次の仕事の機会を見つけましょう

職種、スキル、勤務地で求人を検索できます。応募書類を準備する前に募集要件を確認しましょう。

魅力的な職種名を見つけることは、仕事探しの出発点です。業務内容、応募条件、働き方を自分の経験と照らし合わせましょう。このガイドでは、候補の絞り込み、応募書類の準備、提出先の確認を順番に進めるためのポイントを紹介します。

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

条件をクリア

検索結果: 7,993

← 検索結果に戻る

Detection and Response Lead

One Identity

リモート勤務

勤務地
Remote (India)
勤務時間
Full Time
掲載日
2026年10月7日

応募する前に、企業のウェブサイトで現在も募集中かどうかと詳しい条件を確認してください。

仕事内容

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

Overview Detection and Response Lead One Identity · Information Security, Cyber Defense Senior individual contributor, practice lead · India · Reports to the Director of Information Security Why this role exists One Identity builds the software that decides who gets into everything else our customers run, and the ground this practice defends is our own: the corporate environment and the hosted services we operate in the cloud. Coverage spans external attacks and insider threats across everything we run, and the detection work is shaped around that full range. Twenty-four seven monitoring is handled by a managed provider, which means this is not a shift-rotation job. The provider covers first-line triage and escalates when needed. This role owns everything above the provider: what gets detected in the first place, whether the coverage matches how we're actually attacked, how good the escalations are, and what happens once something real lands on the desk. Directing that relationship well is a large part of the work. We're separating from Quest Software and building an independent security function. The team is lean and globally distributed, and this role leads the detection and response practice inside it. Scope comes from what you build and from the standard you set for what a real incident response looks like here. What you'll do Own what gets detected Set the strategy for detection use cases and own the catalog built from it: identity and authentication abuse, privileged access misuse, cloud control plane activity across Azure and AWS, endpoint and email vectors, and the paths specific to how our own products are deployed internally. Treat detections as code. Version them, review them, test them against real telemetry, and track coverage against a threat model rather than a vendor's rule count. Detection changes arrive as pull requests with the reasoning attached. Own the signal quality problem end to end. Tune what's noisy, retire what's dead, and know which gaps are deliberate. Set the telemetry standard. Decide what we need to collect and retain to investigate an incident properly, and make the case for it when that costs something. Own the response Lead incident response from escalation through closure: scoping, containment, evidence handling, root cause, and the write-up that survives a customer or auditor reading it. Direct the managed provider. Set escalation criteria, hold the quality bar on what comes through, and close the loop when something should have been caught and wasn't. Run the exercises that make a response work under pressure. Tabletops with engineering and leadership, and the runbooks that make an on-call decision obvious at two in the morning. Own the notification path. Know which obligations attach to which kinds of incident, contractual and regulatory, and make sure the clock is understood before it's running. Work with product security when an incident touches what we ship. Internal detection and customer-facing disclosure are different disciplines that occasionally share a root cause. Make it scale Decide where agentic workflows belong in detection and response. Enrichment, correlation, and first-pass investigation are tractable now; containment actions are a harder call. You set where automation acts, where it recommends, and how we verify what it did. Automate the response path itself, not just the alerting. The measure is how much of an investigation is already done by the time a person opens it. Bring threat intelligence into the practice with an output attached: adversary tradecraft translated into detection use cases, hunts, or control changes. Advance the program's metrics: coverage against the threat model, escalation quality from the provider, time to detect and time to close, reported in terms leadership steers by. Hunt on a schedule. Structured hypotheses against our own telemetry, and every finding either becomes a detection or gets written down as a deliberate gap. What we're looking for Required Eight or more years in security operations, detection engineering, or incident response, with time spent leading incidents rather than only working them. Equivalent depth counts. Detection engineering in a modern SIEM, with the query fluency to build and validate rules yourself. We run Microsoft Sentinel and Defender XDR. Identity attack fluency. Entra ID and Active Directory attack paths, token and session abuse, OAuth consent, and federation. Hands-on work with AI-assisted detection, triage, or investigation within the last six months, and a considered view on where automation should and shouldn't be trusted to act. The three above are the bar. Everything below is depth we'd like and can build. If you meet the requirements and bring most of the rest, apply. We'd rather assess the gap ourselves than have you decide it for us. Also matters: cloud detection across Azure and AWS control planes; scripting and automation in Python or PowerShell; managing or directing an MDR or managed SOC relationship; forensic investigation and evidence handling; writing that holds up when an executive or an auditor reads it. Helpful: threat hunting from structured hypotheses; insider risk detection, container and Kubernetes runtime detection, SOAR or workflow automation platforms, threat intelligence work with an operational output, prior time on the engineering side. What you should know going in This is a practice to build, not a queue to work. The managed tier handles the volume, which leaves you the engineering and the judgment: what we detect, how well, and what happens next. You'll have functional direction of the SOC analysts, with people leadership held by the director, and direct access to engineering leadership. Your incident write-ups will be read at the executive level. If you want to own a detection and response practice rather than inherit someone else's rules, this is that seat. Company Description One Identity enables organizations of all sizes to better secure, manage, monitor, protect, and analyse information and infrastructure to help fuel innovation and drive their businesses forward. With team members around the globe, we intend to continue to grow revenues and add value to customers. When you join our team, you will have the opportunity to build and develop products at a scale few others can provide. Our product portfolio serves a large base of customers and we are addressing the strategic imperatives for enterprise businesses. Working with some of the most talented employees the industry has to offer, we provide enhanced career opportunities for team members to learn and grow in a rapidly changing environment. Why work with us? Life at One Identity means collaborating with dedicated professionals with a passion for technology. When we see something that could be improved, we get to work inventing the solution. Our people demonstrate our winning culture through positive and meaningful relationships. We invest in our people and offer a series of programs that enables them to pursue a career that fulfills their potential. Our team members’ health and wellness is our priority as well as rewarding them for their hard work. One Identity is an Equal Opportunity Employer and Prohibits Discrimination and Harassment of Any Kind: One Identity is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at One Identity are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. One Identity will not tolerate discrimination or harassment based on any of these characteristics. One Identity encourages applicants of all ages. Come join us. Note: We do not use text messaging or third-party messaging apps like Telegram to communicate with applicants, so please exercise caution if you are approached in this way and only interact with people claiming to be One Identity employees if they have an email address ending in @oneidentity.com. Originally posted on Himalayas

