Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Harvey

Director of Detection and Response

Harvey

. Build and lead the Detection and Response organization .

Posted 10/8/2026full-timeNew York City • New York • United StatesLead💰 $280,000 - $385,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in building and leading Detection and Response teams, with a strong focus on incident response, threat hunting, and digital forensics. Capable of establishing technical direction and fostering collaboration across cross-functional teams while maintaining composure and integrity during sensitive investigations.

Highest-signal resume keywords
Detection And Response LeadershipIncident Response ExperienceCloud Infrastructure KnowledgeThreat Hunting ExpertiseDigital Forensics Skills

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection EngineeringIncident ResponseThreat IntelligenceForensic ToolingResponse AutomationTelemetryInvestigation ToolsSecurity EngineeringAI-Assisted InvestigationEscalation Path Development
Soft Skills
Clear CommunicationComposure Under PressureIntegrityDiscretionTeam Leadership
Tools & Technologies
Cloud EnvironmentsEndpoint SecurityIdentity ManagementSaaS PlatformsApplication Security
Industry Keywords
Security IncidentsCrisis ManagementRegulatory CompliancePrivileged-Access GovernanceCustomer Data Protection

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Build and lead the Detection and Response organization
  • Hire and develop detection engineers, incident responders, and technical leaders
  • Establish ownership, team culture, roadmap, staffing plan, and investment decisions
  • Lead responses to major security incidents, including investigation, containment, recovery, and executive communication
  • Build severity criteria, escalation paths, playbooks, sustainable 24/7 coverage, and incident commander development through exercises
  • Set technical direction for telemetry, detection pipelines, forensic tooling, and response automation across cloud, endpoint, identity, SaaS, and application environments
  • Apply software engineering practices to test detections, improve signal quality, and reduce manual work
  • Evaluate AI-assisted investigation with measurable quality and appropriate human oversight
  • Use threat intelligence, threat hunting, and attacker perspective to prioritize meaningful threats
  • Partner with offensive security and platform owners to validate coverage and close blind spots
  • Partner with Engineering, IT, Legal, Privacy, Communications, and Customer Trust on sensitive investigations and crisis decisions
  • Establish escalation and decision authority, preserve evidence, and provide findings for Legal-led notification and disclosure decisions
  • Prepare cross-functional responders for broader incident support
  • Drive blameless reviews and ensure corrective actions have owners, deadlines, and verified outcomes
  • Measure detection coverage, time to detect and contain, recurring failure modes, and responder workload
  • Use metrics to guide investments and reduce customer impact

Requirements

What you’ll need
  • Experience building and leading Detection and Response, incident response, or security engineering teams in a technology company with complex production systems
  • Record of hiring strong engineers, developing technical leaders, and scaling teams and operating models
  • Deep incident response experience and demonstrated judgment during serious security events
  • Ability to lead investigations with incomplete information, make timely containment decisions, and communicate clearly with executives, engineers, and business partners
  • Composure, integrity, and discretion during sensitive investigations and decisions under scrutiny
  • Strong technical foundations in cloud infrastructure, operating systems, networking, identity, and attacker tradecraft
  • Depth in detection engineering, threat hunting, or digital forensics
  • Understanding of investigations across corporate and production environments
  • Experience building detection platforms, investigation tools, or response automation
  • Ability to evaluate architecture and code and guide senior engineers
  • Ability to make practical build, buy, or retire decisions
  • Ability to turn business risk into a focused strategy and deliver it through influence and partnership
  • Experience protecting enterprise SaaS, sensitive customer data, or AI/ML environments is especially valuable
  • Experience investigating insider threats, partnering on privileged-access governance, or leading response under regulatory and public scrutiny is especially valuable
  • Ability to work from the New York office 3 days per week as part of Harvey’s hybrid work model

Benefits

Comp & perks
  • Equity plan
  • Comprehensive health, dental and vision coverage
  • Retirement benefits with 401(k) match up to 4%
  • Flexible PTO
  • Up to 4 applications to Harvey in any 30-day period
  • Opportunity to reapply after 90 days if a previous application was unsuccessful
  • Reasonable accommodations for applicants with disabilities