Stand out for this role — generate a tailored resume and cover letter in about a minute.
InfraTech Solutions LLC in Chicago, IL is seeking a Detection & Response Engineering Manager to build and lead a modern threat detection and incident handling practice. You will mentor an engineering team while maturing security operations across multi-cloud, endpoints, and SaaS environments.
The role emphasizes automation, detection-as-code, AI integrations, and measuring program maturity with MTTR and coverage, reporting to senior IT and security executives.
Job Title: Detection & Response Engineering Manager
Location: Chicago, IL (Hybrid)
About the Opportunity Are you ready to build and lead a modern threat detection and incident handling practice for a rapidly growing fintech enterprise? We are seeking a hands‑on technical leader to mature our security operations, pioneer artificial intelligence integrations, and refine our threat infrastructure. In this role, you will mentor a dedicated engineering team while driving automated response strategies across a modern cloud ecosystem.
Responsibilities
Direct security monitoring, threat triage, and incident handling operations across multi‑cloud infrastructure, endpoint assets, and SaaS environments.
Serve as operational escalation lead during security incidents and participate in the team’s on‑call rotation.
Oversee the end‑to‑end detection engineering lifecycle—authoring, tuning, and decommissioning rules mapped against the MITRE ATT&CK framework to minimize false positives.
Manage security data pipelines, ensuring proper ingestion, normalization, enrichment, and API‑based telemetry routing.
Champion detection‑as‑code principles by shifting rules into version‑controlled repositories backed by peer review and automated testing.
Design, architect, and deploy net‑new detection platforms and response tools from initial proof‑of‑concept through production rollout.
Integrate automation and generative AI into security operations center workflows to streamline alert processing, orchestration, and triage.
Present metrics regarding incident trends, detection coverage, and overall program maturity to senior IT and security executives.
Requirements
7+ years of hands‑on experience in security operations, threat detection engineering, or incident response.
Proven capability to break down strategic roadmaps into concrete deliverables and mentor technical team members (formal management tenure is not required).
Strong capability to author custom scripts and build detection logic using code‑based frameworks.
Track record of taking security tools and architecture from initial design to full production deployment.
Technical expertise with modern cloud SIEM/SOAR platforms and telemetry collection from AWS environments.
Ability to define, track, and optimize operational KPIs, including mean time to respond (MTTR), false‑positive rates, and detection coverage.
Preferred Qualifications
Professional certifications such as CISSP, OSCP, or specialized GIAC incident response titles.
Direct experience integrating AI models or large language models (LLMs) into security workflows.
Familiarity with AI‑specific risk vectors, including prompt injection mechanics and agent trust boundaries.
Practical experience conducting threat‑hunting campaigns or purple‑team exercises.
Background in regulated domains (such as financial services or fintech) with exposure to SOC 2, PCI DSS, or GLBA standards.
Experience securing cloud‑native setups and containerized application deployments.
Compensation & Benefits
Base Salary: $150,000 – $180,000 USD annually, plus eligibility for an annual performance bonus.
Comprehensive health, dental, and vision insurance options.
Generous paid time off (PTO), paid holidays, and paid parental leave.
401(k) retirement plan with employer matching.
Continuous training allowances, career development resources, and merit growth tracks.
Equal Opportunity Employer: All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.