Lead Threat Detection Engineer

Refinitiv

Richmond (VA)

On-site

USD 140,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Mental Health Days off
401k with company match
Tuition reimbursement

Job summary

Thomson Reuters is seeking a Lead Cyber Threat Management Analyst to design, develop, and continuously improve advanced threat detection across SIEM, EDR, and cloud platforms. You will lead detection content development, operationalize threat intelligence, and collaborate with Security Operations, Threat Intelligence, Incident Response, and Engineering to reduce risk in a diverse technology environment.

You will drive mature detection strategies, minimize false positives, and guide analysts

Qualifications

  • 5+ years in threat detection engineering, security operations, or related cybersecurity discipline.
  • Experience developing, tuning, and maintaining detection logic across multiple security platforms.
  • Strong ability to translate threat intelligence into practical detection use cases.

Responsibilities

  • Architect, develop, and maintain scalable threat detection logic across SIEM, EDR, cloud platforms.
  • Tune detections to identify threats while minimizing false positives and alert fatigue.
  • Map detections to MITRE ATT&CK to assess coverage and gaps.
  • Operationalize threat intelligence into actionable monitoring strategies.
  • Collaborate with Threat Intelligence, Incident Response, and Security Engineering to validate effectiveness and improve workflows.
  • Analyze logs, telemetry, and behavioral data to identify patterns and anomalies.
  • Lead development of detection workflows and automation to speed investigations.
  • Use AI-enabled security tools to accelerate detection, while validating outputs.

Skills

Threat detection engineering
SIEM & EDR
MITRE ATT&CK
Threat intel operationalization
Python/PowerShell
Cloud security
Leadership

Tools

SIEM
EDR
Cloud security

Job description

Thomson Reuters is seeking a Lead Cyber Threat Management Analyst to design, develop, and continuously improve advanced threat detection across SIEM, EDR, and cloud platforms. You will lead detection content development, operationalize threat intelligence, and collaborate with Security Operations, Threat Intelligence, Incident Response, and Engineering to reduce risk in a diverse technology environment.

You will drive mature detection strategies, minimize false positives, and guide analysts

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Detection Architect
Senior Threat Detection Architect

Thomson Reuters • Richmond (VA)

On-site
USD 118,000 - 220,000
Hybrid Work Model
Flexibility & Work-Life Balance
Career Development
+1
Senior Threat Detection Architect
Senior Threat Detection Architect

Thomson Reuters • Richmond (VA)

Hybrid
USD 118,000 - 220,000
Hybrid Work Model
Flexible Benefits
401k Match
Lead Threat Detection Architect
Lead Threat Detection Architect

Refinitiv • Richmond (VA)

Hybrid
USD 120,000 - 150,000
Lead Threat Detection Engineer
Lead Threat Detection Engineer

1P284 THE CARLYLE GROUP EMPLOYEE CO., LLC • Washington

On-site
USD 160,000 - 180,000
Lead Security Engineer — Hybrid, Global Security Leader
Lead Security Engineer — Hybrid, Global Security Leader

Thomson Reuters • Frisco (TX)

Hybrid
USD 140,000 - 190,000
Lead Security Engineer: Cloud, App & Infra Defender
Lead Security Engineer: Cloud, App & Infra Defender

Refinitiv • Frisco (TX), Northern (KY)

Hybrid
USD 118,000 - 220,000
Flexible vacation
Mental Health Days
Headspace access
+2
Lead Threat Detection Engineer - SIEM & Hunting
Lead Threat Detection Engineer - SIEM & Hunting

CVS Health • Carson City (NV)

On-site
USD 107,000 - 284,000
Bonus program
Equity awards
Comprehensive benefits
Senior Threat Detection Lead - SOAR & SIEM Expert
Senior Threat Detection Lead - SOAR & SIEM Expert

ADP • Roseland (NJ)

On-site
USD 150,000 - 210,000
Senior Cyber Incident Coordination Lead
Senior Cyber Incident Coordination Lead

Refinitiv • Eagan (MN)

Hybrid
USD 118,000 - 220,000
Hybrid work model
Mental health days
Employee benefits
Senior Threat Detection Architect (Expert)
Senior Threat Detection Architect (Expert)

Huntington Bancshares, Inc. • Columbus (OH)

On-site
USD 70,000 - 140,000