Alert, Detection, and Response Engineer, Associate

Blackstone Inc

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Miami, FL
Salary
$110,000–$170,000 / yr
Employment
Full-time
Posted
9 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $179k
This role $140k
$97k most similar roles pay here $232k

This role pays less than 79% of similar roles. Most pay $145,000–$213,625 — the shaded band above. At the midpoint, this role pays about $140k versus about $179k for comparable roles.

Based on 240 similar postings.

Employer

About Blackstone Inc

Blackstone Inc. operates as a global investment firm specializing in real estate, private equity, credit, infrastructure, and life sciences, focusing on creating long-term value for institutional and individual investors.

Blackstone Inc currently has 24 open roles on FindRole.

Listed pay typically runs $160,000–$200,000 across 21 roles with salary data.

Most-posted roles

View all roles at Blackstone Inc

At a glance

TL;DR · Alert, Detection, and Response Engineer, Associate

Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity serves as a Tier 2 incident responder on the front line of cyber defense. This role involves managing an incident queue to detect, investigate, and respond to security incidents across email, endpoint, identity, network, and cloud environments. The Associate handles complex escalations from Tier 1 analysts, performs host containment in EDR platforms, and conducts deep investigations into phishing and credential misuse. Key responsibilities include authoring and tuning SIEM detections, building automation to reduce repetitive tasks, and utilizing agentic AI tools for triage and enrichment. Required skills include proficiency in Python or PowerShell, experience with major enterprise SIEMs like Splunk or Sentinel, and knowledge of identity providers such as Okta. The role focuses on securing firm assets by identifying threats and improving detection capabilities through proactive threat hunting and playbooks.

What you'll do

  • Manage the full incident lifecycle from intake through investigation, containment, and closure across email, endpoint, identity, network, and cloud environments.
  • Handle complex escalations from Tier 1 analysts and lead investigations as their scope grows.
  • Investigate security telemetry in the SIEM to identify threats and conduct live response actions within the EDR platform.
  • Analyze email threats including phishing and business email compromise using header and message trace analysis.
  • Investigate cloud and identity compromises involving credential misuse, privilege abuse, and multi-factor bypass.
  • Author and tune detection logic based on investigation findings to reduce noise and automate repetitive tasks.
  • Mentor Tier 1 analysts through hands-on coaching and sharing of technical tradecraft during case reviews.
  • Document incidents for technical teams and stakeholders while maintaining strict evidence handling and chain of custody.

What we're looking for

  • 2+ years of hands-on experience in security operations, incident response, or a comparable technical security role.
  • Demonstrated experience running end-to-end security investigations from alert through root cause and containment in a SOC or IR setting.
  • Hands-on SIEM experience writing and troubleshooting queries using major enterprise platforms like Splunk, Microsoft Sentinel, or Elastic.
  • Hands-on EDR experience conducting endpoint investigation and containment using platforms such as CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint.
  • Working knowledge of cloud and identity investigation including IAM, SSO, and providers like Okta or Microsoft Entra ID.
  • Practical understanding of attacker behavior across the intrusion lifecycle, including phishing, credential theft, and lateral movement.
  • Experience scripting in Python and/or PowerShell for enrichment, parsing, and automation of repetitive analysis.
  • Demonstrated experience using AI tooling to automate or accelerate tasks with sound judgment regarding output reliability.
  • Clear technical writing skills to explain incidents and impacts to both engineers and non-technical stakeholders.
  • Detection engineering (preferred).
  • Experience authoring/tuning SIEM correlation searches, EDR rules, Sigma content, or SOAR automation (preferred).
  • Digital forensics capability in memory, disk, or network analysis, or hands-on malware triage (preferred).
  • Threat hunting experience, particularly hypothesis-driven hunts against endpoint or cloud telemetry (preferred).
  • Working knowledge of at least one major cloud platform (AWS, Azure, or GCP) (preferred).
  • Experience in financial services or other heavily regulated environments (preferred).
  • At least one active security certification such as Security+, GCIH, GCFA, GCIA, GCED, CySA+, or a vendor SIEM certification (preferred).
  • B.S. in Computer Science, Cybersecurity, Information Systems, or a related technical field (preferred).

More like this

Similar roles

Threat Detection Security Engineer

CoStar Group

Arlington, VA +1 95 days ago $90,000–$154,000
Incident Response Sentinel Defender Azure Kubernetes Python Mitre Att&ck Automation Detection Engineering
4+ yrs exp

Senior Cyber Threat Defense Security Operations Engineer

Proofpoint

Draper, UT 45 days ago $136,200–$214,005
Incident Response SIEM SOAR EDR XDR Python PowerShell Bash MITRE ATT&CK Threat Hunting Threat Modeling AWS Microsoft Azure Google Cloud Platform Digital Forensics AI DLP STRIDE
8+ yrs exp

Detection & Response Engineer

eBay

Austin, TX 19 days ago $118,800–$205,600
Incident Response Detection Engineering Threat Hunting SIEM Python AWS Azure GCP Kubernetes Digital Forensics Threat Modeling Automation SaaS
5+ yrs exp

DFIR Analyst

SentinelOne

24 days ago $108,000–$120,000
DFIR EDR XDR SIEM Python AWS Azure GCP X-Ways Forensics Axiom FTK Malware Analysis Reverse Engineering Windows Linux macOS Network Security Threat Hunting SaaS
4+ yrs exp