Manager Threat Research (Integration-Detections)

Arctic Wolf

Karnataka

On-site

INR 350,000 - 600,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity for all employees
Flexible annual leave
Training and career development
Private medical insurance for you and/
Parental leave

Job summary

Arctic Wolf is seeking a Manager – Detection Engineering, XDR to lead detection development and drive initiatives across endpoint, network, cloud, identity, and email telemetry. You will manage a team, collaborate with product managers, data engineers, and security analysts, and align work with strategic roadmaps.

The role emphasizes building high-quality detection content, improving precision and recall, and delivering capabilities on time.

Qualifications

  • 10+ years in cybersecurity with detection focus.
  • 3+ years in management leading detection engineers.
  • Experience with multiple telemetry sources (EDR, NDR, CSPM, CWPP, IdP, email).
  • Proven ability to develop detection content using rules and analytics.
  • Familiarity with SIEM/XDR platforms and query languages.
  • Strong knowledge of MITRE ATT&CK framework.
  • Proficiency in Python, Bash, or PowerShell.
  • Excellent leadership and mentoring skills.

Responsibilities

  • Generate and manage day-to-day work for the team.
  • Define and deliver the six-month roadmap with Product Team.
  • Drive detection coverage expansion across telemetry sources.
  • Maintain high technical bar for detection quality and false positives.
  • Lead Agile development practices across the team.
  • Mentor and develop team members towards senior/lead roles.

Skills

Cybersecurity
Detection engineering
Team leadership
Agile development
SIEM/XDR
Python/Bash/PowerShell
Machine learning
MITRE ATT&CK

Education

Bachelor's or Master's in CS/IT/Cybersecurity
Security certifications CISSP GCIA GCIH GCED GREM OSCP

Tools

Splunk SPL
Kusto (KQL)
SQL
Sigma

Job description

At Arctic Wolf, you will not just watch the cybersecurity industry evolve – you will help lead the change. Our global team is made up of people who thrive on solving complex problems, moving quickly, and building technology that protects organizations around the world. We are proud to be recognized by Forbes, CNBC, Fortune, CRN, Gartner Peer Insights, and International Data Corporation MarketScape. What matters most is the work behind these recognitions: delivering real outcomes for customers through award-winning innovation such as our Aurora Platform. If you are looking for meaningful work, smart teammates, and the opportunity to make a real impact in a high-growth company that is redefining security operations, Arctic Wolf is the right place for you.

Our mission is simple: End Cyber Risk. We are looking for a Manager – Detection Engineering, XDR to lead detection development activities and help achieve our mission of End Cyber Risk.

The Manager – Detection Engineering, XDR plans and directs all aspects of detection development activities within their team. This includes ensuring that engineering projects, initiatives, and processes are aligned with the organization's established policies and objectives. The Manager reports to a Senior Manager of Research and Development and works closely with Research and Development Leadership, Product Management, and Security Services (S2) to ensure the team is building what our customers and users need in a timely manner.

This is a detection development team responsible for building generalized detections across multiple telemetry sources, including endpoint, network, cloud, identity, and email, to provide broad Extended Detection and Response (XDR) coverage for customers.

Managers may also have specialized subject matter expertise within the technical areas their teams support.

SCOPE OF ROLE

Generate and manage the day-to-day work for the team. Work with the Product Team to define and deliver the six-month roadmap. Contribute to longer-term planning and strategy in partnership with the Director. Provide direction, clarity, and support to the team to ensure detection development activities remain focused on organizational and customer needs.

