Manager, Detection Engineering – Rapid Response Team

Posted 19hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Detection engineering manager leading SentinelOne’s Rapid Response Team for AI-native cybersecurity. Developing threat detections, managing senior engineers, and improving rapid-response operations.

Responsibilities:

  • Lead the Rapid Response Team responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps
  • Personally develop, review, and drive detections to merge and release, especially during threat surges and for the hardest threats
  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations
  • Own threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats
  • Protect team focus and capacity while ensuring high-priority work meets target turnaround times
  • Build cross-functional partnerships and represent the team in shared forums
  • Own and evolve the team roadmap, process documentation, service charter, and metrics
  • Champion detection automation and tooling
  • Communicate the team's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership

Requirements:

  • Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team
  • Direct people management experience is ideal; strong technical leads ready to move into management will also be considered
  • Current, hands-on detection engineering expertise, including writing, reviewing, and tuning detection rules
  • Firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops
  • Strong hands-on experience with GitHub and detection-as-code pipelines, including pull requests, code review, and merge-to-release workflows
  • Hands-on experience developing detections across more than one engine, including endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based engines across multiple data sources, or ability to ramp quickly across engines
  • Experience developing detections at a product or vendor company serving many customers and industries
  • Strong understanding of adversary behavior, MITRE ATT&CK, ransomware, and in-the-wild campaigns
  • Track record in fast-moving, SLO-driven environments with competing priorities
  • Flexibility to lead emerging threat responses outside a traditional schedule
  • Excellent communication and stakeholder management skills
  • Experience establishing or maturing team processes, metrics, and documentation
  • Familiarity with intake and triage workflows and detection automation tooling is a strong plus

Benefits:

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement