Lead a team of Detection Engineers in designing, implementing, and maintaining advanced detection capabilities to safeguard the organization against emerging cyber threats
Develop the strategy for the Detection Engineering program and establish metrics for continuous improvement
Define detection engineering strategy, roadmap, and objectives to achieve
Design and implement advanced threat detection techniques using tools such as SIEM, EDR, NDR, and SOAR platforms
Develop innovative custom detection rules and automated remediation, playbooks, and alerts tailored to the organization’s threat landscape
Leverage industry standard MITRE frameworks to identify detection coverage and close gaps
Monitor, optimize, and continuously improve detection systems for performance, scalability, and effectiveness
Collaborate with Threat Detection and Response team
Perform attack simulation testing to validate efficacy of use cases
Collaborate with incident response team to ensure rapid detection and containment of cyber threats
Leverage threat intelligence to enhance detection capabilities and proactively mitigate risks
Ensure all detection processes and tools adhere to regulatory requirements and industry standards (e.g., GDPR, PCI-DSS, NIST)
Requirements
Bachelor's degree in Computer Science or equivalent
8+ years of industry related professional experience
3+ years of management or leadership experience with direct people management responsibilities
Multi-cloud security experience (AWS, Azure, GCP)
Strong experience with Information Security, Network Security, Security Monitoring, and Incident Response
Strong experience with developing SIEM/SOAR detection and automation use cases
Working experience with industry standard security technologies and services (e.g., Threat Intelligence, Firewalls, SASE, IPS, Endpoint Security, DLP, SIEM/SOAR, and Data Lakes)
Expert level knowledge on Detection Engineering and Security Operations
Expert level knowledge on the attack kill chain and diamond model
5+ years’ experience in an Incident Response or Security Operations role
3+ years’ leadership experience in a SOC or equivalent role
Must live within a commutable distance to North Hills NY or Atlanta GA
Applicants must currently be authorized to work in the United States for any employer without current or future sponsorship. No OPT, CPT, STEM/OPT or visa sponsorship now or in future.
Benefits
Health insurance (medical, dental, vision)
401(k) matching
Flexible work hours
Paid time off (including bereavement leave, time off to vote, jury duty leave, volunteer time off, military leave, parental leave)
Up to 160 hours of paid wellness annually for their own wellness or that of family members
Paid holidays (seven) throughout the calendar year
Jr Information Security Analyst conducting PCI - DSS compliance projects for AuditSafe. Supporting security controls implementation and leading technical meetings in a hybrid work environment.
Cybersecurity Consultant ensuring cybersecurity operations and delivering consultancy projects for clients, focusing on strategic risk management and compliance assessments.
Senior IT Security Engineer developing and optimizing innovative security solutions in an international environment. Engaging in corporate information security utilizing best practices.
Regional Lead overseeing physical security infrastructure and operations for OpenAI’s data centers in Singapore. Collaborating with teams and managing security technologies for compliance and risk assessment.
Business Continuity and Cybersecurity Awareness Manager at ZEAL, leading BCM and cybersecurity training initiatives. Ensuring resilient operations and fostering secure behavior across teams.
Responsable d'Opérations en sécurité incendie et équipements du bâtiment chez Bureau Veritas. Animer une équipe tout en contribuant au développement commercial et à la qualité des prestations.
Senior Inhouse IT Consultant responsible for the network and server infrastructure of the L - mobile Group. Planning security measures and managing cloud and virtualization platforms.
Senior Manager in Cybersecurity leading Cyber Defense Center operations and strategy development for effective threat response. Collaborating with stakeholders to enhance security posture across the organization.
(Junior) Information Security Officer responsible for ISMS management at Sana Clinics. Ensuring compliance with NIS - 2 and training staff on information security.