Talent.com
Lead Threat Detection Engineer
Lead Threat Detection EngineerMcKesson • Irving, TX, United States
Lead Threat Detection Engineer

Lead Threat Detection Engineer

McKesson • Irving, TX, United States
17 days ago
Job type
  • Full-time
Job description

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care.

What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you.

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection capabilities and tools. This team is responsible for building detection content, enabling integration, automation, enrichment, and performance of alerts. This role enables speed, quality, and coverage of threats for security operations and reduces risk to McKesson business operations.

Position Description / Responsibilities

  • Mature from a manual detection practice to a modern, automated, and standardized Detection-as-Code practice and infrastructure.
  • Develop use-cases based on intelligence, red team results, and incident data
  • Develop IOC workflows and a feedback loop for the Threat Intel Platform (TIP)
  • Write detection and correlation rules to identify threats across our stack
  • Assist in onboarding logs and identifying gaps in logs or alert results
  • Develop a deep understanding of data models, macros, indexes, sources, and field alias and the technology foundation our detection stack is built
  • Understand data schema / API standards, automation, and messaging systems
  • Bring a metrics-driven mindset to our rules, signals (IOCs), and alerts

Critical Requirements

  • Prioritize detection use-case and scope and create a logical rule
  • Ability to prioritize decisions to either write a rule and / or tune a tool / policy
  • Practical experience with threat Actor tracking, tactics, tools, and techniques and working closely with Intel, SOC, and Red Teams (Purple Teams)
  • Ability to measure detection coverage across common frameworks (e.g. NIST CSF, MITRE, KC) and simplify rules and configurations to optimize alerts
  • Ability to automate tasks via scripting, automating inputs and outputs of APIs, and programming skills such as python to enable detection engineering tasks
  • Exceptional interpersonal, organizational, and communication skills and ability to internalize and exemplify Mckesson core values.
  • Splunk SPL knowledge and SIEM experience or additional SIEM background
  • Following Qualifications would be advantageous :

  • 10+ years of professional experience in two or more domains, including : detection engineering, data engineering, incident response, threat hunting, threat intelligence.
  • Bachelor's degree in computer science, Information Security, Security Engineering, Statistics, or Data Science
  • Chronicle Experience, Splunk Certifications (1,2), Automation certifications (Security with Python SEC573), Sigma Rules
  • We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here.

    Our Base Pay Range for this position

    $139,000 - $231,600

    McKesson is an Equal Opportunity Employer

    McKesson provides equal employment opportunities to applicants and employees and is committed to a diverse and inclusive environment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age or genetic information. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page.

    Join us at McKesson!

    Create a job alert for this search

    Detection Engineer • Irving, TX, United States

    Related jobs
    Security Practice Lead (Nationwide)

    Security Practice Lead (Nationwide)

    Presidio Networked Solutions, LLC • Irving, TX, United States
    Full-time
    Presidio, Where Teamwork and Innovation Shape the Future.AtPresidio, we're at the forefront of a global technology revolution, transforming industries throughcutting-edge digital solutions and next...Show more
    Last updated: 30+ days ago • Promoted
    Senior SaaS Security Engineer

    Senior SaaS Security Engineer

    CoStar Group • Arlington, Texas, USA
    Full-time
    CoStar Group (NASDAQ : CSGP) is a leading global provider of commercial and residential real estate information analytics and online marketplaces. Included in the S&P 500 Index and the NASDAQ 100...Show more
    Last updated: 23 days ago • Promoted
    Security Engineer Incident Response, Kuiper Security Controls and Assurance

    Security Engineer Incident Response, Kuiper Security Controls and Assurance

    Amazon • Arlington, Texas, USA
    Full-time
    Project Kuiper is Amazons low Earth orbit satellite broadband network.Its mission is to deliver fast reliable internet to customers and communities around the world and weve designed the system wit...Show more
    Last updated: 23 days ago • Promoted
    Senior Director - Catastrophe Management Analytics

    Senior Director - Catastrophe Management Analytics

    Aon • Farmers Branch, TX, United States
    Full-time +1
    Aon is looking for a Senior Director - Catastrophe Modeling - Boston, NYC, Bloomington, Atlanta, Dallas or Chicago.Senior Director of Catastrophe Risk Management. As part of the Catastrophe Manageme...Show more
    Last updated: 29 days ago • Promoted
    Cyber Threat Analyst, Senior – Army (TSSCI)

    Cyber Threat Analyst, Senior – Army (TSSCI)

