This role pays less than
79%
of similar roles. Most pay
$145,000–$213,625
— the shaded band above.
At the midpoint, this role pays about
$140k
versus about
$179k
for comparable roles.
Based on 240 similar postings.
Employer
About Blackstone Inc
Blackstone Inc. operates as a global investment firm specializing in real estate, private equity, credit, infrastructure, and life sciences, focusing on creating long-term value for institutional and individual investors.
Blackstone Inc currently has
24 open roles
on FindRole.
Listed pay typically runs
$160,000–$200,000
across 21 roles with salary data.
Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity serves as a Tier 2 incident responder on the front line of cyber defense. This role involves managing an incident queue to detect, investigate, and respond to security incidents across email, endpoint, identity, network, and cloud environments. The Associate handles complex escalations from Tier 1 analysts, performs host containment in EDR platforms, and conducts deep investigations into phishing and credential misuse. Key responsibilities include authoring and tuning SIEM detections, building automation to reduce repetitive tasks, and utilizing agentic AI tools for triage and enrichment. Required skills include proficiency in Python or PowerShell, experience with major enterprise SIEMs like Splunk or Sentinel, and knowledge of identity providers such as Okta. The role focuses on securing firm assets by identifying threats and improving detection capabilities through proactive threat hunting and playbooks.
Manage the full incident lifecycle from intake through investigation, containment, and closure across email, endpoint, identity, network, and cloud environments.
Handle complex escalations from Tier 1 analysts and lead investigations as their scope grows.
Investigate security telemetry in the SIEM to identify threats and conduct live response actions within the EDR platform.
Analyze email threats including phishing and business email compromise using header and message trace analysis.
Investigate cloud and identity compromises involving credential misuse, privilege abuse, and multi-factor bypass.
Author and tune detection logic based on investigation findings to reduce noise and automate repetitive tasks.
Mentor Tier 1 analysts through hands-on coaching and sharing of technical tradecraft during case reviews.
Document incidents for technical teams and stakeholders while maintaining strict evidence handling and chain of custody.
What we're looking for
2+ years of hands-on experience in security operations, incident response, or a comparable technical security role.
Demonstrated experience running end-to-end security investigations from alert through root cause and containment in a SOC or IR setting.
Hands-on SIEM experience writing and troubleshooting queries using major enterprise platforms like Splunk, Microsoft Sentinel, or Elastic.
Hands-on EDR experience conducting endpoint investigation and containment using platforms such as CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint.
Working knowledge of cloud and identity investigation including IAM, SSO, and providers like Okta or Microsoft Entra ID.
Practical understanding of attacker behavior across the intrusion lifecycle, including phishing, credential theft, and lateral movement.
Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation of repetitive analysis.
Demonstrated experience using AI tooling to automate or accelerate tasks with sound judgment regarding output reliability.
Clear technical writing skills to explain incidents and impacts to both engineers and non-technical stakeholders.