Lead Threat Detection Engineer
Core
Building automated detection content, rules, and infrastructure to identify threats across McKesson's technology stack and reduce business risk.
Role type
Lead Threat Detection Engineer (Detection-as-Code)
Builds
Automated detection rules, IOC workflows, and alerting infrastructure for the Threat Intel Platform (TIP)
Domain
Cybersecurity / Threat Intelligence / SIEM
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
Detection engineering, Threat hunting, Incident response, Threat intelligence, Python scripting, SIEM operations, Log analysis, Data modeling, Automation, Metrics-driven analysis
Preferred skills
Chronicle experience, Splunk SPL, Sigma Rules, NIST CSF/MITRE/KC frameworks, Data engineering
Technologies
Splunk, Python, TIP, Chronicle, SIEM
Responsibilities
Mature manual detection to automated Detection-as-Code practice, Develop use-cases based on intelligence and incident data, Write detection and correlation rules, Automate tasks via scripting and API integration, Measure detection coverage against frameworks, Assist in onboarding logs and identifying gaps
Seniority
Senior, hands-on IC with strategic scope