Director, Detection Engineering and Automation
Core
Lead the Detection Engineering and Automation function to establish a center of excellence for high-fidelity detections across endpoint, identity, network, and cloud environments, reducing risk and improving operational response.
Role type
Senior leadership IC (Director) with people management responsibilities
Builds
Scalable detection platforms, automation workflows (SOAR/SIEM/EDR), and cloud-native detection capabilities
Domain
Cybersecurity / Threat Detection / Cloud Security
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Detection engineering, Security operations, Threat intelligence, People leadership, Risk quantification, Adversary tactics (MITRE ATT&CK), Cross-functional alignment, Cloud security, Detection-as-code, Executive communication
Preferred skills
Enterprise-scale detection platform evaluation, Threat hunting operationalization, Financial services experience, Version-controlled detection pipelines, Automation efficiency improvement
Technologies
SIEM, EDR, SOAR, AWS, GCP, Azure
Responsibilities
Define and execute detection engineering strategy, Lead and scale a team of ~14 engineers and 1 manager, Own the end-to-end detection lifecycle, Drive automation integration across SOAR/SIEM/EDR, Mature the detection platform with scalable tooling, Lead cloud detection capability development, Partner cross-functionally with SecOps/Threat Intel/SIRT, Define and track detection metrics, Represent the function in senior leadership forums
Seniority
Director, strategic leadership and team management