STAGE (stage.in)
Threat Detection & Response - Blue Team Lead
New York or Boston · Senior
Sponsorship not specified$150k-$180kDetected 26 days ago
KubernetesCI/CDCybersecuritySOARSOC OperationsDetection EngineeringIncident ResponseStakeholder ManagementLeadershipCommunicationCollaborationAdaptability
About the role
- KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions.
- KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities.
- KKR's insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group.
Responsibilities
- Incident Leadership & Command (U.S. Regional Lead)
- Act as U.S. escalation lead / incident commander for high-severity incidents, owning response strategy, containment decisions, and coordination through resolution.
- Lead cross-functional response with internal CIRT, infrastructure/platform teams, cloud teams, identity teams, legal/compliance, and business stakeholders.
- Perform and lead advanced investigations across endpoint, network, identity, cloud control plane, SaaS, and (as needed) on-prem telemetry.
- Develop investigative narratives: attacker objectives, sequence of actions, impacted assets, containment efficacy, and residual risk.
- Own and continuously improve incident response playbooks (e.g., ransomware/extortion, BEC, cloud account compromise, token/key theft, data exfiltration, insider risk).
- Lead and coordinate exercises and simulations
- As U.S. Regional Lead, you will shape incident response outcomes for critical enterprise operations and directly influence how KKR modernizes response for a cloud-first, AI-enabled future.
- You'll partner with a high-performing MSSP and an engineering-driven TDR team to improve readiness, accelerate containment, and raise the bar on response quality across the organization.
Requirements
- 6+ years in Incident Response, Security Operations, or Blue Team roles, including leading high-severity incidents end-to-end.
- Working knowledge of cloud-native architectures (containers/Kubernetes, serverless, CI/CD) and the investigative/containment challenges they introduce.
- Experience partnering with MSSPs and distributed teams
- Proven ability to serve as an escalation lead and incident commander-calm, decisive leadership in ambiguous, high-pressure situations.
- Strong communication skills: able to translate complex technical details into clear, actionable updates for executives and stakeholders.
- Strong familiarity with identity-centric security models and investigations (federated identity, IAM abuse patterns, token theft, conditional access signals).
- comfortable operating in a hybrid SOC model (internal + ReliaQuest).
Nice to have
- Experience with purple teaming, detection validation, or adversary simulation platforms (e.g., Atomic Red Team, Caldera, Cymulate). (Preferred)
- Ability to influence engineering roadmaps (telemetry, enrichment, workflow improvements) based on operational pain points and incident learnings. (Preferred)
Skills
- Experience operating in cloud-forward enterprises, including hybrid environments spanning SaaS, cloud-native workloads, and on-prem systems.
- Experience partnering with MSSPs and distributed teams; comfortable operating in a hybrid SOC model (internal + ReliaQuest).
- Familiarity with MITRE ATT&CK and applying it to investigative thinking, readiness planning, and validation priorities.
- Experience designing, using, or validating automated response workflows (SOAR) and promoting safe automation patterns.
- Exposure to AI-assisted SOC/IR tooling, including governance considerations (data handling, audit logging, human approval, evaluation).
- able to translate complex technical details into clear, actionable updates for executives and stakeholders.
- Technically deep and business-aware: understands attacker behavior and business impact equally well.
- Operationally disciplined: strong instincts for repeatability, playbooks, and learning loops.
Compensation
- $150,000 - $180,000 USD
- KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws.
- Emails sent for unrelated issues, such as following up on an application, will not receive a response.
- Only emails left for this purpose will be returned.
- Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
- An employer who violates this law shall be subject to criminal penalties and civil liability.
- This is the expected annual base salary range for this New York-based position.
- Base Salary Range
Benefits
- Employees may be eligible for a discretionary bonus, based on factors such as individual and team performance.
Company info
- We are seeking a Blue Team Lead to serve as KKR's U.S. Regional Lead and escalation point for complex cyber incidents within the Threat Detection & Response (TD&R) function in our New York or Boston office.
Equal opportunity
- KKR is an equal opportunity employer.
Apply directly at STAGE (stage.in) →Create a free account for alerts like thisView STAGE (stage.in) immigration profile
This listing is sourced directly from STAGE (stage.in)'s careers page and normalized into a canonical job model.