
Manager, Detection Engineering – Rapid Response Team
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Lead the Rapid Response Team tasked with providing swift and dependable detection coverage for emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps.
• Personally develop, evaluate, and drive detections to merge and release, particularly during threat surges and for the most challenging threats.
• Lead, mentor, and expand a team of five or more Senior to Staff detection engineers, overseeing hiring, development, performance, and daily operations.
• Manage threat triage and prioritization, ensure SLO adherence, coordinate incidents, and balance workloads across simultaneous threats.
• Safeguard team focus and capacity while guaranteeing that high-priority tasks meet target turnaround times.
• Establish cross-functional partnerships and represent the team in collaborative forums.
• Own and enhance the team roadmap, process documentation, service charter, and performance metrics.
• Advocate for detection automation and tooling improvements.
• Communicate the team's efforts, coverage, and results to stakeholders, partner teams, and detection leadership.
• Demonstrated experience in leading or mentoring a detection engineering, threat detection, or SOC-adjacent team.
• Previous direct people management experience is preferred; strong technical leads ready to transition into management will also be considered.
• Current, hands-on expertise in detection engineering, including the writing, reviewing, and tuning of detection rules.
• Strong understanding of the complete detection lifecycle and the dynamics of false negative and false positive feedback loops.
• Extensive hands-on experience with GitHub and detection-as-code pipelines, including pull requests, code reviews, and merge-to-release processes.
• Practical experience in developing detections across multiple engines, including endpoint behavioral, signature-based technologies such as YARA, and cloud or SIEM-based systems utilizing various data sources, or the ability to quickly adapt across engines.
• Experience in developing detections within a product or vendor organization that serves a diverse clientele across various industries.
• Solid understanding of adversary behavior, MITRE ATT&CK framework, ransomware, and campaigns active in the wild.
• Proven track record in fast-paced, SLO-driven environments with competing priorities.
• Willingness to lead responses to emerging threats outside of conventional schedules.
• Exceptional communication and stakeholder management capabilities.
• Experience in establishing or enhancing team processes, metrics, and documentation is highly desirable.
• Familiarity with intake and triage workflows and detection automation tools is a significant advantage.
• Restricted Stock Units (RSUs)
• Employee Stock Purchase Plan (ESPP)
• Flexible time off
• Paid company holidays and paid sick leave
• Gender-neutral parental leave
• Grandparent leave
• Medical, dental, and vision insurance
• 401(k) retirement plan with company match
• Life and disability insurance
• Health and dependent care Flexible Spending Account (FSA)
• Voluntary benefits (hospital, accident, critical illness)
• Employee Assistance Program (EAP)
• ARAG pre-paid legal services
• Nationwide pet insurance
• Cancer Care program
• Global business travel medical insurance
• Home office allowance
• Mobile phone reimbursement
• Wellness coach
• Wellness/gym reimbursement
• Fertility coverage
• Adoption & surrogacy reimbursement
3Core Systems, Inc
Fortrea
Stralynn Consulting Services, Inc
Abacus Group
Get handpicked remote jobs straight to your inbox weekly.