Logo for Greystar

Senior Detection & Response Engineer

Role overview

Qualifications

  • 6+ years in security operations, detection engineering, incident response, or a combined security engineering role
  • Hands-on digital forensics experience across endpoint and cloud, including artifact collection, timeline reconstruction, and evidence handling
  • Proficiency scripting and building automation (Python, PowerShell, KQL, or similar), including the effective use of AI tooling to accelerate development
  • Strong understanding of hybrid identity environments, including AD Connect sync behavior and Entra ID

Responsibilities

  • Design, build, test, and tune detection rules across our SIEM and security tooling, targeting real attack techniques observed in our environment
  • Build scripts, automation, and API integrations to accelerate detection engineering, investigation, and response workflows
  • Lead incident response investigations end to end, from triage through containment, eradication, and closure
  • Analyze Microsoft 365 and Entra ID log sources including interactive sign-ins, non-interactive sign-ins, audit logs, and the unified audit log

About the company

Greystar logo

Greystar

Real Estate Development & Management

Founded in 1993, Greystar provides world-class service in the residential rental housing industry. Our innovative vertically integrated business model integrates the management, development and investment disciplines of the rental housing industry on international, regional and local levels. This unique approach and our commitment to hiring the best professionals have resulted in record growth, making us one of the most respected and trusted global real estate companies. Because our vertically integrated business model includes both investment and service-oriented businesses, we’re able to maintain a constant presence in local markets and create value in all phases of the real estate cycle. Our international platform provides economies of scale, financial sophistication, institutional quality reporting and tremendous capital relationships, while our city offices provide local market expertise and execution. Supported by a global team of 20,000+ employees, Greystar’s experienced and cross-functional executive team boasts on average over 23 years of industry experience and provides a diverse perspective throughout the investment process. Over the years, Greystar has learned what’s important to people when it comes to a place to call home. That’s why we continually strive to provide beautiful living environments and innovative services that enhance the living experience. We take great pride in knowing that our homes are inviting places for residents to celebrate life’s important moments. Privacy Policy: https://www.greystar.com/privacy DMCA: https://www.greystar.com/terms-of-use#Copyright%20Infringement%20Policy

Company details

Company typeXLarge
IndustryReal Estate Development & Management
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

ABOUT GREYSTAR

Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing. Headquartered in Charleston, South Carolina, Greystar manages and operates over $300 billion of real estate in more than 265 markets globally with offices throughout North America, Europe, South America, and the Asia-Pacific region. Greystar is the largest operator of apartments in the United States, managing over one million units/beds globally. Across its platforms, Greystar has nearly $79 billion of assets under management, including over $35 billion of development assets and over $36.5 billion of regulatory assets under management. Greystar was founded by Bob Faith in 1993 to become a provider of world-class service in the rental residential real estate business. To learn more, visit www.greystar.com.

JOB DESCRIPTION SUMMARY

Greystar is seeking a Senior Detection & Response Engineer to join our Cybersecurity Operations team. This is a hybrid engineering and operations role for someone who can build detections, write code and automation, run full incident response investigations, and apply solid security engineering fundamentals across our environment. You will own the full loop: engineer the detection, respond to what it catches, and feed those lessons back into stronger coverage. This role spans EDR, IAM, SIEM, Data governance and works closely with our SOC.

JOB DESCRIPTION

Responsibilities 

  • Design, build, test, and tune detection rules across our SIEM and security tooling, targeting real attack techniques observed in our environment 

  • Build scripts, automation, and API integrations (using code and AI tooling) to accelerate detection engineering, investigation, and response workflows 

  • Lead incident response investigations end to end, from triage through containment, eradication, and closure 

  • Perform host and cloud forensic analysis, including disk, memory, and log artifact examination to reconstruct attacker activity and establish incident timelines 

  • Participate in an on-call rotation and perform hands-on alert and incident analysis 

  • Analyze Microsoft 365 and Entra ID log sources including interactive sign-ins, non-interactive sign-ins, audit logs, and the unified audit log 

  • Investigate EDR detections, perform process tree analysis, and recommend containment actions 

  • Triage and investigate escalations from the SOC 

  • Develop and maintain automated response playbooks 

  • Conduct root cause analysis and determine initial access, persistence, and exfiltration methods during investigations 

  • Apply security engineering fundamentals to improve identity security, conditional access, and endpoint posture 

  • Produce clear, executive-ready incident briefings, IOC documentation, and technical writeups 