検索して比較し、応募を準備しましょう

次の仕事で活かしたい職種やスキルから検索を始めましょう。勤務地と職種の条件を調整し、求人を開いて担当業務を比較してください。結果がない場合は、短い検索語を試すか、条件を一つずつ外してみましょう。

必須条件と歓迎条件を分けて確認し、勤務時間、報酬、勤務地が掲載されている場合は目を通しましょう。リモート勤務でも、居住国、就労資格、勤務時間帯が指定されることがあります。現在の募集状況と詳しい条件は企業に確認してください。

募集要件に関連する実際の経験を選び、自分の役割と貢献を説明しましょう。数値は根拠がある場合にのみ使ってください。企業の応募方法に従い、送信前に連絡先、内容、PDFの表示を確認しましょう。

応募前の確認リスト

仕事探しに関するよくある質問

英語の求人が表示されるのはなぜですか?

職種名や説明文は企業が作成したものです。条件や要件を変えないように原文を掲載しています。操作画面とこのガイドは日本語です。日本語の検索で見つからない場合は、「software engineer」のように、掲載言語の職種名やスキル名でも検索してみてください。検索語が自動翻訳されるわけではありません。

リモート求人なら、どの国からでも働けますか?

必ずしもそうではありません。居住国、就労資格、勤務時間帯が指定されている場合があります。元の求人ページで条件を確認してください。記載がない場合は、自分の居住地から応募できると判断する前に企業へ確認しましょう。リモートという表示だけでは、勤務地の制限がないことは分かりません。

検索結果が出ない場合はどうすればよいですか?

より一般的な職種名や一つのスキルで検索し、条件を一つずつ外してみてください。同じような仕事でも企業によって呼び方が異なります。特定の求人が見つからなくなった場合は、企業の採用ページで求人番号を探しましょう。検索条件を広げても、終了した募集が再開するわけではありません。

ResumizeAIから応募が送信されますか?

応募ボタンは外部サイトを開きます。企業または採用サービスの案内に従い、そのサイトで送信を完了してください。ResumizeAIで応募書類を作成しただけでは応募は送信されません。リンク先が企業のトップページの場合は、該当する募集を探してから手続きを進めましょう。

応募書類とカバーレターはどう調整すればよいですか?

募集要件と、自分が説明できるプロジェクト、業務、成果を結び付けます。経験していない技術や実績を加えず、関連する経験を分かりやすく示してください。カバーレターでは応募理由を具体例とともに伝えます。指定された言語とファイル形式に従い、送信前に両方の書類を確認しましょう。