Senior Detection & Response Engineer
ABOUT GREYSTAR
Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $300 billion of real estate in more than 265 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $35 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit .
JOB DESCRIPTION SUMMARY
JOB DESCRIPTION
Responsibilities
Design, build, test, and tune detection rules across our SIEM and security tooling, targeting real attack techniques observed in our environment
Build scripts, automation, and API integrations (using code and AI tooling) to accelerate detection engineering, investigation, and response workflows
Lead incident response investigations end to end, from triage through containment, eradication, and closure
Perform host and cloud forensic analysis, including disk, memory, and log artifact examination to reconstruct attacker activity and establish incident timelines
Participate in an on-call rotation and perform hands-on alert and incident analysis
Analyze Microsoft 365 and Entra ID log sources including interactive sign-ins, non-interactive sign-ins, audit logs, and the unified audit log
Investigate EDR detections, perform process tree analysis, and recommend containment actions
Triage and investigate escalations from the SOC
Develop and maintain automated response playbooks
Conduct root cause analysis and determine initial access, persistence, and exfiltration methods during investigations
Apply security engineering fundamentals to improve identity security, conditional access, and endpoint posture
Produce clear, executive-ready incident briefings, IOC documentation, and technical writeups
Identify and tune false positive patterns to improve detection fidelity
Required Qualifications
6+ years in security operations, detection engineering, incident response, or a combined security engineering role
Demonstrated ability to build detections and understand the underlying logic, not just operate a tool
Hands-on digital forensics experience across endpoint and cloud, including artifact collection, timeline reconstruction, and evidence handling
Proficiency scripting and building automation (Python, PowerShell, KQL, or similar), including the effective use of AI tooling to accelerate development
Working knowledge of attacker tradecraft and the ability to attribute activity based on TTPs
Experience building or consuming API integrations across security and identity platforms
Proficiency with EDR platforms
Working knowledge of SIEM platforms and detection rule development
Strong understanding of hybrid identity environments, including AD Connect sync behavior and Entra ID
Experience investigating modern attack techniques including AiTM phishing, OAuth consent abuse, BEC, token replay, and living-off-the-land techniques
Solid security engineering fundamentals across identity, endpoint, and cloud
Willingness to participate in an on-call rotation and perform hands-on incident response
Strong written communication and documentation discipline
Preferred Qualifications
Demonstrated use of AI tools (such as Claude, Copilot, or similar) to accelerate detection engineering, investigation workflows, scripting, and documentation
Experience prompting and directing AI models to produce useful outputs in a security context, including log analysis, detection logic drafting, and incident timeline construction
Familiarity with Microsoft Sentinel, including analytic rule development using KQL and automation via Logic Apps or Playbooks
Familiarity with Microsoft Entra ID, Purview and Defender Suite
Hands-on experience with CrowdStrike Falcon, including alert triage, process tree analysis, and prevention policy management
Experience with identity security tooling such as Saviynt, Entra ID Protection, or similar IGA and privileged access platforms
Prior experience in a large enterprise or managed security environment (5,000+ endpoints or 10,000+ users)
Relevant certifications such as GCIA, GCIH, GCFE, GCFA, SC-200, AZ-500, or equivalent
What You'll Work On
This is a hands-on role with real ownership. You will build the detections that protect Greystar, respond to the incidents they surface, and continuously improve coverage based on what you learn in the field. You will write the automation that makes the team faster, investigate live compromises, and have direct input into detection strategy, SIEM direction, and identity security architecture. You will work directly with the Senior Manager of Cybersecurity Operations on initiatives including our SIEM migration to Microsoft Sentinel and ongoing detection engineering buildout.
Additional Compensation :
Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location.
Corporate Positions : In addition to the base salary, this role may be eligible to participate in a quarterly or annual bonus program based on individual and company performance.
Onsite Property Positions : In addition to the base salary, this role may be eligible to participate in weekly, monthly, and/or quarterly bonus programs.
Robust Benefits Offered*:
Competitive Medical, Dental, Vision, and Disability & Life insurance benefits. Low (free basic) employee Medical costs for employee-only coverage; costs discounted after 3 and 5 years of service.
Generous Paid Time off. All new hires start with 15 days of vacation, 4 personal days, 10 sick days, and 11 paid holidays. Plus your birthday off after 1 year of service! Additional vacation accrued with tenure.
For onsite team members, onsite housing discount at Greystar-managed communities are available subject to discount and unit availability.
6-Week Paid Sabbatical after 10 years of service (and every 5 years thereafter).
401(k) with Company Match up to 6% of pay after 6 months of service.
Paid Parental Leave and lifetime Fertility Benefit reimbursement up to $10,000 (includes adoption or surrogacy).
Employee Assistance Program.
Critical Illness, Accident, Hospital Indemnity, Pet Insurance and Legal Plans.
Charitable giving program and benefits.
*Benefits offered for full-time employees. For Union and Prevailing Wage roles, compensation and benefits may vary from the listed information above due to Collective Bargaining Agreements and/or local governing authority.
Greystar will consider for employment qualified applicants with arrest and conviction records.
Important Notice: Greystar will never request your banking details or other sensitive personal information during the interview process. Greystar does not conduct any interviews via text or messaging, and all communication will come from official Greystar email addresses (@greystar.com). If you receive suspicious requests, please report them immediately to [email protected].
Recommended Jobs
On Call Substitute Teacher-SST Advancement
Job Description Job Description Position: Substitute Department/Campus: Campus Reports to: Principal FLSA Status: Exempt Role/ Salary Band: $150 per day Job Type F…
LEAD BARISTA (FULL TIME AND PART TIME)
Job Description Job Description We are hiring immediately for full time and part time LEAD BARISTA position. Location : Lone Star College - 3200 College Park Drive, Conroe, TX 77384. Not…
Business Development Executive - Power Generation
JOB DESCRIPTION PRIMARY RESPONSIBILITIES Work closely with the ISE executive team to create and implement business development strategies with a focus on power generation customers. This inc…
Bilingual Production Line Leads - IMMEDIATE HIRE
Production Team Lead (Food Production) Lewisville, TX Hours: 5:00AM - 1:30PM or until finished. M-F including weekends when needed. Pay Rate: $18/hr - $19/hr Must be willing to work under v…
Front Office Manager
Job Description Job Description Job Title: Front Office Manager Department: Rooms Supervisor: Assistant General Manager and General Manager Summary The Hotel Front Office Manager over…
Housekeeper - Killeen, TX
Overview: We are looking for a reliable and detail-oriented Housekeeper to join our team. The ideal candidate takes pride in maintaining a clean, organized, and welcoming environment for our resid…
Assistant Professor, Clinical Faculty Appointment, Department of Emergency Medicine
ORGANIZATIONAL RELATIONSHIPS This is a faculty position responsible to the Chair of the Department of Emergency Medicine who reports to the Head of the Division of Internal Medicine. CHARACTERI…
CapEx Project Engineer
job summary: Our industrial gas services client is seeking a seasoned Capex Project Engineer to join their lean engineering team located approximately 30 minutes NW of the Fort Worth, TX area. In t…
Oracle Integration Cloud Technical Lead
Oracle Integration Cloud Technical Lead HIGHLIGHTS Location:Â Lewisville, TX - Hybrid Position Type: Â Direct Hire Hourly / Salary: Â Based on Experience Status: US Citizen/GCH Only …
Solutions Architect Associate
Solutions Architect Associate Austin, TX VirtuCrypt is seeking talented individuals with a passion for technology and an interest in business to join our Solutions Architect team in the position of …