Manager, Detection Engineering (Rapid Response Team)

Socket.dev

United States

On-site

USD 164,000 - 226,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs
ESPP
Flexible time off
Parental leave
Medical insurance
401(k)

Job summary

SentinelOne in the United States seeks a Manager, Detection Engineering to lead the Rapid Response Team, delivering fast and reliable detection across emerging threats, critical vulnerabilities, and supply chain attacks. You will stay hands-on, write and review detections, and guide a team of five or more engineers toward excellence.

You will collaborate with cross-functional partners, shape the team's roadmap and metrics, and champion detection automation in a fast-paced, SL O-driven

Qualifications

  • Proven experience leading or mentoring a detection engineering or SOC-adjacent team.
  • Hands-on detection engineering: write, review, and tune detection rules today.
  • Fluency with GitHub and detection-as-code pipelines and PR workflows.
  • Experience developing detections across multiple engines (endpoint, signature-based, cloud) and data sources.
  • Experience in product/vendor environments with multi-customer coverage.

Responsibilities

  • Hands-on development and review of detections; merge and release during surges.
  • Lead and grow a team of five or more engineers; manage hiring, performance, and day-to-day operations.
  • Own threat triage, SLO adherence, incident coordination, and workload balancing across threats.
  • Shield the team from unscoped demand while delivering high-priority work on time.
  • Foster cross-functional partnerships; communicate impact to leadership and stakeholders.
  • Own evolving roadmap, charter, and metrics for the detection team; ensure defensibility and maturity.
  • Drive automation and tooling to multiply engineer output; align with team needs.
  • Communicate work, coverage, and outcomes to stakeholders and leadership.

Skills

People management
Detection engineering
GitHub pipelines
Detection across engines
Product/vendor experience
MITRE ATT&CK
SLO-driven environment
Stakeholder management
Process documentation
Detection automation

Tools

GitHub
Detection pipelines

Job description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.


About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.


Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.


What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.


As a Manager, Detection Engineering, you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence. This is a hands‑on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast‑moving, reactive environment. You will partner closely with cross‑functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage.


What Will You Do?

Primary responsibilities include:



  • Stay hands‑on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.

  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day‑to‑day operations.

  • Own RRT's operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.

  • Protect the team's focus and capacity, shielding engineers from unscoped demand while ensuring high‑priority work is met within target turnaround times.

  • Grow the cross‑functional partnerships that extend RRT's reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.

  • Own and evolve the team's roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.

  • Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team's needs.

  • Drive proactive, transparent communication of RRT's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.


What Skills and Knowledge Will You Bring?

Ideal candidates will have:



  • Proven experience leading or mentoring a detection engineering, threat detection, or SOC‑adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.

  • Current, hands‑on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end‑to‑end detection lifecycle and false negative and false positive feedback loops.

  • Strong, hands‑on experience with GitHub and detection‑as‑code pipelines, including fluency in pull requests, code review, and merge‑to‑release workflows.

  • Hands‑on experience developing detections across more than one engine (endpoint behavioral, signature‑based such as YARA, and cloud or SIEM‑based across multiple data sources), or the ability to ramp quickly across engines.

  • Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.

  • Strong understanding of adversary behavior, MITRE ATT&CK, and real‑world threats such as ransomware and in‑the‑wild campaigns.

  • A track record in fast‑moving, SLO‑driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.

  • Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.

  • Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.

  • Familiarity with intake and triage workflows and detection automation tooling is a strong plus.


Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI‑native platform designed to operate at machine speed, not as an add‑on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.


We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:


Equity & Rewards



  • Restricted Stock Units (RSUs)

  • Employee Stock Purchase Plan (ESPP)


Time Off & Wellbeing



  • Flexible time off

  • Paid company holidays and paid sick time

  • Gender‑neutral parental leave

  • Grandparent leave


Insurance & Financial Security



  • Medical, dental, and vision coverage

  • 401(k) retirement plan with company match

  • Life and disability insurance

  • Health and dependent care FSA

  • Voluntary benefits (hospital, accident, critical illness)

  • Employee Assistance Program (EAP)

  • ARAG pre‑paid legal

  • Nationwide pet insurance

  • Cancer Care program

  • Global business travel medical insurance


Work Perks & Flexibility



  • Home office allowance

  • Mobile phone reimbursement


Wellness & Lifestyle



  • Wellness coach

  • Wellness/gym reimbursement

  • Fertility coverage

  • Adoption & surrogacy reimbursement


This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply. If so, this range will be provided to you during the recruiting process.


$164,000 — $226,000 USD


SentinelOne is proud to be an Equal Employment Opportunity and Affil...


SentinelOne participates in the E-Verify Program for all U.S. based roles.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Manager, AI Software Engineering
Sr. Manager, AI Software Engineering

SentinelOne • United States

On-site
USD 200,000 - 275,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+1
Staff Endpoint Software Engineer, Prompt (Python & OS Internals)
Staff Endpoint Software Engineer, Prompt (Python & OS Internals)

SentinelOne • Northern (KY)

Hybrid
USD 156,000 - 215,000
RSUs
ESPP
Flexible time off
+8
Principal Software Engineer, AI SIEM
Principal Software Engineer, AI SIEM

SentinelOne • United States

On-site
USD 216,000 - 297,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+15
Staff Forward Deployed Engineer, AI
Staff Forward Deployed Engineer, AI

SentinelOne • United States

On-site
USD 156,000 - 215,000
RSUs
ESPP
Home office allowance
+1
Staff Software Engineer, Endpoint Escalations (C++, Windows/OS Internals)
Staff Software Engineer, Endpoint Escalations (C++, Windows/OS Internals)

SentinelOne • United States

On-site
USD 156,000 - 215,000
RSUs
ESPP
Flexible time off
+11
Staff Forward Deploy Engineer (Fullstack - Java/React)
Staff Forward Deploy Engineer (Fullstack - Java/React)

SentinelOne • United States

On-site
USD 156,000 - 215,000
Equity & Rewards
Flexible time off
Medical, dental, and vision coverage
+1
Senior Backend Software Engineer - Agent Platform
Senior Backend Software Engineer - Agent Platform

SentinelOne • United States

On-site
USD 132,000 - 182,000
RSUs
ESPP
Flexible time off
+9
Staff Backend Software Engineer - Agent Platform (Java)
Staff Backend Software Engineer - Agent Platform (Java)

Socket.dev • United States

On-site
USD 156,000 - 215,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+8
Director, Product Management – Cloud Security
Director, Product Management – Cloud Security

Socket.dev • United States

On-site
USD 206,000 - 309,000
Equity rewards
RSU program
ESPP plan
+5
Sr Manager, Solutions Engineering
Sr Manager, Solutions Engineering

SentinelOne • Town of Texas (WI)

On-site
USD 232,000 - 319,000
RSUs
ESPP
Flexible time off
+13