Назад
Company hidden
16 часов назад

Manager, Threat Detection Engineer (Cybersecurity)

160 000 - 180 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Threat Detection Engineer (Cybersecurity): Building and operating production threat detections, intelligence workflows, and security automation across endpoint, identity, email, network, cloud, and business-critical application telemetry with an accent on detection lifecycle governance, threat intelligence, and operational quality. Focus on translating adversary behavior into tested analytics, integrating AI-assisted and deterministic automation, and improving telemetry, platform reliability, and incident-response outcomes.

Location: Washington, DC, with an in-office requirement of 4 days per week. Compensation applies to Washington, DC and New York, NY.

Salary: $160,000–$180,000 annual base salary, plus potential discretionary incentive compensation.

Company

Private-markets investment firm bringing together people, ideas, and capital to support companies and investors.

What you will do

  • Own the detection-content lifecycle from requirements and design through testing, deployment, tuning, and retirement.
  • Develop high-fidelity detections across endpoint, identity, email, network, cloud, and business-critical application telemetry.
  • Translate threat intelligence, adversary behavior, incident learnings, and control gaps into detection hypotheses, production analytics, hunting activities, and response logic.
  • Manage intelligence requirements and produce strategic, operational, and tactical assessments for security operations, incident response, executives, and other stakeholders.
  • Build automation playbooks, scripts, integrations, and data transformations for alert enrichment, evidence correlation, investigation support, and workflow routing.
  • Lead technical initiatives, coach contributors, improve platform reliability, and coordinate with incident response, vulnerability management, engineering, infrastructure, cloud, identity, Communications, and service providers.

Requirements

  • Bachelor's degree required; cybersecurity, computer science, information systems, engineering, or a related discipline preferred.
  • 5–7 years of relevant information-security or cybersecurity experience, including 4+ years spanning threat detection engineering and cyber threat intelligence.
  • Hands-on experience creating, testing, deploying, and tuning production detection logic using structured query, rule, or analytic languages.
  • Experience working with multi-domain security telemetry, diagnosing data-quality and schema issues, and developing automation with a general-purpose programming language and APIs.
  • Experience using AI-assisted or analytical techniques in production security workflows, including testing generated content and measuring results.
  • Strong knowledge of adversary behavior, detection engineering, MITRE ATT&CK, SIEM, EDR/XDR, SOAR, threat intelligence, detection testing, and lifecycle governance.

Nice to have

  • Advanced degree or relevant security operations, incident response, threat intelligence, cloud security, or information security certifications.
  • Experience with cloud security telemetry and controls, dark-web analysis, domain impersonation, executive-protection digital risk, or takedown coordination.
  • Experience translating detection analytics across Sigma, KQL, SPL, XQL, YARA-L, EQL, SQL, YARA, or comparable languages.

Culture & Benefits

  • Retirement benefits, health insurance, life insurance, and disability coverage.
  • Paid time off and paid holidays.
  • Family planning benefits and wellness programs.
  • Potential eligibility for an annual discretionary incentive program based on individual and organizational performance.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →