Назад
Company hidden
2 часа назад

Detection & Response Engineering Manager (Cybersecurity)

150 000 - 180 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection & Response Engineering Manager (Cybersecurity): Owning monitoring, detection engineering, incident response, and security telemetry pipelines across SaaS applications, workstations, and AWS with an accent on detection-as-code, SIEM/SOAR, and operational maturity. Focus on building new detection and response capabilities, applying automation and AI to SOC workflows, and leading investigations, reporting, and team development.

Location: Chicago, IL (Hybrid)

Base annual salary: $150,000–$180,000 USD, plus eligibility for an annual bonus.

Company

hirify.global helps Americans address significant debt through individualized care, compliance-focused practices, user-centric technology, and customized financial solutions.

What you will do

  • Own monitoring, triage, and incident response across SaaS applications, user workstations, AWS, and insider-risk signals.
  • Lead the detection lifecycle, including writing, tuning, retiring, and mapping detections to MITRE ATT&CK while reducing false positives.
  • Build and improve logging pipelines that ingest, normalize, enrich, and route security telemetry through APIs and connectors.
  • Move detections into version control with testing and peer review as part of a detection-as-code practice.
  • Build new detection and response platforms from architecture through production, including automation and AI capabilities for triage, alert summarization, orchestration, and response recommendations.
  • Brief security and IT leadership on incidents, detection coverage, KPIs, and program maturity while mentoring engineers or analysts.

Requirements

  • 7+ years of experience in security operations, detection, or incident response.
  • Hands-on scripting and detection-logic development as code.
  • Experience taking projects from prototype to production, including architecture and implementation.
  • Strong experience with SIEM and SOAR; the environment uses Datadog Cloud SIEM and AWS log sources.
  • Ability to prioritize a broad roadmap, define relevant KPIs and thresholds, and lead or mentor engineers or analysts.
  • Ability to work in a hybrid role based in Chicago, Illinois.

Nice to have

  • CISSP, GIAC detection or incident-response certifications, or OSCP.
  • Experience applying AI or LLMs to security operations and understanding risks such as prompt injection and agent trust boundaries.
  • Threat hunting, purple teaming, or adversary-emulation experience.
  • Fintech or regulated-industry experience, including PCI DSS, SOC 2, or GLBA.
  • Experience securing cloud-native and containerized environments.

Culture & Benefits

  • Uplifting, collaborative environment focused on community, connection, and belonging.
  • Health, dental, and vision programs with considerable employer contributions for eligible full-time employees.
  • Generous PTO, paid holidays, and paid parental leave.
  • 401(k) matching program.
  • Merit advancement opportunities and career development and training.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →