Jobs and Careers
GR

Senior Detection & Response Engineer

Greystar
United Statesfull_timeVerifiedPosted 30 Jun 2026

About the role

ABOUT GREYSTAR

Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $300 billion of real estate in more than 265 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $35 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit www.greystar.com.

JOB DESCRIPTION SUMMARY

Greystar is seeking a Senior Detection & Response Engineer to join our Cybersecurity Operations team. This is a hybrid engineering and operations role for someone who can build detections, write code and automation, run full incident response investigations, and apply solid security engineering fundamentals across our environment. You will own the full loop: engineer the detection, respond to what it catches, and feed those lessons back into stronger coverage. This role spans EDR, IAM, SIEM, Data governance and works closely with our SOC.

JOB DESCRIPTION

Responsibilities 

  • Design, build, test, and tune detection rules across our SIEM and security tooling, targeting real attack techniques observed in our environment 

  • Build scripts, automation, and API integrations (using code and AI tooling) to accelerate detection engineering, investigation, and response workflows 

  • Lead incident response investigations end to end, from triage through containment, eradication, and closure 

  • Perform host and cloud forensic analysis, including disk, memory, and log artifact examination to reconstruct attacker activity and establish incident timelines 

  • Participate in an on-call rotation and perform hands-on alert and incident analysis 

  • Analyze Microsoft 365 and Entra ID log sources including interactive sign-ins, non-interactive sign-ins, audit logs, and the unified audit log 

  • Investigate EDR detections, perform process tree analysis, and recommend containment actions 

  • Triage and investigate escalations from the SOC 

  • Develop and maintain automated response playbooks 

  • Conduct root cause analysis and determine initial access, persistence, and exfiltration methods during investigations 

  • Apply security engineering fundamentals to improve identity security, conditional access, and endpoint posture 

  • Produce clear, executive-ready incident briefings, IOC documentation, and technical writeups 

  • Identify and tune false positive patterns to improve detection fidelity 

Required Qualifications 

  • 6+ years in security operations, detection engineering, incident response, or a combined security engineering role 

  • Demonstrated ability to build detections and understand the underlying logic, not just operate a tool 

  • Hands-on digital forensics experience across endpoint and cloud, including artifact collection, timeline recon

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Greystar

View company profile →