CareerPlanGet AI match score →

Lead Threat Detection Engineer

USA, TX, Irving💼 Full-time💰 $139,000–$139,000🗓 2025-02-03 → 2026-07-30

Core

Building automated detection content, rules, and infrastructure to identify threats across McKesson's technology stack and reduce business risk.

Role type

Lead Threat Detection Engineer (Detection-as-Code)

Builds

Automated detection rules, IOC workflows, and alerting infrastructure for the Threat Intel Platform (TIP)

Domain

Cybersecurity / Threat Intelligence / SIEM

Deliverable

production ML models | product features | dashboards & analysis | infrastructure

Required skills

Detection engineering, Threat hunting, Incident response, Threat intelligence, Python scripting, SIEM operations, Log analysis, Data modeling, Automation, Metrics-driven analysis

Preferred skills

Chronicle experience, Splunk SPL, Sigma Rules, NIST CSF/MITRE/KC frameworks, Data engineering

Technologies

Splunk, Python, TIP, Chronicle, SIEM

Responsibilities

Mature manual detection to automated Detection-as-Code practice, Develop use-cases based on intelligence and incident data, Write detection and correlation rules, Automate tasks via scripting and API integration, Measure detection coverage against frameworks, Assist in onboarding logs and identifying gaps

Seniority

Senior, hands-on IC with strategic scope

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Workday ↗