We are seeking a dynamic and experienced Senior Manager of Cybersecurity Detection Engineering to spearhead our team of Detection Engineers. In this critical role, you will drive the design, implementation, and maintenance of cutting-edge detection capabilities to protect our organization from emerging cyber threats. You will play a pivotal part in enhancing our Cyber Defense practice, enabling swift threat responses and automated remediation.
Your responsibilities will include developing a robust strategy for the Detection Engineering program, establishing metrics to showcase continuous improvement, and ensuring our detection systems remain optimized for performance and effectiveness. The ideal candidate will have expert-level knowledge in SIEM implementation, SOAR, Incident Response, Threat Intelligence, and the ability to analyze data-driven decisions while showcasing strong communication and leadership skills.
Key Responsibilities :
- Develop and define the detection engineering strategy, roadmap, and objectives for the team.
- Design and implement advanced threat detection techniques utilizing tools such as SIEM, EDR, NDR, and SOAR platforms.
- Create innovative custom detection rules, automated remediation processes, playbooks, and alerts tailored to our threat landscape.
- Utilize industry-standard MITRE frameworks to assess detection coverage and address any gaps.
- Continuously monitor and enhance detection systems for performance and scalability.
- Collaborate with the Threat Detection and Response team to bolster our cybersecurity capabilities in managing and responding to threats effectively.
- Conduct attack simulation testing to evaluate use case efficacy while working with the Vulnerability Management team.
- Manage and maintain SIEM and log ingestion infrastructure in collaboration with Cyber Defense Engineering.
- Assess, tune, and refine detection capabilities as necessary.
- Maintain comprehensive operational guidelines, diagrams, and documentation for security detection and response.
Incident Response Collaboration :
Work closely with the incident response team for rapid detection and containment of cyber threats.Provide technical expertise to develop detection use cases during high-severity security incidents.Enhance detection and response processes based on insights gained from past incidents.Offer off-hour support when needed for security administration, detection, and response activities.Threat Intelligence Integration :
Leverage threat intelligence to improve detection capabilities and proactively mitigate risks.Analyze new and emerging threat vectors to refine detection strategies.Stakeholder Collaboration :
Partner with Cybersecurity, Engineering, and Product teams to align detection strategies with our organizational goals.Effectively communicate detection capabilities and findings to both technical and non-technical stakeholders, including executive leadership.Governance and Compliance :
Ensure that all detection processes and tools comply with regulatory requirements and industry standards such as GDPR, PCI-DSS, and NIST.Document detection strategies, processes, and configurations comprehensively.Professional Technology Skills :
Deep experience building scalable organizations focused on world-class threat detection capabilities.Technical proficiency in executing security investigations across endpoints, cloud, identity, network, and email threats.Collaborate with internal IT teams and external MSSPs for developing and operationalizing Detection Engineering use cases.Hands-on experience with Detection & Response tools related to network, endpoints, cloud, and identity.Utilize security Threat Intelligence to uncover new threats.Lead initiatives to enhance security monitoring and response capabilities.Possess a solid background in security engineering and architecture to implement effective monitoring.Strong knowledge of Linux, MacOS, and Windows operating systems.Communicate security issues effectively with management and various stakeholders.Maintain operational metrics that foster team efficiency and quality, along with detection use case configurations and standards.Passionate about mentoring individuals aspiring to grow in detection engineering careers.Build and manage relationships with organizational leaders, establish a roadmap, and drive initiatives to completion.Understand Machine Learning concepts as they relate to predictive analytics.Qualifications :
Bachelor's degree in Computer Science or equivalent with 8+ years of relevant industry experience, or other combinations of education and experience.Demonstrated multi-cloud security experience across AWS, Azure, and GCP.Expert knowledge in Detection Engineering and Security Operations.3+ years of management or leadership experience with direct people management responsibilities.Strong background in Information Security, Network Security, Security Monitoring, and Incident Response.Experience developing SIEM / SOAR detection and automation use cases.Proficient with industry-standard security technologies such as Threat Intelligence, Firewalls, SASE, IPS, Endpoint Security, DLP, and Data Lakes.In-depth understanding of the attack kill chain and diamond model.5+ years of experience in Incident Response or Security Operations.3+ years of leadership experience within a SOC or similar environment.Located within commuting distance to North Hills NY or Atlanta GA, with availability to work onsite 3 times a week.U.S. work authorization without sponsorship required.Desirable Qualifications :
Relevant professional certifications such as GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA.Experience in Development, Dev Ops, Engineering, Networking, or System Administration.Compensation : The base salary for this role ranges from $173,900.00 to $289,800.00, with potential additional compensation through an incentive program.
Benefits : We offer eligible employees flexible vacation time, seven paid holidays, and up to 160 hours of paid wellness time annually. Additional paid time off is available for bereavement leave, voting, jury duty, volunteer activities, military leave, and parental leave.