  • Identify and tune false positive patterns to improve detection fidelity 

Required Qualifications 

  • 6+ years in security operations, detection engineering, incident response, or a combined security engineering role 

  • Demonstrated ability to build detections and understand the underlying logic, not just operate a tool 

  • Hands-on digital forensics experience across endpoint and cloud, including artifact collection, timeline reconstruction, and evidence handling 

  • Proficiency scripting and building automation (Python, PowerShell, KQL, or similar), including the effective use of AI tooling to accelerate development 

  • Working knowledge of attacker tradecraft and the ability to attribute activity based on TTPs 

  • Experience building or consuming API integrations across security and identity platforms 

  • Proficiency with EDR platforms 

  • Working knowledge of SIEM platforms and detection rule development 

  • Strong understanding of hybrid identity environments, including AD Connect sync behavior and Entra ID 

  • Experience investigating modern attack techniques including AiTM phishing, OAuth consent abuse, BEC, token replay, and living-off-the-land techniques 

  • Solid security engineering fundamentals across identity, endpoint, and cloud 

  • Willingness to participate in an on-call rotation and perform hands-on incident response 

  • Strong written communication and documentation discipline 

Preferred Qualifications 

  • Demonstrated use of AI tools (such as Claude, Copilot, or similar) to accelerate detection engineering, investigation workflows, scripting, and documentation 

  • Experience prompting and directing AI models to produce useful outputs in a security context, including log analysis, detection logic drafting, and incident timeline construction 

  • Familiarity with Microsoft Sentinel, including analytic rule development using KQL and automation via Logic Apps or Playbooks 

  • Familiarity with Microsoft Entra ID, Purview and Defender Suite 

  • Hands-on experience with CrowdStrike Falcon, including alert triage, process tree analysis, and prevention policy management 

  • Experience with identity security tooling such as Saviynt, Entra ID Protection, or similar IGA and privileged access platforms 

  • Prior experience in a large enterprise or managed security environment (5,000+ endpoints or 10,000+ users) 

  • Relevant certifications such as GCIA, GCIH, GCFE, GCFA, SC-200, AZ-500, or equivalent 

What You'll Work On 

This is a hands-on role with real ownership. You will build the detections that protect Greystar, respond to the incidents they surface, and continuously improve coverage based on what you learn in the field. You will write the automation that makes the team faster, investigate live compromises, and have direct input into detection strategy, SIEM direction, and identity security architecture. You will work directly with the Senior Manager of Cybersecurity Operations on initiatives including our SIEM migration to Microsoft Sentinel and ongoing detection engineering buildout. 

Additional Compensation:

Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location.

  • Corporate Positions: In addition to the base salary, this role may be eligible to participate in a quarterly or annual bonus program based on individual and company performance.

  • Onsite Property Positions: In addition to the base salary, this role may be eligible to participate in weekly, monthly, and/or quarterly bonus programs.

Robust Benefits Offered*:

  • Competitive Medical, Dental, Vision, and Disability & Life insurance benefits. Low (free basic) employee Medical costs for employee-only coverage; costs discounted after 3 and 5 years of service.

  • Generous Paid Time off. All new hires start with 15 days of vacation, 4 personal days, 10 sick days, and 11 paid holidays. Plus your birthday off after 1 year of service! Additional vacation accrued with tenure.

  • For onsite team members, onsite housing discount at Greystar-managed communities are available subject to discount and unit availability.

  • 6-Week Paid Sabbatical after 10 years of service (and every 5 years thereafter).

  • 401(k) with Company Match up to 6% of pay after 6 months of service.

  • Paid Parental Leave and lifetime Fertility Benefit reimbursement up to $10,000 (includes adoption or surrogacy).

  • Employee Assistance Program.

  • Critical Illness, Accident, Hospital Indemnity, Pet Insurance and Legal Plans.

  • Charitable giving program and benefits.

*Benefits offered for full-time employees. For Union and Prevailing Wage roles, compensation and benefits may vary from the listed information above due to Collective Bargaining Agreements and/or local governing authority.

Greystar will consider for employment qualified applicants with arrest and conviction records.

Important Notice: Greystar will never request your banking details or other sensitive personal information during the interview process. Greystar does not conduct any interviews via text or messaging, and all communication will come from official Greystar email addresses (@greystar.com). If you receive suspicious requests, please report them immediately to AskHR@greystar.com.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Greystar

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.