CareerPlanSign in

Lead Cyber Threat Management Analyst

United States of America, Richmond, Virginia💼 Full-time🗓 2026-09-21 → 2026-09-26

Core

Lead the design, development, and continuous improvement of advanced threat detection capabilities across the enterprise, translating emerging threats into practical detection strategies.

Role type

Senior IC threat detection engineer (security operations)

Builds

Scalable detection logic, operationalized threat intelligence, and automated security workflows

Domain

Cybersecurity, Threat Detection, Security Operations

Deliverable

production ML models | product features

Required skills

Threat detection engineering, SIEM/EDR/cloud-native security platforms, MITRE ATT&CK framework, threat intelligence operationalization, Python/PowerShell scripting, security log/telemetry analysis, adversary TTPs understanding, detection automation, incident response collaboration, technical leadership/mentoring

Preferred skills

Cloud security (Azure/AWS/GCP), SOAR/XDR, threat hunting, detection-as-code, security data enrichment pipelines, AI-enabled security tools

Technologies

SIEM, EDR, SOAR, XDR, Python, PowerShell, MITRE ATT&CK, Azure, AWS, GCP

Responsibilities

Architect and maintain scalable threat detection logic across enterprise security platforms; Design and tune detection content to identify threats while minimizing false positives; Map detections to MITRE ATT&CK to assess coverage and identify gaps; Operationalize threat intelligence into actionable monitoring strategies; Collaborate with IR, Threat Intel, and Engineering teams to validate detection effectiveness; Analyze security logs and telemetry to identify malicious activity; Lead development of detection workflows and automation; Mentor junior detection engineers and analysts; Contribute to the strategic direction of the Threat Detection program

Seniority

Senior, hands-on IC with leadership responsibilities

Sourced via workday · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.