IN THIS ROLE, YOU WILL:
  • Team Leadership and Detection Development
  • Manage teams responsible for delivering high-quality, innovative detection content spanning multiple telemetry sources.
  • Work collaboratively with architects, developers, Product Managers, data engineers, and security analysts.
  • Support the team by providing direction, clarity, and removing obstacles.
  • Instill the Foundations of Research and Development within the team by living them on a daily basis.
  • Set and maintain a high technical bar for detection quality, coverage, and false-positive rates across the team's output.
  • Ensure teams are highly motivated, performing well, and delivering work on time.
  • Ensure each team is clear on the objectives and goals they are striving to achieve.
  • Work with team members to deliver key features.
  • Build collaborative relationships with other teams and stakeholders within the organization.
Product Roadmap and Detection Strategy
  • Execute the Product roadmap.
  • Work with the Product Team to define and deliver the six-month roadmap.
  • Work with Architects to define and execute on the company's technical roadmap.
  • Drive detection coverage expansion across telemetry sources, ensuring breadth and depth of XDR detection capabilities.
  • Champion cross-telemetry detection strategies that maximize coverage while minimizing false positives across diverse customer environments.
  • Own detection quality metrics and continuously raise the bar on precision, recall, and mean-time-to-detect.
  • Represent the team's work to senior leadership with data-driven reporting on detection coverage, efficacy, and operational impact.
Detection Development Lifecycle
  • Oversee the full detection development lifecycle, from research and hypothesis through implementation, testing, tuning, and retirement.
  • Establish and enforce rigorous peer review processes for all detection content before production deployment.
  • Ensure the team delivers high-quality detection content across endpoint, network, cloud, identity, and email telemetry.
  • Ensure detection development processes and engineering initiatives remain aligned with organizational policies and objectives.
Team Execution and Delivery
  • Remove blockers preventing teams from getting their work done.
  • Make sure each team is clear on the objectives and goals they are striving to achieve.
  • Support the team in delivering key features and detection capabilities.
  • Drive continuous development process improvements.
  • Continuously improve team velocity and delivery predictability.
  • Lead Agile development practices across the team.
Research and Development Responsibilities
  • Implement the Research and Development Department and Team Responsibilities.
  • Ensure teams are following Information Security Management System (ISMS) regulations, including Secure Coding Practices Acceptable Use.
  • Establish and maintain processes that support technical excellence and secure detection development.
People Development and Mentoring
  • Develop the careers of team members.
  • Mentor each team member and help them grow their technical and leadership skills.
  • Establish career development plans and achievable goals for direct reports.
  • Conduct regular one-on-ones.
  • Provide career and personal development coaching.
  • Build a culture of continuous learning, knowledge sharing, and technical excellence.
  • Maintain a clear history of learning and skills development across the team.
  • Regularly help detection developers develop their skills in a variety of ways.
  • Support and mentor individuals toward senior and lead roles.
Administrative and Financial Responsibilities
  • Manage employee compensation and vacation time.
  • Manage and approve conference and training budgets.
  • Participate in helping set and manage the Directorate-level budget.
  • Apply strong financial management skills to team and organizational responsibilities.
Recruitment
  • Lead recruitment efforts for the team for both full-time and co-op employees.
  • Be a key contributor to planning, hiring, and recruitment strategy for the team.
  • Maintain a high hiring bar by assessing candidates for both depth of security knowledge and breadth of cross-domain thinking.
WE'RE LOOKING FOR SOMEONE WITH EXPERIENCE IN:
  • 10+ years of experience in cybersecurity, with a strong focus on detection engineering, threat detection, or security analytics at scale.
  • 3+ years of management or team lead experience in a cybersecurity or detection engineering role, with demonstrated success building and scaling high-performing teams.
  • Deep understanding of diverse telemetry sources, including Endpoint and Endpoint Detection and Response (EDR) Network and Network Detection and Response (NDR) Cloud, including Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) Identity Provider (IdP) telemetry Email security.
  • Hands-on experience normalizing and correlating signals across diverse telemetry sources.
  • Proven track record of developing detection content using correlation rules, behavioral analytics, and machine learning-based approaches across heterogeneous data sources in production environments.
  • Expert-level familiarity with Security Information and Event Management (SIEM) and Extended Detection and Response (XDR) platforms and query languages such as Splunk Processing Language (SPL), Kusto Query Language (KQL), SQL, Sigma, or equivalent.
  • Ability to evaluate detection efficacy through metrics-driven approaches.
  • Strong knowledge of the MITRE ATT&CK framework and demonstrated experience applying it to detection coverage mapping, gap analysis, and prioritization.
  • Proficiency in scripting languages such as Python, Bash, or PowerShell, with the ability to build tooling and automation for detection development workflows.
  • Experience leading Agile development teams, preferably with formal Agile training.
  • Track record of continuously improving team velocity and delivery predictability.
  • A clear history of technical influence, such as public conference talks, published research, open-source contributions, patents, or similar contributions.
  • A clear history of learning and skills development.
  • Experience regularly helping detection developers develop their skills and mentoring individuals into senior or lead roles.
  • Professional security certifications are required, such as CISSP, GCIA, GCIH, GCED, GREM, or OSCP.
  • Permanently located in Bengaluru, India.
NICE TO HAVE:
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • Formal Agile training.
  • Experience with machine learning-based detection approaches.
  • Experience building and managing generalized detection capabilities across multiple telemetry sources.
  • Experience with cross-telemetry detection strategies and XDR coverage.
  • Experience with detection quality metrics, including precision, recall, and mean-time-to-detect.
  • Experience with technical research, public speaking, published research, open-source contributions, or patents.
On-Camera Policy

To support a fair, transparent, and engaging interview experience, candidates interviewing remotely are expected to be on camera during all video interviews. Being on camera fosters authentic connection, improves communication, and allows for full engagement from both candidates and interviewers.

