Live Nation produces more concerts, sells more tickets and connects more brands to music than anyone else in the world.
Lead Cyber Security Detection Engineer
Location
United States
Posted
2 days ago
Salary
Not specified
Seniority
Lead
Job Description
Job Summary:
WHO ARE WE?
Live Nation Entertainment is the world’s leading live entertainment company, comprised of global market leaders: Ticketmaster, Live Nation Concerts, and Live Nation Media & Sponsorship. Ticketmaster is the global leader in event ticketing with over 620 million tickets sold annually and approximately 10,000 clients worldwide. Live Nation Concerts is the largest provider of live entertainment in the world promoting more than 50,000 events annually for nearly 7,000 artists in 40+ countries. These businesses allow Live Nation Media & Sponsorship to create strategic music marketing programs that connect more than 1,200 sponsors with the 145 million fans that attend Live Nation Entertainment events each year. For additional information, visit www.livenationentertainment.com.
WHO ARE YOU?
Passionate and motivated. Driven, with an entrepreneurial spirit. Resourceful, innovative, forward thinking and committed. At Live Nation Entertainment, our people embrace these qualities, so if this sounds like you then please read on!
THE ROLE
We are searching for a Lead Cybersecurity Engineer to join our expanding security operations team at Live Nation Entertainment.
This role focuses on engineering detection and incident response capabilities. Key responsibilities include developing automated incident response playbooks and engineering high-fidelity detections within SIEM, EDR and cloud environments. The position also entails engineering and implementing security tools, security controls, and infrastructure in collaboration with system owners.
The role would work closely with cyber threat intelligence analysts to develop detections to evolving threat actor TTPs
WHAT THIS ROLE WILL DO
Collaborate with security analysts to create playbooks for triage and response for high fidelity detections.
Lead the development of orchestrations and automations that significantly reduce manual tasks
Perform expert-level intrusion and/or defensive analysis
Develop automated incident response playbooks.
Evaluate and improve current monitoring and detection capabilities to identify areas for improvement.
Engineer detections with SIEM and XDR using various query languages.
Engineer and implement security controls based on industry standards while continuously evaluating and enhancing our security infrastructure.
Collaborate with system owners to architect, configure, and implement security monitoring and defense tools to safeguard against security breaches, cyber threats, and unauthorized access.
Conduct adversary simulation testing and vulnerability scanning.
Assist in analyzing large and complex datasets to uncover anomalous behavior and potential threats.
Support the deployment and implementation of various security tools and technologies
WHAT THIS PERSON WILL BRING:
5+ years working in a security operations role
5+ years of writing custom SIEM detection queries and security automation logic
Experience working multiple concurrent operating environments
Advanced knowledge of the signals of both insider and external threat actors, their tactics and procedures, and how they evolve or change over time.
SME level knowledge of current cyber threats and how to detect them using SIEM, XDR, EDR, and cloud technologies.
Detection Development
Detection Enablement
Detection Effectiveness (Tuning, Validation, etc.)
Advanced usage of at least one query language(KQL, Splunk, CQL, SQL) and the ability to understand, analyze, and write code.
Thorough understanding of Identity Platforms—EntraID, Okta, CyberArk and major public cloud vendors—Azure, OCI, AWS, and GCP, both for development of detections, support investigations and determine secure solutions.
Work well under pressure and within time/budget constraints to solve problems or meet objectives.
Strong problem-solving and analytical thinking skills.
Strong curiosity and a desire to learn.
Ability to contribute in a collaborative global environment and team.
Ability to identify and address gaps in security telemetry and monitoring required
Capable of developing metrics reporting to support cyber operations teams
Proven experience investigating and responding to security incidents, contributing to post-incident analysis, and remediation efforts; across multiple environments
Willingness to work in an on-call rotation to support major incident response
Excellent analytical and problem-resolution skills
Ability to work independently, set own goals, work multiple tasks, and develop and train team members within a globally distributed environment required
WHY JOIN OUR TEAM:
A collaborative and inclusive environment focused on mentorship, diversity of thought, and continuous growth.
Remote-friendly and flexible work culture.
Exposure to a wide range of threat landscapes across live entertainment, e-commerce, and cloud infrastructure.
A chance to directly shape the maturity and impact of Live Nation’s global threat intelligence function.
BENEFITS & PERKS
Our motto is ‘Taking Care of Our Own’ through 6 pillars of benefits:
HEALTH: Medical, vision, dental and mental health benefits for you and your family, with access to a health care concierge, and Flexible or Health Savings Accounts (FSA or HSA)
YOURSELF: Free concert tickets, generous paid time off including paid holidays, sick time, and personal days
WEALTH: 401(k) program with company match, stock reimbursement program
FAMILY: New parent programs including caregiver leave and baby bonuses, plus fertility, adoption, foster, or surrogacy support
CAREER: Career and skill development programs with School of Live, tuition reimbursement, and student loan repayment
OTHERS: Volunteer time off, crowdfunding match
EQUAL EMPLOYMENT OPPORTUNITY
We aspire to build teams that reflect and support the fans and artists we serve. Every day we aim to promote environments where everyone can be themselves, contribute fully, and thrive within our company and at our events. As a growing business we will encourage you to develop your professional and personal aspirations, enjoy new experiences, and learn from the talented people you will be working with.
