Detection Engineer, Manager
Core
Manager-level Detection Engineer owning end-to-end detection coverage for the Endpoint domain, leveraging AI/ML and Detection-as-Code to protect customers and assets.
Role type
Manager-level Individual Contributor (IC) Detection Engineer
Builds
Automated threat detections, high-fidelity alerts, and coverage gap analysis for the Endpoint threat surface
Domain
Cybersecurity, Endpoint Security, Threat Detection
Deliverable
production ML models | product features
Required skills
Endpoint security expertise, EDR telemetry analysis, SQL/data querying at scale, Red Team methodologies, ML/data science concepts for security, Technical leadership
Preferred skills
Python, Data science techniques (anomaly detection), CI/CD workflows, Databricks/Apache Spark, Detection-as-Code (YAML), Endpoint forensics, Malware triage
Technologies
GitHub, CI/CD pipelines, MITRE ATT&CK, CrowdStrike Falcon, SentinelOne, Microsoft Defender, Sysmon, Windows Event Logs
Responsibilities
Lead design and maintenance of detection rules using Detection-as-Code methodologies; Design and build high-fidelity behavioral detections identifying adversary patterns; Partner with business leaders and CSOC to ensure robust monitoring; Mentor engineers on security concepts and AI-driven workflows; Conduct hypothesis-driven threat research to identify coverage gaps; Manage full lifecycle from telemetry onboarding through alert deployment and tuning.
Seniority
Manager, hands-on technical leadership & mentorship