Cybersecurity Threat Detection & Automation Manager
Listed on 2026-09-09
-
IT/Tech
Cybersecurity
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role . The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall Sec Ops maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
The Impact You Will MakeIn this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.
You will directly influence:
Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
Alert fidelity and false-positive reduction
Investigation speed and analyst consistency
SOAR automation maturity and response scalability
Detection lifecycle governance, testing, validation, and documentation
Sec Ops modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
Reduced manual triage and improved operational repeatability
Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams
Manage, mentor, and develop a team of detection engineering and automation professionals.
Build a culture of engineering rigor, operational discipline, innovation, accountability, quality, and continuous improvement.
Operate as a hands-on manager by personally owning, reviewing, and contributing to key detections, automation workflows, technical initiatives, and program improvements.
Define and execute the threat detection and automation strategy aligned to business risk, operational needs, threat landscape, compliance requirements, and organizational priorities.
Establish the team’s operating rhythm, including intake, prioritization, backlog management, planning, peer review, release readiness, metrics, and continuous improvement.
Coach team members on detection logic, investigation quality, automation design, threat modeling, analyst usability, operational impact, and stakeholder communication.
Partner closely with SOC Monitoring, Incident Response, Threat Intelligence, SIEM Engineering, Cloud, Identity, Network, OT, IT Infrastructure, Vulnerability Management, GRC, and business stakeholders.
Design, develop, tune, and optimize threat detection logic across SIEM, EDR, identity, cloud, email, network, OT, SaaS, and other security platforms.
Personally own a portfolio of high-impact detections focused on complex use cases, crown jewel risks, advanced adversary behaviors, and top enterprise threats.
Translate adversary tactics, techniques, and procedures into actionable analytics using MITRE ATT&CK, kill-chain models, threat intelligence, incident findings, red team results, vulnerability exposure, and business risk.
Conduct detection gap analysis and threat modeling to prioritize improvements based on exposure, telemetry readiness, attacker behavior, business impact, and operational value.
Build and maintain detection validation practices, including test cases, replay or verification methods, regression checks, tuning evidence, performance monitoring, and analyst feedback loops.
Ensure detections are operationally useful by including clear context, enrichment, severity guidance, response steps, escalation paths, and containment recommendations.
Measure and expand detection coverage across ATT&CK tactics and techniques, critical assets, identities, cloud platforms, OT environments, and enterprise telemetry sources.
Stay current with emerging threats, adversary tradecraft, tools, vulnerabilities, and detection methods.
Lead the design, development, and continuous improvement of SIEM and SOAR-driven detection and response workflows.
Build and optimize SIEM content,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).