Senior Detection & Response Engineer
GreystarAbout the role
ABOUT GREYSTAR
Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $300 billion of real estate in more than 265 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $35 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit www.greystar.com.
JOB DESCRIPTION SUMMARY
Greystar is seeking a Senior Detection & Response Engineer to join our Cybersecurity Operations team. This is a hybrid engineering and operations role for someone who can build detections, write code and automation, run full incident response investigations, and apply solid security engineering fundamentals across our environment. You will own the full loop: engineer the detection, respond to what it catches, and feed those lessons back into stronger coverage. This role spans EDR, IAM, SIEM, Data governance and works closely with our SOC.JOB DESCRIPTION
Responsibilities
Design, build, test, and tune detection rules across our SIEM and security tooling, targeting real attack techniques observed in our environment
Build scripts, automation, and API integrations (using code and AI tooling) to accelerate detection engineering, investigation, and response workflows
Lead incident response investigations end to end, from triage through containment, eradication, and closure
Perform host and cloud forensic analysis, including disk, memory, and log artifact examination to reconstruct attacker activity and establish incident timelines
Participate in an on-call rotation and perform hands-on alert and incident analysis
Analyze Microsoft 365 and Entra ID log sources including interactive sign-ins, non-interactive sign-ins, audit logs, and the unified audit log
Investigate EDR detections, perform process tree analysis, and recommend containment actions
Triage and investigate escalations from the SOC
Develop and maintain automated response playbooks
Conduct root cause analysis and determine initial access, persistence, and exfiltration methods during investigations
Apply security engineering fundamentals to improve identity security, conditional access, and endpoint posture
Produce clear, executive-ready incident briefings, IOC documentation, and technical writeups
Identify and tune false positive patterns to improve detection fidelity
Required Qualifications
6+ years in security operations, detection engineering, incident response, or a combined security engineering role
Demonstrated ability to build detections and understand the underlying logic, not just operate a tool
Hands-on digital forensics experience across endpoint and cloud, including artifact collection, timeline recon
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s