Old National Bank

Cybersecurity Detection & Response Engineer

Old National Bank$77K — $153K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience.
  • Minimum 4 years of cybersecurity experience, particularly in security monitoring or incident response.
  • Hands-on experience with Microsoft Sentinel and Microsoft Defender XDR technologies.
  • Proficient in KQL for developing detection logic and queries.
  • Experience with automation scripting using tools like PowerShell or Python.
  • Working knowledge of MITRE ATT&CK and security environments requiring compliance.

Responsibilities

  • Develop and maintain detection use cases based on threat intelligence and attack techniques.
  • Conduct validation testing and participate in threat-hunting exercises to assess detection capabilities.
  • Identify and address monitoring gaps to enhance coverage and response processes.
  • Collaborate with SOC analysts and third-party providers to improve investigation outcomes.
  • Design and maintain Sentinel playbooks and automation workflows to streamline SOC operations.
  • Automate repetitive processes to increase efficiency and response time.
  • Serve as an escalation point for complex security incidents and support evidence collection.

Benefits

  • Comprehensive training and development opportunities.
  • Access to cutting-edge security technology and tools.
  • Collaboration with experienced cybersecurity professionals.
  • Participation in innovative projects involving AI and automation in security.
  • Opportunities for growth in a regulated financial environment.
Full Job Description
Overview

The Cybersecurity Detection and Response Engineer administers, engineers, and improves ONB’s security monitoring and response platforms, with primary focus on Microsoft Sentinel and Microsoft Defender XDR. This role builds and tunes detections, supports complex investigations, partners with third-party monitoring providers to receive and triage escalations, automates repeatable security workflows, and uses modern tools—including AI-assisted analysis—to improve speed, accuracy, and consistency across security operations.

Salary Range

The salary range for this position is $77,900/yr - $153,000/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate’s relevant skills and professional experience, educational qualifications, and geographic location.

Key Accountabilities 

Detection Engineering & Threat Detection 

  • Develop and maintain detection use cases based on threat intelligence, emerging attack techniques, and MITRE ATT&CK. 
  • Conduct validation testing, threat hunting, and participate in red/purple-team testing to evaluate detection effectiveness. 
  • Identify monitoring gaps and implement improvements to coverage, telemetry, and response processes. 
  • Partner with SOC analysts, IT teams, and third-party providers to improve investigation quality and operational outcomes. 

Security Automation & SOAR 

  • Design and maintain Sentinel playbooks, Logic Apps, APIs, and automation workflows. 
  • Automate repetitive SOC processes to improve response speed, consistency, and analyst efficiency. 
  • Evaluate and responsibly apply AI-assisted capabilities to support investigation, summarization, triage, detection development, and operational improvement. 

Incident Response Support 

  • Serve as an escalation resource for complex security events and investigations. 
  • Support incident response through data analysis, evidence collection, and investigative support. 
  • Maintain practical playbooks, response procedures, and after-action improvement recommendations. 

Continuous Improvement 

  • Research emerging threats, vulnerabilities, defensive capabilities, and practical uses of AI in security operations. 
  • Support audit, regulatory, and governance needs including FFIEC, NIST, and applicable banking requirements. 
  • Continuously improve monitoring, response, automation, and operational processes. 

Key Competencies for Position 

  • Technical depth: Strong understanding of Sentinel, Defender XDR, KQL, detection engineering, automation, and incident response. 
  • Investigative judgment: Able to analyze complex events, identify root cause, and develop practical risk-based improvements. 
  • Communication and partnership: Clearly explains technical issues and works effectively across security, IT, risk, and business teams. 
  • Continuous improvement mindset: Seeks opportunities to improve security operations through automation, AI-assisted workflows, and better detection outcomes. 

Qualifications & Education Requirements 

Required Qualifications 

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience. 
  • Minimum 4 years of cybersecurity experience, including security monitoring, incident response, or detection engineering. 
  • Experience administering Microsoft Sentinel and Microsoft Defender XDR technologies. 
  • Strong KQL skills and experience developing detection logic, dashboards, or hunting queries. 
  • Experience with scripting or automation such as PowerShell, Python, APIs, Logic Apps, or similar tools. 
  • Working knowledge of MITRE ATT&CK, endpoint security, log analysis, and regulated security environments. 
  • Interest in responsibly using AI-assisted tools to improve security operations, investigation, automation, and documentation. 

Preferred Qualifications 

  • SC-200, AZ-500, CISSP, GCIH, GCIA, GCFA, or equivalent certifications. 
  • Experience in banking, financial services, or other regulated industries where security programs must be measured, documented, tested, and audit-defensible. 
  • Practical experience using AI-assisted tools to accelerate investigation, summarize security data, generate or refine detection logic, improve documentation, or support automation workflows. 
  • Hands-on experience with security automation, orchestration, AI-assisted analysis, or response technologies. 

Key Measures of Success / Key Deliverables 

  • Improves detection accuracy, reduces false-positive volume, and strengthens SOC visibility. 
  • Develops and maintains high-quality Sentinel detections, Defender XDR improvements, workbooks, dashboards, and automation workflows. 
  • Supports timely response to security events and complex investigations. 
  • Operationalizes new telemetry, monitoring capabilities, and AI-assisted efficiencies where appropriate. 
  • Proactively communicates status, risks, obstacles, and recommendations to leadership and stakeholders. 

 

About Old National Bank

Old National Bank is a regional bank with its headquarters in Evansville, Indiana. It is the largest financial services holding company headquartered in Indiana and operates in Indiana, Kentucky, Michigan, Wisconsin, and Minnesota. The bank offers a range of financial services, including personal and business banking, wealth management, and insurance. Old National Bank has a strong commitment to community involvement and has been recognized for its philanthropic efforts. The bank has received numerous awards for its workplace culture and has been named one of the Best Banks to Work For by American Banker.
Learn more about Old National Bank
Size
4,333 employees
Market Cap
$5.1 billion
Industry
Net Income
$226.4 million
Founded
1834
5 Year Trend
+7.4%
NASDAQ

Similar Jobs

More Jobs at Old National Bank

More Information Technology Jobs

Find similar Cybersecurity Detection & Response Engineer jobs: