Detection and Response Lead
One Identity · Remote, UNAVAILABLE, IN · India · Remote
Posted Oct 6, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Overview
Detection and Response Lead
One Identity · Information Security, Cyber Defense
Senior individual contributor, practice lead · India · Reports to the Director of Information Security
Why this role exists
One Identity builds the software that decides who gets into everything else our customers run, and the ground this practice defends is our own: the corporate environment and the hosted services we operate in the cloud. Coverage spans external attacks and insider threats across everything we run, and the detection work is shaped around that full range.
Twenty-four seven monitoring is handled by a managed provider, which means this is not a shift-rotation job. The provider covers first-line triage and escalates when needed. This role owns everything above the provider: what gets detected in the first place, whether the coverage matches how we're actually attacked, how good the escalations are, and what happens once something real lands on the desk. Directing that relationship well is a large part of the work.
We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role leads the detection and response practice inside it. Scope comes from what you build and from the standard you set for what a real incident response looks like here.
What you'll do
Own what gets detected
Set the strategy for detection use cases and own the catalog built from it: identity and authentication abuse, privileged access misuse, cloud control plane activity across Azure and AWS, endpoint and email vectors, and the paths specific to how our own products are deployed internally.
Treat detections as code. Version them, review them, test them against real telemetry, and track coverage against a threat model rather than a vendor's rule count. Detection changes arrive as pull requests with the reasoning attached.
Own the signal quality problem end to end. Tune what's noisy, retire what's dead, and know which gaps are deliberate.
Set the telemetry standard. Decide what we need to collect and retain to investigate an incident properly, and make the case for it when that costs something.
Own the response
Lead incident response from escalation through closure: scoping, containment, evidence handling, root cause, and the write-up that survives a customer or auditor reading it.
Direct the managed provider. Set escalation criteria, hold the quality bar on what comes through, and close the loop when something should have been caught and wasn't.
Run the exercises that make a response work under pressure. Tabletops with engineering and leadership, and the runbooks that make an on-call decision obvious at two in the morning.
Own the notification path. Know which obligations attach to which kinds of incident, contractual and regulatory, and make sure the clock is understood before it's running.
Work with product security when an incident touches what we ship.…