bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesKKRThreat Detection & Response - Blue Team Lead

Threat Detection & Response - Blue Team Lead

KKR · New York or Boston · Hybrid · Active · $150,000–$180,000 / year · Greenhouse

Job facts

FieldValue
CompanyKKR
TitleThreat Detection & Response - Blue Team Lead
Normalized title-
Department / teamTechnology
LocationNew York, NY, United States
Work modelHybrid / Hybrid
Employment type-
Salary$150,000–$180,000 / year
Statusactive
ATS providerGreenhouse
Posted / first seen2026-02-25 / 2026-05-29
Changed / last seen2026-06-17 / 2026-06-23

Related slices

PageWhat it containsOpen
Company jobsActive postings from KKR.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Greenhouse.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Department jobsActive postings in Technology.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyKKR
Source9914599c-2a4e-495e-8684-be1970e59f3d
ATS providerGreenhouse

Description

COMPANY OVERVIEW KKR is a leading global investment firm that offers alternative asset management as well as capital markets and insurance solutions. KKR aims to generate attractive investment returns by following a patient and disciplined investment approach, employing world-class people, and supporting growth in its portfolio companies and communities. KKR sponsors investment funds that invest in private equity, credit and real assets and has strategic partners that manage hedge funds. KKR’s insurance subsidiaries offer retirement, life and reinsurance products under the management of Global Atlantic Financial Group. References to KKR’s investments may include the activities of its sponsored funds and insurance subsidiaries. TEAM OVERVIEW KKR's Technology organization is a group of passionate technologists and product managers, unified by a shared mission to deliver exceptional products and solutions that drive value for our stakeholders, clients, and investors. Our passion for technology and innovation fuels our commitment to creating high-quality, impactful solutions that address complex challenges and meet the evolving needs of our sophisticated businesses. Teamwork is at the core of the organization’s success. We thrive on open collaboration and continuous learning, driving a culture that values diversity of thought and collective achievement. Our global footprint enables us to integrate diverse perspectives into product and solution delivery, resulting in comprehensive, adaptable, and scalable solutions. We optimize for impact, prioritizing and delivering solutions with excellence while remaining agile in response to the evolving needs of our businesses. POSITION OVERVIEW We are seeking a Blue Team Lead to serve as KKR’s U.S. Regional Lead and escalation point for complex cyber incidents within the Threat Detection & Response (TD&R) function in our New York or Boston office. This is a senior incident response leadership role combining deep investigative expertise with ownership of incident command, containment strategy, stakeholder communication, and response readiness. This is an in-office position, 5 days per week. KKR operates in a hybrid environment today; however, our operating model is increasingly cloud-first and identity-first, with growing focus on runtime and SaaS as primary investigative surfaces. This role will help shape how we respond in that future state - partnering closely with our MSSP, internal Computer Incident Response Team (CIRT), and engineering counterparts to drive faster, more consistent outcomes. You will also be a key operational partner to the TDR SOC Engineer (SOC Engineering, Automation & Agentic Workflows) role. The Blue Team Lead defines the incident response requirements, validates that workflows and automation are usable under pressure, and ensures lessons learned translate into durable improvements across people, process, and technology. RESPONSIBILITIES Incident Leadership & Command (U.S. Regional Lead) Act as U.S. escalation lead / incident commander for high-severity incidents, owning response strategy, containment decisions, and coordination through resolution. Lead cross-functional response with internal CIRT, infrastructure/platform teams, cloud teams, identity teams, legal/compliance, and business stakeholders. Provide executive-ready briefings and situational updates during active incidents, clearly communicating risk, impact, tradeoffs, and next steps. Ensure post-incident reviews are completed and translated into measurable remediation and program improvements. Advanced Investigations (Cloud/Identity/Runtime First; Hybrid Aware) Perform and lead advanced investigations across endpoint, network, identity, cloud control plane, SaaS, and (as needed) on-prem telemetry. Drive evidence collection and preservation strategies appropriate for hybrid environments, including cloud-native logging and ephemeral workload considerations. Develop investigative narratives: attacker objectives, sequence of actions, impacted assets, containment efficacy, and residual risk. Readiness, Playbooks, and Exercising Own and continuously improve incident response playbooks (e.g., ransomware/extortion, BEC, cloud account compromise, token/key theft, data exfiltration, insider risk). Lead and coordinate exercises and simulations; ensure learnings become concrete improvements (process updates, training, tooling enhancements). Establish escalation criteria and