioritize remediation and strengthen overall security posture.

• Collaborate across technical and non-technical teams to ensure rapid, effective response to security incidents and continuous improvement of detection and response capabilities.


Requirements

The Security tools desired are: Crowdstrike, Splunk, Darktrace, CASB

Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field; Master’s degree preferred.

• 6-8 years of experience in security operations, threat detection, incident response, or related cybersecurity roles.

• Hands-on experience with SIEM platforms such as Splunk, including rule creation, correlation logic, dashboarding, and log analysis.

• Strong experience investigating alerts and incidents across endpoint, network, operating system, and cloud environments.

• Deep understanding of incident response methodologies, threat investigation workflows, and root cause analysis.

• Solid knowledge of enterprise log sources including Windows/Linux servers, firewalls, IDS/IPS, endpoints, and cloud-native services.

• Strong knowledge of detection engineering, MITRE ATT&CK techniques, adversary behaviors, and threat hunting methodologies.

• Experience with cloud environments such as AWS, Azure, or similar, including security monitoring and logging services.

• Familiarity with SOAR, automation, or orchestration tools is a plus.

• Strong analytical, problem-solving, and decision-making skills in fast-paced operational environments.

• Excellent written and verbal communication skills, with the ability to clearly present findings to both technical and non-technical stakeholders.

• Ability to lead incident response efforts, mentor team members, and collaborate effectively across diverse global teams.

• Relevant certifications such as CISSP, GCIH, GCIA, Security , Splunk Security certifications, or comparable credentials are a plus.

Salary : $65 - $90

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Detection & Response Lead?

Sign up to receive alerts about other jobs on the Security Detection & Response Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Saige Partners

  • Saige Partners Winona, MN
  • Job Description We strive to be Your Future, Your Solution to accelerate your career. Contact Nick Polutnik at npolutnik@saigepartners.com, you can also sc... more
  • 8 Days Ago

  • Saige Partners Exeter, NH
  • We strive to be Your Future , Your Solution to accelerate your career! Contact Hannah Wilson at hwilson@saigepartners.com, you can also schedule an appoint... more
  • 9 Days Ago

  • Saige Partners Rapids, IA
  • Electrical Engineer Position Summary We are seeking a motivated Electrical Controls Engineer to support the design, programming, troubleshooting, and impro... more
  • Just Posted

  • Saige Partners Rapids, IA
  • Job Title: CNC Machinist Pay: $25 Max for 1st shift - $26.50 for 2nd shift Location: Cedar Rapids, Iowa Job Summary We are seeking a skilled CNC Machinist ... more
  • Just Posted


Not the job you're looking for? Here are some other Security Detection & Response Lead jobs in the San Jose, CA area that may be a better fit.

  • DNAnexus Mountain View, CA
  • Founded in 2009, DNAnexus is the enterprise orchestration platform for precision health. A pioneer in cloud-based omics and purpose-built bioinformatics fo... more
  • Just Posted

  • Robinhood Menlo Park, CA
  • Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger... more
  • 13 Days Ago

AI Assistant is available now!

Feel free to start your new journey!