Detection Engineer Manager, Cyber Security
Core
Lead the design, development, and maintenance of AI-driven cybersecurity detections and detection-as-code workflows to automate threat identification and reduce false positives across endpoint environments.
Role type
Manager, Detection Engineering (Cyber Security)
Builds
Automated detection logic, behavioral detection rules, and detection architecture for endpoint threat surfaces.
Domain
Cyber Security / Threat Detection / Endpoint Security
Deliverable
production ML models
Required skills
Endpoint telemetry analysis, Detection-as-Code (DaC), MITRE ATT&CK framework, Threat research methodologies, Machine learning for security, Python, EDR platform management, Security incident analysis, Stakeholder risk management, Technical mentorship
Preferred skills
Threat hunting, Cybersecurity frameworks (NIST CSF, CMMC, FedRAMP), Security tooling (Splunk, Qualys, AWS Security Hub), Data science concepts, Endpoint forensics, Adversary emulation, Security certifications (CISSP, GCIA, etc.)
Technologies
LLMs, GenAI, CI/CD pipelines, MITRE ATT&CK, CrowdStrike Falcon, SentinelOne, Microsoft Defender, Sysmon, Windows Event Logs, Splunk, Qualys, AWS Security Hub
Responsibilities
Leverage LLMs and machine learning to automate detection logic and summarize attack chains; Lead the design and maintenance of detection rules using DaC methodologies; Design high-fidelity behavioral detections to identify adversary patterns; Utilize MITRE ATT&CK to visualize and close endpoint coverage gaps; Conduct hypothesis-driven threat research to translate attacker techniques into detections; Own end-to-end detection coverage lifecycle from telemetry onboarding to alert deployment; Partner with business leaders and CSOC to ensure robust monitoring and compliance; Serve as a technical bar-raiser and mentor engineers on detection engineering best practices.
Seniority
Manager, strategic leadership with hands-on technical execution