Detection Engineer, Manager - Capital One

OpenTalent

McLean (VA)

On-site

USD 140,000 - 200,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Capital One is seeking an experienced Detection Engineer in the Cyber Threat Detection (CTD) team to own end-to-end endpoint detection coverage. You will work on telemetry requirements, attack chain summarization, and high-fidelity alert deployment across the endpoint domain.

You'll lead the design and maintenance of detection rules with DaC methods, leverage GenAI-assisted workflows, and push code through GitHub and CI/CD pipelines.

Qualifications

  • Extensive experience in endpoint security detection engineering.
  • Experience building scalable detections across enterprise endpoints.
  • Familiarity with detection rule development and validation processes.

Responsibilities

  • AI-Driven Detection & Engineering: leverage ML/LLMs to automate detection logic and reduce false positives.
  • Detection-as-Code Leadership: design and maintain detection rules using DaC methodologies with CI/CD pipelines.
  • Behavioral Detection Engineering: build high-fidelity detections for adversary patterns and endpoint activity.
  • Strategic Architecture: apply MITRE ATT&CK to visualize gaps and guide detection architecture.

Skills

Endpoint security
Threat detection
Detection Engineering
MITRE ATT&CK
EDR
CI/CD
GitHub
GenAI/AI-assisted development
Behavioral analytics

Tools

GitHub
CI/CD pipelines
Detection tooling

Job description

Are you passionate about building and pioneering in the technology space? Do you enjoy solving complex security problems in a fast-paced, collaborative, and iterative environment? At Capital One, you'll be part of a group of makers, breakers, doers, and disruptors who solve real problems and protect millions of customers every day.

Capital One's Cyber Organization is a fast-paced, dynamic environment committed to enabling and securing the business. Our Cyber Operations & Intelligence division is searching for an experienced Individual Contributor (IC), Manager-level Detection Engineer with deep endpoint security expertise to join our Cyber Threat Detection (CTD) team. In this role, you will own end-to-end detection coverage for our Endpoint domain — from telemetry requirements and threat landscape awareness through to coverage gap identification and high-fidelity alert deployment.

The CTD team engineers, deploys, and validates automated threat detections that protect Capital One's customers, assets, and associates. Our detections power the investigations and incident response work of the Cyber Security Operations Center (CSOC), running continuously across our enterprise SIEM, which processes over 20 million events per second across hundreds of custom detection rules and thousands of out-of-the-box. Underpinning this platform is a Detection-as-Code discipline: every detection is a YAML-based rule, version-controlled in GitHub, CI/CD deployed, peer-reviewed, and unit-tested.

In this role, you will be a senior technical contributor responsible for solving hard problems using cutting-edge technology across endpoint security engineering, alert development, EDR/endpoint log analysis, and monitoring at scale.

What You'll Do

AI-Driven Detection & Engineering: Leverage LLMs and machine learning to automate detection logic, summarize complex attack chains, reduce false positives, and accelerate the full detection development lifecycle using tools such as Capital One's Detection Engineering Assistant.

Detection-as-Code (DaC) Leadership: Lead the design, development, and maintenance of detection rules using DaC methodologies, utilizing GenAI-assisted development workflows and CI/CD pipelines against the Cyber Detection Library (CDL).

Behavioral Detection Engineering: Design and build high-fidelity behavioral detections that identify adversary patterns, TTPs, and anomalous endpoint activity — leveraging user and entity behavior signals, process telemetry, and correlation logic to distinguish malicious from benign activity at scale.

Strategic Architecture: Utilize the MITRE ATT&CK framework to visualize, prioritize, and close endpoint coverage gaps; drive detection architecture decisions that balance fidelity, volume, and operational risk across the endpoint threat surface.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Detection Engineering Lead
Endpoint Detection Engineering Lead

Capital One • Plano (TX)

On-site
USD 179,000 - 205,000
AI-Driven Endpoint Detection Lead
AI-Driven Endpoint Detection Lead

Capital One National Association • McLean (VA)

On-site
USD 197,000 - 225,000
Endpoint Detection Engineering Manager (AI‑Driven)
Endpoint Detection Engineering Manager (AI‑Driven)

Information Technology Senior Management Forum • McLean (VA)

On-site
USD 197,000 - 225,000
Detection Engineer, Manager
Detection Engineer, Manager

Capital One • Plano (TX)

On-site
USD 179,000 - 205,000
Detection Engineer, Manager
Detection Engineer, Manager

Information Technology Senior Management Forum • McLean (VA)

On-site
USD 197,000 - 225,000
Detection Engineer – Manager
Detection Engineer – Manager

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000
Product Senior Manager, Endpoint Security
Product Senior Manager, Endpoint Security

Capital One National Association • McLean (VA)

On-site
USD 230,000 - 262,000
Detection Engineering Lead - MANTECH
Detection Engineering Lead - MANTECH

OpenTalent • McLean (VA)

On-site
USD 120,000 - 160,000
Product Senior Manager, Endpoint Security
Product Senior Manager, Endpoint Security

Capital One • McLean (VA)

On-site
USD 230,000 - 262,000
Detection Engineer, Information Security - CIBC
Detection Engineer, Information Security - CIBC

OpenTalent • Newport Beach (CA)

Hybrid
USD 125,000 - 170,000