We understand that technical, bandwidth, or location-related challenges may occasionally prevent video use. If this applies, candidates are required to notify us in advance so we can explore appropriate accommodations.

Arctic Wolf is a collaborative and inclusive work environment that thrives on diversity of thought, background, and culture.

This is reflected in our multiple awards, including Top Workplace United States, Best Places to Work United States, Great Place to Work Canada, Great Place to Work United Kingdom, and Kununu Top Company Germany.

Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction, with over 10,000 customers worldwide and more than 2,000 channel partners globally.

As we continue to expand and enhance our technology, Arctic Wolf remains a trusted name in the industry.

Our Values

Arctic Wolf recognizes that success comes from delighting our customers, so we work together to ensure that happens every day.

We believe in diversity and inclusion and value the unique perspectives all employees bring to the organization.

By protecting sensitive data and working to end cyber risk, we contribute to an industry that serves the greater good.

We celebrate diverse perspectives through our Pack Unity program and encourage employees to participate in or create new alliances.

We also believe in corporate responsibility and have joined the Pledge One Percent movement to give back to our communities.

All employees receive compelling compensation and benefits packages, including:

  • Equity for all employees
  • Flexible annual leave, paid holidays, and volunteer days
  • Training and career development programs
  • Comprehensive private benefits plan including medical insurance for you and your family, life insurance equal to three times compensation, and personal accident insurance
  • Fertility support and paid parental leave

Arctic Wolf is an equal opportunity employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under applicable law.

Security Requirements

  • Conduct duties in accordance with Arctic Wolf information security policies, standards, processes, and controls
  • Background checks are required for this position
  • This role may require access to information protected under United States export control laws and regulations

We are committed to fostering a welcoming, accessible, and inclusive environment ensuring equal access and participation for people with disabilities.

We strive to make our recruitment, assessment and selection processes as accessible as possible and provide accommodations as required for applicants with disabilities.

If you require a reasonable accommodation for any part of the application or hiring process, you may make a request by calling the Arctic Wolf general contact number at 1-888-272-8429 and asking to speak to Recruiting, or by emailing recruiting@arcticwolf.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager Threat Research (Integration-Detections)
Manager Threat Research (Integration-Detections)

Arctic Wolf Networks India Private Limited • Bengaluru

Hybrid
INR 4,000,000 - 7,000,000
Equity
Flexible leave
Medical insurance
+2
Senior Threat Researcher (Integrations Team)
Senior Threat Researcher (Integrations Team)

Arctic Wolf Networks India Private Limited • Bengaluru

On-site
INR 2,800,000 - 6,000,000
Equity for all employees
Comprehensive private benefits plan
Fertility support and paid parental le
Manager Threat Research (Integration-Detections)
Manager Threat Research (Integration-Detections)

Arctic Wolf • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Senior Threat Researcher (Integrations Team)
Senior Threat Researcher (Integrations Team)

Arctic Wolf • Bengaluru

On-site
INR 3,500,000 - 5,200,000
Threat Researcher -Cloud & Endpoint Detection
Threat Researcher -Cloud & Endpoint Detection

Arctic Wolf • Bengaluru

On-site
INR 1,800,000 - 2,800,000
Equity and compensation packages
Senior Staff Developer - AI
Senior Staff Developer - AI

Arctic Wolf Networks India Private Limited • Bengaluru

On-site
INR 4,000,000 - 8,000,000
Equity for all employees
Flexible annual leave
Training and career development
+2
Senior Staff Developer - AI
Senior Staff Developer - AI

Arctic Wolf • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Equity for all employees
Flexible annual leave and holidays
Training and career development
Senior Staff Developer - AI SOC Automation
Senior Staff Developer - AI SOC Automation

Arctic Wolf • India

On-site
INR 4,000,000 - 8,000,000
Equity for all
Flexible leave and holidays
Training and career development
+1
Senior Developer
Senior Developer

Arctic Wolf • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Threat Intelligence Researcher
Threat Intelligence Researcher

Arctic Wolf • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Equity for all employees
Private medical insurance
Life insurance