Live Nation is an equal opportunity employer. It hires and promotes employees based on their experience, talent, and qualifications for the job and does not tolerate discrimination toward employees based on age (40 and over), ancestry, color, religious creed (including religious dress and grooming practices), family and medical care leave or the denial of family and medical care leave, mental or physical disability (including HIV and AIDS), marital status, domestic partner status, medical condition (including cancer and genetic characteristics), genetic information, military and veteran status, political affiliation, national origin (including language use restrictions), citizenship, race, sex (including pregnancy, childbirth, breastfeeding and medical conditions related to pregnancy, childbirth or breastfeeding), gender, gender identity, and gender expression, sexual orientation, intersectionality, or any other basis protected by applicable federal, state or local law, rule, ordinance or regulation.
We will consider qualified applicants with criminal histories in a manner consistent with the requirements of the Los Angeles Fair Chance Ordinance, San Francisco Fair Chance Ordinance and the California Fair Chance Act and consistent with other similar and / or applicable laws in other areas.
Live Nation affords equal employment opportunities to qualified individuals with a disability. For this reason, Live Nation will make reasonable accommodations for the known physical or mental limitations of an otherwise qualified individual with a disability who is an applicant or an employee consistent with its legal obligations to do so. As part of its commitment to make reasonable accommodations, Live Nation also wishes to participate in a timely, good faith, interactive process with a disabled applicant or employee to determine effective reasonable accommodations, if any, which can be made in response to a request for accommodations. Applicants and employees are invited to identify reasonable accommodations that can be made to assist them to perform the essential functions of the position they seek or currently occupy. Any applicant or employee who requires an accommodation in order to perform the essential functions of the job should contact either the hiring manager for the role or a Human Resources representative to request the opportunity to participate in a timely interactive process.
HIRING PRACTICES
The preceding job description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
Live Nation recruitment policies are designed to place the most highly qualified persons available in a timely and efficient manner. Live Nation may pursue all avenues available, including promotion from within, employee referrals, outside advertising, employment agencies, internet recruiting, job fairs, college recruiting and search firms.
#LI-EF1
#LI-SM1
#LI-RemoteUnitedStates
Live Nation Entertainment will never request payment or equipment purchases as part of the hiring process. Recruiters will only contact candidates from official Live Nation or affiliated brand email domains.
Job Requirements
- 5+ years working in a security operations role.
- 5+ years of writing custom SIEM detection queries and security automation logic.
- Experience working in multiple concurrent operating environments.
- Advanced knowledge of the signals of both insider and external threat actors, their tactics and procedures, and how they evolve or change over time.
- SME level knowledge of current cyber threats and how to detect them using SIEM, XDR, EDR, and cloud technologies.
- Advanced usage of at least one query language (KQL, Splunk, CQL, SQL) and the ability to understand, analyze, and write code.
- Thorough understanding of Identity Platforms—EntraID, Okta, CyberArk and major public cloud vendors—Azure, OCI, AWS, and GCP.
- Strong problem-solving and analytical thinking skills.
- Strong curiosity and a desire to learn.
- Ability to contribute in a collaborative global environment and team.
- Proven experience investigating and responding to security incidents, contributing to post-incident analysis, and remediation efforts across multiple environments.
- Willingness to work in an on-call rotation to support major incident response.
- Ability to work independently, set own goals, work on multiple tasks, and develop and train team members within a globally distributed environment.
Benefits
- Medical, vision, dental and mental health benefits for you and your family, with access to a health care concierge, and Flexible or Health Savings Accounts (FSA or HSA).
- Free concert tickets, generous paid time off including paid holidays, sick time, and personal days.
- 401(k) program with company match, stock reimbursement program.
- New parent programs including caregiver leave and baby bonuses, plus fertility, adoption, foster, or surrogacy support.
- Career and skill development programs with School of Live, tuition reimbursement, and student loan repayment.
- Volunteer time off, crowdfunding match.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer
SpyCloudSpyCloud is a leader in digital identity protection, dedicated to preventing targeted cyberattacks and unmasking threat actors through innovative solutions. Fou
Experienced Security Engineer for SpyCloud's internal security team
This role is responsible for regional oversight of safety and security supporting Raytheon international operations, requiring coordination and implementation of security plans, programs, and strategies while providing operational support to business units. The manager will devise cost-effective security initiatives to implement global security standards, policies, and practices, and address specific program-related security requirements.
We’re looking for a Founding Security Engineer to build and lead our security program as we scale from Series A toward Series B. This is a hands-on role with leadership trajectory. You will work directly with our engineering and platform teams to design secure systems, lead com...
The intern will assist with supporting the assigned area, gaining practical application experience, and expanding their knowledge and skills base by performing job-specific tasks to assist with operations. They will also have the opportunity to observe the workplace and gain industry knowledge.


