Detection Engineer – Manager

Jobtailor

New York (NY)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Jobtailor in New York seeks a senior Detection Engineer to own end-to-end endpoint threat detection, leveraging telemetry, ML, and GenAI-assisted workflows to reduce false positives and accelerate development.

You will design detections on MITRE ATT&CK, mentor engineers, ensure fintech compliance, and collaborate with CSOC, Threat Intelligence, and CI/CD teams to operationalize across the enterprise SIEM.

Qualifications

  • Must have 4+ years in cybersecurity or IT.
  • 4+ years of experience with endpoint logs (Windows Event Logs, Sysmon, EDR telemetry).
  • 2+ years with EDR platforms (CrowdStrike Falcon, SentinelOne, or Microsoft Defender).
  • 4+ years of alert development for threat detection.

Responsibilities

  • Own end-to-end detection coverage for the Endpoint domain from telemetry requirements to high-fidelity alert deployment.
  • Leverage LLMs and ML to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development.
  • Lead the design, development, and maintenance of Detection-as-Code rules using GenAI-assisted workflows and CI/CD pipelines.
  • Design and build behavioral detections identifying adversary patterns, TTPs, and anomalous endpoint activity.
  • Use MITRE ATT&CK to visualize, prioritize, and close endpoint coverage gaps.
  • Mentor engineers on security concepts, AI-driven workflows, and detection engineering best practices.

Skills

Endpoint security expertise
Threat detection development
Machine learning in security
Mentoring
Communication

Education

Bachelor's Degree

Tools

CrowdStrike Falcon
SentinelOne
Microsoft Defender
Databricks
Apache Spark
CI/CD workflows
YAML-based detection frameworks

Job description

  • Own end-to-end detection coverage for the Endpoint domain, from telemetry requirements and threat landscape awareness through coverage gap identification and high-fidelity alert deployment
  • Leverage LLMs and machine learning to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development
  • Lead the design, development, and maintenance of Detection-as-Code rules using GenAI-assisted workflows and CI/CD pipelines
  • Design and build behavioral detections identifying adversary patterns, TTPs, and anomalous endpoint activity
  • Use the MITRE ATT&CK framework to visualize, prioritize, and close endpoint coverage gaps
  • Conduct hypothesis-driven threat research across enterprise endpoint environments and translate attacker techniques into detections
  • Manage telemetry onboarding, alert deployment, tuning, and continuous coverage gap analysis
  • Partner with business leaders, CSOC, Cyber Threat Intelligence, Cyber Threat Hunt, and the Coverage Review Team
  • Ensure documentation meets fintech compliance and audit standards
  • Mentor engineers on security concepts, AI-driven workflows, and detection engineering best practices
  • Contribute to detections powering CSOC investigations and incident response across the enterprise SIEM
Requirements
  • High School Diploma, GED, or equivalent certification
  • At least 4 years of experience working in cybersecurity or information technology
  • At least 4 years of experience with endpoint and host logs, including Windows Event Logs, Sysmon, and EDR telemetry
  • At least 2 years of experience with EDR platforms, including CrowdStrike Falcon, SentinelOne, or Microsoft Defender
  • At least 4 years of experience developing alerts for threat detection
  • At least 2 years of experience with penetration testing, offensive security, or adversary emulation
  • At least 1 year of experience with machine learning or data science applied to security
  • Deep expertise in endpoint security, EDR platforms, and Windows, Linux, and macOS telemetry analysis
  • Previous experience on a detection engineering, threat detection, or threat detection operations team focused on endpoint threat surfaces
  • Extensive experience with SQL and data querying at scale
  • Strong understanding of attacker TTPs, Red Team methodologies, and translating offensive security insights into high-fidelity detections
  • Experience with ML or data science concepts applied to security use cases, including anomaly detection, behavioral analytics, or risk scoring
  • Ability to perform independent root cause analysis and convey complex security risks to technical and executive audiences
  • Demonstrated ability to mentor engineers and contribute to continuous improvement
  • No employer-sponsored immigration support is available for new applicants
  • Preferred: Bachelor's Degree
  • Preferred: 6+ years of experience in Threat Detection, Threat Hunting, or Security Engineering
  • Preferred: 4+ years of experience with Python
  • Preferred: 4+ years of experience with data science concepts and techniques
  • Preferred: 2+ years of experience publishing code to GitHub using CI/CD workflows
  • Preferred experience with Databricks, Apache Spark, streaming data platforms, Detection-as-Code, YAML-based detection frameworks, CrowdStrike Falcon, Windows internals, endpoint forensics, malware triage, or adversary emulation
  • Preferred: 2 or more professional certifications such as GCIA, GCIH, CISSP, GMON, GREM, GCTD, MLE, AWS Cloud Practitioner, or AWS Security
Core Competencies

Demonstrates expertise in endpoint security and threat detection, leveraging machine learning and data science to enhance detection capabilities. Proficient in developing high-fidelity alerts and conducting threat research while ensuring compliance with fintech standards.

Highest-signal resume keywords
  • Endpoint Security Expertise
  • Detection Engineering
  • Machine Learning Application in Security
  • EDR Platform Experience
  • Threat Detection Development
ATS Optimization Keywords
Hard Skills
  • SQL
  • Data Querying
  • Windows Event Logs
  • Sysmon
  • EDR Telemetry
  • Behavioral Analytics
  • Anomaly Detection
  • Root Cause Analysis
  • Python
  • Detection-as-Code
Soft Skills
  • Mentoring
  • Communication
  • Collaboration
Certifications & Qualifications
  • GCIA
  • GCIH
  • CISSP
  • GMON
  • GREM
  • GCTD
  • MLE
  • AWS Cloud Practitioner
  • AWS Security
Industry Keywords
  • MITRE ATT&CK
  • Threat Hunting
  • Adversary Emulation
  • Cybersecurity
  • Fintech Compliance
Tools & Technologies
  • CrowdStrike Falcon
  • SentinelOne
  • Microsoft Defender
  • Databricks
  • Apache Spark
  • CI/CD Workflows
  • YAML-based Detection Frameworks
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer – Threat Intelligence, Detection
Senior Security Engineer – Threat Intelligence, Detection

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Security Engineer
Security Engineer

Jobtailor • Arizona

On-site
USD 85,000 - 130,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Security Engineer, Level 5 – Detection & Response
Security Engineer, Level 5 – Detection & Response

Jobtailor • California (MO)

On-site
USD 125,000 - 180,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Cybersecurity Threat Analyst I
Cybersecurity Threat Analyst I

Jobtailor • Sioux Falls (SD)

On-site
USD 45,000 - 65,000
Security Engineer
Security Engineer

Jobtailor • California (MO)

On-site
USD 140,000 - 190,000
Detection Engineer, Manager - Capital One
Detection Engineer, Manager - Capital One

OpenTalent • McLean (VA)

On-site
USD 140,000 - 200,000
Cybersecurity Detection Engineer 3643279
Cybersecurity Detection Engineer 3643279

Axiom-Path • Charlotte (NC)

Hybrid
USD 110,000 - 150,000
Network Security Engineering
Network Security Engineering

Jobtailor • Town of Florida (NY)

Hybrid
USD 120,000 - 160,000