decision frameworks (severity, containment triggers, business engagement, recovery prioritization). AI-Enabled Response & Analyst Acceleration (Operational Owner) Operationalize AI-assisted workflows to improve incident execution (e.g., alert/case summarization, timeline generation, correlation support, case documentation), ensuring strong governance, auditability, and human-in-the-loop controls. Partner with SOC Engineering to define requirements and validate that automation/agentic workflows reduce toil and time-to-contain without increasing operational risk or noise. Continuous Improvement, Threat-Informed Defense, and Partner Management Convert incident lessons-learned into durable improvements across enrichment, routing/prioritization, response plays, and coverage enhancements in partnership with SOC Engineering and ReliaQuest. Support threat hunting and purple-team efforts by shaping hypotheses and prioritizing validation based on real incident patterns and business risk (enablement and translation to controls - not primary hunt execution). Maintain strong operating rhythm with ReliaQuest and internal teams to ensure smooth escalations, clear responsibilities, and consistent response quality globally. Metrics & Reporting Help define, track, and improve operational KPIs such as MTTR, MTTC, time-to-triage, containment SLA adherence, repeat-incident drivers, and quality of post-incident actions. Provide insight-driven reporting to TD&R leadership on trends, systemic issues, and targeted investments needed to raise response maturity. QUALIFICATIONS 6+ years in Incident Response, Security Operations, or Blue Team roles, including leading high-severity incidents end-to-end. Proven ability to serve as an escalation lead and incident commander—calm, decisive leadership in ambiguous, high-pressure situations. Strong communication skills: able to translate complex technical details into clear, actionable updates for executives and stakeholders. Experience operating in cloud-forward enterprises, including hybrid environments spanning SaaS, cloud-native workloads, and on-prem systems. Strong familiarity with identity-centric security models and investigations (federated identity, IAM abuse patterns, token theft, conditional access signals). Working knowledge of cloud-native architectures (containers/Kubernetes, serverless, CI/CD) and the investigative/containment challenges they introduce. Experience partnering with MSSPs and distributed teams; comfortable operating in a hybrid SOC model (internal + ReliaQuest). Familiarity with MITRE ATT&CK and applying it to investigative thinking, readiness planning, and validation priorities. Experience designing, using, or validating automated response workflows (SOAR) and promoting safe automation patterns. Exposure to AI-assisted SOC/IR tooling, including governance considerations (data handling, audit logging, human approval, evaluation). Experience with purple teaming, detection validation, or adversary simulation platforms (e.g., Atomic Red Team, Caldera, Cymulate). (Preferred) Ability to influence engineering roadmaps (telemetry, enrichment, workflow improvements) based on operational pain points and incident learnings. (Preferred) IDEAL CANDIDATE PROFILE Incident leader: takes ownership, drives clarity, and brings structure to high-severity response. Technically deep and business-aware: understands attacker behavior and business impact equally well. Operationally disciplined: strong instincts for repeatability, playbooks, and learning loops. Collaborative and influential: can align MSSP + internal teams, and partner effectively with SOC Engineering and platform teams. Future-oriented: comfortable modernizing response for cloud-first and AI-enabled operating models. WHY JOIN US? This is a pivotal leadership role in a globally scaled Threat Detection & Response function at a leading investment firm. As U.S. Regional Lead, you will shape incident response outcomes for critical enterprise operations and directly influence how KKR modernizes response for a cloud-first, AI-enabled future. You’ll partner with a high-performing MSSP and an engineering-driven TDR team to improve readiness, accelerate containment, and raise the bar on response quality across the organization. This is the expected annual base salary range for this New York-based position. Actual salaries may vary based on factors, such as skill, experience, and qualification for the role. Employees may be eligible for a discretionary bonus, based on factors such as individual and team performance. Base Salary Range $150,000 — $180,000 USD KKR is an equal opportunity employer. Individuals seeking employment are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, sexual orientation, or any other category protected by applicable law. KKR will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email [email protected] . Emails sent for unrelated issues, such as following up on an application, will not receive a response. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access https://www.kkr.com/careers because of your disability. You can request reasonable accommodations by sending an email to [email protected] . Only emails left for this purpose will be returned. Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. This notice applies only to applicants and employees who work or will work in Massachusetts, in accordance with applicable state law.

