Windows Detection Engineering Manager
Core
Leading a team to build advanced Windows behavioral detections and in-memory traps for an AI-native endpoint security platform.
Role type
Manager of Detection Engineering (Windows)
Builds
Production behavior-based detection capabilities and attack simulation tools for SentinelOne's Endpoint Protection platform.
Domain
Cybersecurity / Endpoint Security / Windows Internals
Deliverable
production ML models | product features
Required skills
Leading detection engineering teams, writing behavioral detection rules, deep understanding of Windows Internals (processes, threads, virtual memory), C++ development, scripting in Lua
Preferred skills
Experience leading researchers, modern C++ expertise, knowledge of AV/EDR internals
Technologies
C++, Lua, Windows OS
Responsibilities
Manage detection engineers and guide R&D of detection rules and infrastructure; Drive detection of new malware/exploits via the Endpoint Protection platform; Lead development of attack tools and PoCs for exploitation attacks; Overcome technical challenges in detecting newest attacks; Influence design of disruptive security products
Seniority
Manager, hands-on technical leadership