Threat Response Engineer (TRE)
Job description
About the role
You will own the full lifecycle of threat response for customer endpoints under active remediation, driving investigations from detection to verified cleanup. In this role, you leverage the world's largest security data lake to analyze complex compromises and ensure customer environments are restored to a secure state. You act as the trusted advisor to customers, translating technical findings into clear reports and actionable protection strategies. You harness AI tools to accelerate triage and response, embodying the company value of using intelligent systems to stay ahead of evolving threats. You work autonomously yet collaborate closely with Detection Engineering, Threat Hunting, Intel, and Product teams to refine remediation playbooks. Your decisions directly impact the security posture of the customer base, and you are expected to innovate continuously on methods for timely threat remediation. You embrace ambiguity and build meaningful solutions in a fast-paced, dynamic environment where impact matters more than activity.
Key facts
What you'll do
Investigate detected threats across customer environments using security products to analyze, contain, and remediate compromises effectively.
Provide customers with thorough reports of actions taken, ensuring clarity on environment cleanup and protection strategies to build trust and transparency.
Identify indicators of compromise, analyze attack paths, and implement effective response strategies to enhance the security posture of the customer base.
Collaborate with Detection Engineering, Threat Hunting, Intel, and Product teams to develop innovative methods for timely threat remediation and share findings to improve processes.
Prioritize and execute tasks in a fast-paced operational environment while participating in a 24x7 on-call rotation to address urgent incidents promptly.
Leverage AI tools to accelerate triage, analysis, and remediation steps, integrating new technologies to augment problem-solving and daily workflows.
Translate complex technical findings into professional documentation and clear communication for customers, ensuring they understand the steps taken to secure their environments.
Monitor evolving threat landscapes and use the world's largest security data lake to proactively identify trends that inform better response strategies.
Validate remediation success by confirming endpoint integrity and verifying that threats are fully eradicated without disrupting business operations.
Continuously seek opportunities to improve response playbooks, automate repetitive tasks, and drive higher quality outcomes for the customer base.
Serve as a technical advisor to customers, guiding them through remediation activities and helping them adopt best practices for future protection.
Maintain a bias for action by navigating between high-level strategy and hands-on execution to resolve incidents efficiently.
Uphold transparency and constructive debate within cross-functional teams to arrive at the best ideas faster and refine response capabilities.
Demonstrate ownership by taking responsibility for end-to-end threat response engagements and following through to verified closure.
Requirements
You thrive in a dynamic, fast-paced environment, viewing ambiguity not as a hindrance but as the raw material to build meaningful solutions to complex problems.
You act like an owner with a strong passion for the mission and a bias for action, navigating seamlessly between high-level strategy and hands-on execution to drive results.
You are a natural problem-solver who is energized by finding solutions to complex technical challenges, knowing that tackling hard problems delivers the biggest impact for customers.
You are a lifelong learner with a true growth mindset, actively seeking feedback to continuously develop yourself and become a stronger teammate in high-accountability situations.
You are driven by innovation, possessing a deep curiosity for how things work and a belief in the power of technology to accelerate digital transformation and security outcomes.
You have strong analytical and problem-solving skills demonstrated through direct experience responding to security events and threats in live customer environments.
You possess experience with Endpoint Detection and Response (EDR) products including CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or CarbonBlack and familiarity with Identity security technologies that are foundational to modern endpoint security.
You have a foundational understanding of internal system functionality for Windows and MacOS operating systems, enabling you to investigate issues at the system level.
You demonstrate curiosity and active exploration of AI tools, with a proven history of integrating new technologies to enhance daily workflows and augment problem-solving in security operations.
You communicate professionally and articulately, with the ability to provide clear technical documentation that supports customer understanding and trust.
You can work Monday through Friday from 6:00am to 2:00pm MT and participate in a recurring, monthly on-call rotation to support incident response needs.
You are committed to transparency and value constructive, honest debate within cross-functional teams to arrive at the best ideas quickly.
You build high-performing partnerships with Detection Engineering, Threat Hunting, Intel, and Product teams to improve the speed and quality of threat remediation.
You maintain a bias for execution, taking ownership of end-to-end threat response while navigating between strategic planning and tactical implementation.
You embrace the company value of impact over activity, ensuring that every action you take drives measurable outcomes for customers.
Practical notes
This is a Remote (USA Only) role.
You will participate in a 24x7 on-call rotation and a recurring, monthly on-call rotation.
Work hours are Monday through Friday, 6:00am to 2:00pm MT.
The position reports to the Senior Manager, Threat Response Engineering in the ZSS
Security Services department.