Full job record

Job ID9da278db7b301fddd2fd93a7fd24e35d79ae4888
Org ID7227f5b6-0bf0-4a57-98d8-2cf9c00ec4f6
Source ID9914599c-2a4e-495e-8684-be1970e59f3d
Board ID9914599c-2a4e-495e-8684-be1970e59f3d
Providergreenhouse
Provider Job Key5665544004
TitleThreat Detection & Response - Blue Team Lead
Normalized Title
Statusactive
Activeyes
Location TextNew York or Boston
DepartmentTechnology
Team
Employment Type
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionNY
CityNew York
Salary RawSalary Range $150,000 — $180,000 USD KKR is an equal opportunity employer
Salary Min150,000
Salary Max180,000
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://www.kkr.com/careers/career-opportunities/post?gh_jid=5665544004
Apply URLhttps://www.kkr.com/careers/career-opportunities/post?gh_jid=5665544004
First Seen At2026-05-29 22:41:22Z
Last Seen At2026-06-23 07:36:16Z
Last Checked At2026-06-23 07:36:16Z
Last Changed At2026-06-17 07:36:45Z
Inactive At
Source Posted At2026-02-25 22:56:30Z
Source Updated At2026-06-16 20:09:58Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=greenhouse/board=stage/date=2026-06-23/2026-06-23T07-36-16-194Z-071da7feb5321084e093734942d3771a4b9c5e9e1d482668fda7d39f9b521f55.json
Event Fields
{
  "content_hash": "e92cfa681250199d8e6a14070855de77aed7c4081e5e085905094f0dbc08c326",
  "source_hash": "1acd47946e6c38551398d9e2469336c6e5cd36c79612003d3644cf69336348b1",
  "last_changed_at": "2026-06-17T07:36:45.178Z",
  "active_status": "active"
}
Parsed Structured
{
  "dedupe": null,
  "language": "en",
  "location": {
    "raw": "New York",
    "city": "New York",
    "region": "NY",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.75
  },
  "salary_max": 180000,
  "salary_min": 150000,
  "inferred_at": "2026-06-23T07:36:16.601Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York",
      "city": "New York",
      "region": "NY",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.75
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": "year",
  "workplace_type": "hybrid",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "title": "Threat Detection & Response - Blue Team Lead",
  "offices": [
    {
      "id": 4003382004,
      "name": "New York",
      "location": "New York, New York, United States",
      "child_ids": [],
      "parent_id": 4003379004
    }
  ],
  "language": "en",
  "location": {
    "name": "New York or Boston"
  },
  "metadata": [],
  "updated_at": "2026-06-16T16:09:58-04:00",
  "departments": [
    {
      "id": 4007025004,
      "name": "Technology",
      "child_ids": [
        4085005004,
        4085014004,
        4085018004,
        4085017004,
        4085016004,
        4034513004,
        4034512004,
        4034518004,
        4034517004,
        4118525004,
        4034515004,
        4007032004,
        4007034004,
        4034520004,
        4007031004,
        4007030004,
        4007029004,
        4007028004,
        4007027004,
        4007026004,
        4007033004,
        4034519004,
        4034514004,
        4085007004,
        4085006004,
        4085013004,
        4117443004,
        4117442004
      ],
      "parent_id": null
    }
  ],
  "company_name": "Careers at KKR",
  "requisition_id": 4987082004,
  "first_published": "2026-02-25T17:56:30-05:00",
  "application_deadline": null
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/9da278db7b301fddd2fd93a7fd24e35d79ae4888?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/7227f5b6-0bf0-4a57-98d8-2cf9c00ec4f6JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/9914599c-2a4e-495e-8684-be1970e59f3dJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/9da278db7b301fddd2fd93a7fd24e35d79ae4888/eventsJSON