Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Capital One is seeking an experienced Detection Engineer in the Cyber Threat Detection (CTD) team to own end-to-end endpoint detection coverage. You will work on telemetry requirements, attack chain summarization, and high-fidelity alert deployment across the endpoint domain.
You'll lead the design and maintenance of detection rules with DaC methods, leverage GenAI-assisted workflows, and push code through GitHub and CI/CD pipelines.
Are you passionate about building and pioneering in the technology space? Do you enjoy solving complex security problems in a fast-paced, collaborative, and iterative environment? At Capital One, you'll be part of a group of makers, breakers, doers, and disruptors who solve real problems and protect millions of customers every day.
Capital One's Cyber Organization is a fast-paced, dynamic environment committed to enabling and securing the business. Our Cyber Operations & Intelligence division is searching for an experienced Individual Contributor (IC), Manager-level Detection Engineer with deep endpoint security expertise to join our Cyber Threat Detection (CTD) team. In this role, you will own end-to-end detection coverage for our Endpoint domain — from telemetry requirements and threat landscape awareness through to coverage gap identification and high-fidelity alert deployment.
The CTD team engineers, deploys, and validates automated threat detections that protect Capital One's customers, assets, and associates. Our detections power the investigations and incident response work of the Cyber Security Operations Center (CSOC), running continuously across our enterprise SIEM, which processes over 20 million events per second across hundreds of custom detection rules and thousands of out-of-the-box. Underpinning this platform is a Detection-as-Code discipline: every detection is a YAML-based rule, version-controlled in GitHub, CI/CD deployed, peer-reviewed, and unit-tested.
In this role, you will be a senior technical contributor responsible for solving hard problems using cutting-edge technology across endpoint security engineering, alert development, EDR/endpoint log analysis, and monitoring at scale.
AI-Driven Detection & Engineering: Leverage LLMs and machine learning to automate detection logic, summarize complex attack chains, reduce false positives, and accelerate the full detection development lifecycle using tools such as Capital One's Detection Engineering Assistant.
Detection-as-Code (DaC) Leadership: Lead the design, development, and maintenance of detection rules using DaC methodologies, utilizing GenAI-assisted development workflows and CI/CD pipelines against the Cyber Detection Library (CDL).
Behavioral Detection Engineering: Design and build high-fidelity behavioral detections that identify adversary patterns, TTPs, and anomalous endpoint activity — leveraging user and entity behavior signals, process telemetry, and correlation logic to distinguish malicious from benign activity at scale.
Strategic Architecture: Utilize the MITRE ATT&CK framework to visualize, prioritize, and close endpoint coverage gaps; drive detection architecture decisions that balance fidelity, volume, and operational risk across the endpoint threat surface.