Lead Threat Detection Architect

Refinitiv

Richmond (VA)

Hybrid

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Refinitiv is seeking a Lead Cyber Threat Management Analyst to design and operationalize scalable detection capabilities across SIEM, EDR, and cloud environments. You will translate adversary behavior into practical detections and drive improvements with cross-functional teams.

You will mentor junior engineers, map detections to MITRE ATT&CK, integrate threat intel, and leverage AI-enabled security tools to accelerate analysis while ensuring quality reviews before deployment.

Qualifications

  • 5+ years of experience in threat detection engineering, security operations, incident response, threat intelligence, cyber defense, or a related cybersecurity discipline.
  • Experience developing, tuning, and maintaining detection logic across multiple security platforms, including SIEM, EDR, cloud-native security tools, or similar technologies.
  • Strong written and verbal communication skills, including the ability to explain technical risks, findings, and recommendations to a range of technical and business stakeholders.

Responsibilities

  • Architect, develop, implement, and maintain scalable threat detection logic across SIEM, EDR, cloud-native security platforms, and other enterprise security data sources.
  • Design and tune detection content to identify emerging threats, suspicious activity, adversary behaviors, and indicators of compromise while minimizing false positives and alert fatigue.
  • Map detections to the MITRE ATT&CK framework to assess defensive coverage, identify detection gaps, and prioritize improvements based on risk and threat relevance.
  • Operationalize threat intelligence, including indicators of compromise, tactics, techniques, procedures, and vendor intelligence, into actionable detection and monitoring strategies.
  • Collaborate with Threat Intelligence, Incident Response, Security Operations, and Security Engineering teams to validate detection effectiveness and improve response workflows.
  • Analyze security logs, alerts, telemetry, and behavioral data from diverse sources to identify patterns, anomalies, and potential malicious activity.
  • Lead the development and optimization of detection workflows, enrichment pipelines, and automation that improve investigation speed, alert context, and analyst efficiency.
  • Use AI-enabled security tools responsibly to accelerate detection development, alert triage, threat research, documentation, and hypothesis generation, while validating outputs before relying on them operationally.

Skills

Threat detection engineering
Security operations
MITRE ATT&CK
Threat intelligence
Python scripting
PowerShell scripting
Cloud security
Incident Response collaboration

Tools

SIEM
EDR
SOAR
XDR
Cloud security tools

Job description

Refinitiv is seeking a Lead Cyber Threat Management Analyst to design and operationalize scalable detection capabilities across SIEM, EDR, and cloud environments. You will translate adversary behavior into practical detections and drive improvements with cross-functional teams.

You will mentor junior engineers, map detections to MITRE ATT&CK, integrate threat intel, and leverage AI-enabled security tools to accelerate analysis while ensuring quality reviews before deployment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Threat Detection Engineer
Lead Threat Detection Engineer

Refinitiv • Richmond (VA)

On-site
USD 140,000 - 200,000
Mental Health Days off
401k with company match
Tuition reimbursement
Senior Threat Detection Architect
Senior Threat Detection Architect

Thomson Reuters • Richmond (VA)

On-site
USD 118,000 - 220,000
Hybrid Work Model
Flexibility & Work-Life Balance
Career Development
+1
Lead Threat-Informed Defense & Operational Intelligence
Lead Threat-Informed Defense & Operational Intelligence

Prudential Ins Co of America • Newark (NJ)

On-site
USD 124,000 - 204,000
Medical insurance
PTO & leave
401(k) plan match
+4
Lead Threat Detection Engineer
Lead Threat Detection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 160,000 - 180,000
Senior Threat Detection Architect
Senior Threat Detection Architect

Thomson Reuters • Richmond (VA)

Hybrid
USD 118,000 - 220,000
Hybrid Work Model
Flexible Benefits
401k Match
Lead MDR Detection & Response Architect
Lead MDR Detection & Response Architect

X4V Rapid7 LLC • Arlington (VA)

On-site
USD 140,000 - 210,000
Lead Threat Detection Engineer - SIEM & Hunting
Lead Threat Detection Engineer - SIEM & Hunting

CVS Health • Carson City (NV)

On-site
USD 107,000 - 284,000
Bonus program
Equity awards
Comprehensive benefits
Senior Threat Detection Lead - SOAR & SIEM Expert
Senior Threat Detection Lead - SOAR & SIEM Expert

ADP • Roseland (NJ)

On-site
USD 150,000 - 210,000
Lead Threat Hunter & Security Operations Architect
Lead Threat Hunter & Security Operations Architect

Mwiah • Carrollton (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
Lead Detection Engineer — Splunk ES & Threat Hunting (Remote)
Lead Detection Engineer — Splunk ES & Threat Hunting (Remote)

K&A Technologies LLC • Washington

Hybrid
USD 165,000 - 190,000