Rapid7

Detection & Response Analyst

Rapid7$80K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2-4 years of experience in cybersecurity operations or IT security within a SOC or monitoring environment.
  • Foundational understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience utilizing security tools like SIEM, EDR, or NDR for alert triage and telemetry analysis.
  • Knowledge of Windows and Linux operating systems, focusing on system logs and processes.
  • Familiarity with investigative frameworks like MITRE ATT&CK.

Responsibilities

  • Conduct investigations into suspicious activity across multiple telemetry vectors.
  • Analyze security alerts to identify attacker behavior and potential compromises.
  • Investigate standard security incidents like malware infections and unauthorized access.
  • Assist senior analysts in complex threat scenarios for skill development.
  • Document investigation findings clearly in reports with remediation recommendations.
  • Communicate findings and recommended actions effectively to customers.
  • Identify detection gaps to refine the team's alerting processes.
  • Maintain high operational standards for alert triage and investigation quality.

Benefits

  • Access to continuous learning opportunities and professional growth.
  • Collaborative environment fostering teamwork and multi-dimensional perspectives.
  • Exposure to diverse security technologies and threat landscapes.
  • Work within a global team contributing to impactful security solutions.
Full Job Description

Detection & Response Analysts identify, investigate, and respond to security threats across diverse customer environments. They analyze security telemetry across endpoint, identity, cloud, and network vectors to protect global organizations from active cyber threats.

About the Team

Rapid7’s Managed Detection and Response (MDR) team provides 24/7 security monitoring, threat hunting, and incident investigation for organizations around the world.

About the Role

As a Detection & Response Analyst, your primary responsibility will be to identify, investigate, and respond to security threats across customer environments. Specifically, your focus will be to:

  • Conduct investigations into suspicious and malicious activity across endpoint, identity, cloud, and network telemetry within customer environments.

  • Analyze security alerts and telemetry to identify attacker behavior and impact, following defined escalation paths for potential compromises.

  • Investigate standard security incidents, including common malware infections, unauthorized access attempts, and credential abuse.

  • Assist senior analysts and Incident Response Consultants during larger engagements to build exposure to complex threat scenarios.

  • Document investigation findings clearly in reports, detailing timelines of activity and recommended remediation steps aligned with the MITRE ATT&CK framework.

  • Collaborate with SOC Advisors to ensure investigation findings and recommended remediation actions are communicated effectively to customers.

  • Identify and report detection gaps or noisy alerts to help the team refine detection logic.

  • Maintain high operational standards by meeting service level objectives for alert triage and investigation quality.

The skills and qualities you'll bring include

  • Bring 2–4 years of experience in cybersecurity operations, IT security, or a related technical role within a SOC or monitoring environment.

  • Demonstrate a foundational understanding of attacker tactics, techniques, and procedures (TTPs), such as persistence, defense evasion, and lateral movement.

  • Utilize security tools (SIEM, EDR, or NDR) to triage alerts, analyze telemetry, and assess potential compromise.

  • Apply knowledge of Windows and Linux operating systems, including system logs and processes, to conduct thorough technical investigations.

  • Leverage investigative frameworks like MITRE ATT&CK to categorize security events and document timelines of activity.

  • Communicate technical findings clearly in written reports and verbal updates to ensure findings are actionable by conveying objectives and rationale to foster commitment.

  • Drive efficient decision-making to resolve challenges and enable momentum during active incident triaging.

  • Hold self accountable for driving outcomes and meeting operational service level objectives for alert triage.

  • Build a network and work across boundaries with senior analysts and advisors to deliver sustainable security improvements.

  • Demonstrate eager interest in understanding why changes occur and act as an active driver in evolving security environments.

  • Express strong attention to detail and continuous curiosity to adapt and grow in a fast-paced environment.

  • Embody our core values to foster a culture of excellence that drives meaningful impact and collective success.

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

#LI-TD1

About Rapid7

Rapid7 is a cybersecurity company that provides solutions for vulnerability management, incident detection and response, and application security. The company's cloud-based platform, Insight, allows organizations to detect and respond to cyber threats in real-time. Rapid7's products are used by over 9,000 customers in more than 120 countries, including some of the world's largest companies in industries such as financial services, healthcare, and retail.
Learn more about Rapid7
Size
2,353 employees
Market Cap
$1.9 billion
Industry
Net Income
-$98.8 million
Founded
2000
5 Year Trend
+27.7%
Revenue
$411.4 million
NASDAQ

Similar Jobs

More Jobs at Rapid7

More Information Technology Jobs

Find similar Detection & Response Analyst jobs: