Old National Bank Logo

Old National Bank

Cybersecurity Detection & Response Engineer

Posted 10 Hours Ago
Be an Early Applicant
In-Office
3 Locations
78K-153K Annually
Mid level
In-Office
3 Locations
78K-153K Annually
Mid level
Administers and improves Microsoft Sentinel and Defender XDR security monitoring and response platforms. Develops and tunes detections, performs threat hunting and complex investigations, automates SOC workflows using Sentinel playbooks and Logic Apps, and supports incident response. Partners with SOC analysts, IT teams, and third-party providers, researches emerging threats, applies AI-assisted security capabilities, and improves monitoring, response, documentation, and regulatory compliance.
The summary above was generated by AI
Overview

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. 


We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance.  401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization.  We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Responsibilities

The Cybersecurity Detection and Response Engineer administers, engineers, and improves ONB’s security monitoring and response platforms, with primary focus on Microsoft Sentinel and Microsoft Defender XDR. This role builds and tunes detections, supports complex investigations, partners with third-party monitoring providers to receive and triage escalations, automates repeatable security workflows, and uses modern tools—including AI-assisted analysis—to improve speed, accuracy, and consistency across security operations.

Salary Range

The salary range for this position is $77,900/yr - $153,000/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate’s relevant skills and professional experience, educational qualifications, and geographic location.

Key Accountabilities 

Detection Engineering & Threat Detection 

  • Develop and maintain detection use cases based on threat intelligence, emerging attack techniques, and MITRE ATT&CK. 
  • Conduct validation testing, threat hunting, and participate in red/purple-team testing to evaluate detection effectiveness. 
  • Identify monitoring gaps and implement improvements to coverage, telemetry, and response processes. 
  • Partner with SOC analysts, IT teams, and third-party providers to improve investigation quality and operational outcomes. 

Security Automation & SOAR 

  • Design and maintain Sentinel playbooks, Logic Apps, APIs, and automation workflows. 
  • Automate repetitive SOC processes to improve response speed, consistency, and analyst efficiency. 
  • Evaluate and responsibly apply AI-assisted capabilities to support investigation, summarization, triage, detection development, and operational improvement. 

Incident Response Support 

  • Serve as an escalation resource for complex security events and investigations. 
  • Support incident response through data analysis, evidence collection, and investigative support. 
  • Maintain practical playbooks, response procedures, and after-action improvement recommendations. 

Continuous Improvement 

  • Research emerging threats, vulnerabilities, defensive capabilities, and practical uses of AI in security operations. 
  • Support audit, regulatory, and governance needs including FFIEC, NIST, and applicable banking requirements. 
  • Continuously improve monitoring, response, automation, and operational processes. 

Key Competencies for Position 

  • Technical depth: Strong understanding of Sentinel, Defender XDR, KQL, detection engineering, automation, and incident response. 
  • Investigative judgment: Able to analyze complex events, identify root cause, and develop practical risk-based improvements. 
  • Communication and partnership: Clearly explains technical issues and works effectively across security, IT, risk, and business teams. 
  • Continuous improvement mindset: Seeks opportunities to improve security operations through automation, AI-assisted workflows, and better detection outcomes. 

Qualifications & Education Requirements 

Required Qualifications 

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or equivalent experience. 
  • Minimum 4 years of cybersecurity experience, including security monitoring, incident response, or detection engineering. 
  • Experience administering Microsoft Sentinel and Microsoft Defender XDR technologies. 
  • Strong KQL skills and experience developing detection logic, dashboards, or hunting queries. 
  • Experience with scripting or automation such as PowerShell, Python, APIs, Logic Apps, or similar tools. 
  • Working knowledge of MITRE ATT&CK, endpoint security, log analysis, and regulated security environments. 
  • Interest in responsibly using AI-assisted tools to improve security operations, investigation, automation, and documentation. 

Preferred Qualifications 

  • SC-200, AZ-500, CISSP, GCIH, GCIA, GCFA, or equivalent certifications. 
  • Experience in banking, financial services, or other regulated industries where security programs must be measured, documented, tested, and audit-defensible. 
  • Practical experience using AI-assisted tools to accelerate investigation, summarize security data, generate or refine detection logic, improve documentation, or support automation workflows. 
  • Hands-on experience with security automation, orchestration, AI-assisted analysis, or response technologies. 

Key Measures of Success / Key Deliverables 

  • Improves detection accuracy, reduces false-positive volume, and strengthens SOC visibility. 
  • Develops and maintains high-quality Sentinel detections, Defender XDR improvements, workbooks, dashboards, and automation workflows. 
  • Supports timely response to security events and complex investigations. 
  • Operationalizes new telemetry, monitoring capabilities, and AI-assisted efficiencies where appropriate. 
  • Proactively communicates status, risks, obstacles, and recommendations to leadership and stakeholders. 

Old National is proud to be an equal opportunity employer focused on fostering an inclusive workplace and committed to hiring a workforce comprised of diverse backgrounds, cultures and thinking styles. 


As such, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, status as a qualified individual with disability, sexual orientation, gender identity or any other characteristic protected by law. 


We do not accept resumes from external staffing agencies or independent recruiters for any of our openings unless we have an agreement signed by the Director of Talent Acquisition, SVP, to fill a specific position.


Our culture is firmly rooted in our core values.

We are optimistic. We are collaborative. We are inclusive. We are agile. We are ethical.

We are Old National Bank.  Join our team!

Old National Bank Avon, Illinois, USA Office

Avon, United States

Old National Bank Blue Island, Illinois, USA Office

Blue Island, United States

Old National Bank Chicago, Illinois, USA Office

8750 W Bryn Mawr Ave, Suite 1300, Chicago, Illinois, United States, 60631

Old National Bank Dundee, Illinois, USA Office

Dundee, United States

Old National Bank Gurnee, Illinois, USA Office

Gurnee, United States

Old National Bank Niles, Illinois, USA Office

Niles, United States

Similar Jobs

An Hour Ago
Remote or Hybrid
Chicago, IL, USA
141K-227K Annually
Expert/Leader
141K-227K Annually
Expert/Leader
Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Own new-logo acquisition and expansion across enterprise accounts for Mastercard Identity’s fraud and identity data products. Prospect independently, build qualified pipelines, run consultative multi-threaded sales cycles, navigate technical and risk buyers, and forecast against quota. The role targets large online businesses and fintechs, selling to fraud, payment risk, and trust and safety leaders while collaborating with Mastercard account teams and internal product and technology groups.
Top Skills: APIsWeb-Based Portals
An Hour Ago
In-Office
Chicago, IL, USA
31K-34K Hourly
Entry level
31K-34K Hourly
Entry level
AdTech • eCommerce • Food • Marketing Tech • Retail
Develops Power BI dashboards and reporting tools for strategic Own Brands initiatives. Supports data analysis, project milestone tracking, data validation, stakeholder communications, and cross-functional collaboration. The co-op translates business data into actionable insights, improves reporting quality, and provides visibility into catalog reviews, new item development, supplier transitions, item timeliness, and resets.
Top Skills: ExcelPower AutomatePower BI
3 Hours Ago
Hybrid
2 Locations
209K-262K Annually
Senior level
209K-262K Annually
Senior level
Fintech • Machine Learning • Payments • Software • Financial Services
Architect and scale enterprise software for experimentation, audience segmentation, and customer journey decisioning across marketing and messaging platforms. Build high-performance, AI-powered systems using machine learning, agentic workflows, distributed streaming, and personalization. Partner with data science, product, and engineering teams; mentor engineers; and drive technical excellence, experimentation, and innovation.
Top Skills: A/B TestingAgentic AiApache KafkaArtificial IntelligenceAWSDistributed StreamingGoGoogle Cloud PlatformJavaMachine LearningAzureMulti-Armed Bandit TestingOpen-Source FrameworksPythonSQL

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account