Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity at Blackstone in Miami, FL

  • Company: Blackstone
  • Location: Miami
  • Salary: $110K – $170K
  • Job type: full time
  • Workplace: onsite
  • Posted: 2026-09-25

Apply for this role

All open roles at Blackstone

Job description

Blackstone is the world’s largest alternative asset manager. Blackstone seeks to deliver compelling returns for institutional and individual investors by strengthening the companies in which the firm invests. Blackstone’s over $1.3 trillion in assets under management include global investment strategies focused on real estate, private equity, credit, infrastructure, life sciences, growth equity, secondaries and hedge funds. Further information is available at www.blackstone.com . Follow @blackstone on LinkedIn , X (Twitter) , and Instagram . Business Unit Overview: Blackstone Technology & Innovations (BXTI) is the technology team at the core of each of Blackstone's businesses and new growth initiatives. Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency and improve transparency within the firm and across our broad community of investors and portfolio companies. BXTI is fast paced and entrepreneurial: our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one. We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence. We collaborate to find the best answers for our customers and for Blackstone. We are critical to the firm maintaining its competitive edge. Position Overview: The Alert, Detection, and Response Associate is a Tier 2 incident responder on the Alert, Detection & Response team, the front line of Blackstone's cyber defense. The Associate is responsible for detecting, investigating, and responding to information security incidents across, but not limited to, email, endpoint, identity, network, and cloud. The Associate must have strong working knowledge of incident response procedures, the technology used to execute them, as well as an understanding of how to leverage AI tools effectively. The Associate manages an incident queue, carrying cases from intake through investigation, containment, and closure, and handles the escalations raised by Tier 1 analysts. Day to day the Associate works alongside the Tier 1 and Tier 2 incident response analysts on the team, taking on the harder cases and bringing in additional responders as an investigation grows. The Associate is also expected to turn what each case teaches the team into lasting improvement, feeding findings back into detections, playbooks, and automation so the same problem does not have to be worked twice. Analysts and Associates on this team are expected to play an active role in shaping investigative processes and detection capabilities, with the opportunity to see innovative ideas quickly translated into operational solutions. Responsibilities: Manage an incident queue, carrying cases from intake through investigation, containment, and closure across, but not limited to, email, endpoint, identity, network, and cloud Handle escalations raised by Tier 1 analysts, taking on the more complex investigations and bringing in additional responders as scope grows Investigate in the firm's SIEM, writing and refining searches to pivot across endpoint, authentication, email, network, and cloud telemetry Conduct endpoint investigation, host containment, and live response in the firm's EDR platform, including process lineage, persistence review, and artifact collection Investigate email threats end to end, covering phishing, business email compromise, and malicious attachments and links, using header and message trace analysis to scope who was targeted and drive remediation across affected mailboxes Investigate cloud and identity compromise, covering credential misuse, role and privilege abuse, session hijacking, and multi-factor bypass Investigate third-party and SaaS provider compromise, questioning the provider's incident response team to establish containment status and what Blackstone data was affected, independently scoping the firm's

Alert, Detection, and Response Engineer, Associate - Blackstone Cybersecurity on JobPost.