    Praescient Analytics • Arlington, Texas, USA
    Full-time
    Clearance Required : TS / SCI minimum (US Citizen).Praescient Analytics is a leader in delivering advanced analytic data engineering and technology integration solutions in support of the Department o...Show more
    Last updated: 20 days ago • Promoted
    Jr Industrial Control System Cyber Threat Intelligence Analyst with OTCTIThreat Hunt experience

    Jr Industrial Control System Cyber Threat Intelligence Analyst with OTCTIThreat Hunt experience

    Peraton • Arlington, Texas, USA
    Full-time
    Jr Industrial Control System Cyber Threat Intelligence Analyst.Federal Strategic Cyber programs.As a Jr Industrial Control System Cyber Threat Intelligence Analyst you will play a vital role in saf...Show more
    Last updated: 23 days ago • Promoted
    Security Engineer

    Security Engineer

    Bilt • Grapevine, TX, United States
    Full-time
    BILT - Global Brand Support Center, Grapevine, Texas 76051.BILT Incorporated is a fast-growing software-as-a-service company revolutionizing instructions and training for consumers and professional...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer Purple Team (Dallas Ft Worth Metro)

    Lead Security Engineer Purple Team (Dallas Ft Worth Metro)

    Gartner • Irving, Texas, USA
    Full-time
    Hiring near our Irving TX Center of Excellence with a flexible environment.Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients.We...Show more
    Last updated: 30+ days ago • Promoted
    CT Tech PRN

    CT Tech PRN

    Methodist Health System • Midlothian, TX, United States
    Full-time
    PRN (United States of America).In this highly technical allied imaging professional position, you'll collaborate with a multidisciplinary team to provide the very best imaging services, which inclu...Show more
    Last updated: 25 days ago • Promoted
    Project Engineer

    Project Engineer

    Motion Recruitment • Carrollton, TX, United States
    Full-time
    This is a 6 month W2 contract to hire with benefits! •.Lead technical engineering for integration, software, and hardware projects. Ensure project requirements and design standards are met.Collaborat...Show more
    Last updated: 8 days ago • Promoted
    IT Infrastructure & Security Engineer (Full-Time, Onsite)

    IT Infrastructure & Security Engineer (Full-Time, Onsite)

    Paragone Solutions • Euless, Texas, USA
    Full-time
    Secure IT Service Management Inc.IT Infrastructure & Security Engineer.The role involves troubleshooting hardware and software problems strengthening our IT environment and playing an active pa...Show more
    Last updated: 14 days ago • Promoted
    Threat Hunter / Detection Engineer

    Threat Hunter / Detection Engineer

    Elevance Health • Grand Prairie, TX, United States
    Full-time
    Threat Hunter / Detection Engineer.This role requires associates to be in-office 1 - 2 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and...Show more
    Last updated: 17 days ago • Promoted
    Manhattan Active Architect - 46686

    Manhattan Active Architect - 46686

    Cognizant • Waxahachie, TX, US
    Full-time
    Manhattan Active Warehouse Management Systems (MAWM) Architect.This role will influence strategic IT decisions and ensure seamless integration with supply chain systems. Assess client business requi...Show more
    Last updated: 10 days ago • Promoted
    USA_Senior Security Engineer

    USA_Senior Security Engineer

    Varite • Farmers Branch, TX, United States
    Full-time
    Role Description : Not Available.Competencies : Problem Solving, Identity and Access Management Implementation, Design & Architecture, Operational Risk Management. Strong expertise in IAM Concepts RBA...Show more
    Last updated: 14 days ago • Promoted
    Sr Security Engineer, Detection Engineering

    Sr Security Engineer, Detection Engineering

    Lennar • Irving, TX, United States
    Full-time
    Sr Security Engineer, Detection Engineering.Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communit...Show more
    Last updated: 16 days ago • Promoted
    Cybersecurity Intern

    Cybersecurity Intern

    Ever.Ag • Lewisville, Texas, USA
    Full-time
    Lewisville TX hybrid work model.This is a twelve (12) week internship program starting in May 2026.Candidates must be enrolled in college during the internship with a graduation date after August 2...Show more
    Last updated: 22 days ago • Promoted
    Target Security Specialist

    Target Security Specialist

    Target • Carrollton, Texas, USA
    Part-time
    Starting Hourly Rate / Salario por Hora Inicial : $17.Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture.They ...Show more
    Last updated: 17 days ago • Promoted
    Threat Modelling Engineer

    Threat Modelling Engineer

    ApTask • Irving, TX, United States
    Full-time
    The client is a digital business transformation company that helps organizations thrive in the modern digital economy.It combines strategy, consulting, customer experience, and engineering to drive...Show more
    Last updated: 17 days ago • Promoted