Director, Detection Engineering and Automation
$168,750–$281,250 year
HybridChicago, Illinois, United States or Reston, Virginia, United States
Job Summary
Lead the Detection Engineering and Automation function as the authoritative center of excellence for prioritized, high-fidelity detections across endpoint, identity, network, and cloud environments. Define and execute the detection strategy aligned to the evolving threat landscape, then lead, develop, and scale a team of approximately 14 engineers and one manager. Own the end-to-end detection lifecycle from ideation through deployment, tuning, and optimization while driving automation and response workflow integration across SOAR, SIEM, and EDR platforms. Mature the detection platform by evaluating scalable tooling and closing coverage gaps in cloud-native environments. Partner cross-functionally with Threat Intelligence, Incident Response, and Engineering to ensure actionable outputs and reduced manual burden. Define and track key metrics including detection coverage, effectiveness, false positive rates, and mean time to detect. Represent Detection Engineering in senior leadership forums to communicate detection posture and risk coverage. This hybrid role requires a minimum of two days in-person at an assigned TU office location.
Required Qualifications
- 10+ years of cybersecurity experience
- strong focus on detection engineering, security operations, or threat intelligence
- at least 3–5 years in a people leadership role managing teams or managers
- Demonstrated experience building and scaling detection engineering programs
- experience across enterprise environments
- Strong understanding of adversary tactics, techniques, and procedures
- experience applying frameworks such as MITRE ATT&CK to guide detection prioritization, coverage, and risk reduction
- Proven ability to drive cross-functional alignment across Threat Intelligence, Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams
- Bachelor's degree in Computer Science, Information Security, or a related field
- Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies
- hands-on experience with detection rule development and automation workflow design
- Experience developing detections across endpoint, identity, network, and cloud environments
- ability to prioritize based on risk reduction and operational impact
- Experience leading cloud detection initiatives across cloud-native environments
- familiarity with cloud-specific telemetry sources and detection challenges
- Strong analytical and risk-quantification skills
- ability to evaluate detection effectiveness, false positive rates, detection coverage, MTTD, and automation throughput
- Ability to translate technical detection posture into executive-relevant narratives
- Adherence to Company policies
- sound judgment
- trustworthiness
- working safely
- communicating respectfully
- safeguarding business operations, confidential and proprietary information, and the Company's reputation
Desired Qualifications
- Experience evaluating and adopting new detection platforms or tooling at enterprise scale
- Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs
- Experience working in financial services, fintech, or a similarly regulated industry
- Familiarity with version-controlled detection pipelines and detection-as-code practices
- Track record of building detection automation that measurably reduces analyst toil and improves response efficiency
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.