Skip to content
← Back to job listings

Detection & Response Engineering Manager

Beyond Finance · Chicago, United States

External listingfull-time14 days ago

About The Role

Join our team as a Detection & Response Engineering Manager, where you'll lead the monitoring, triage, and incident response for our SaaS applications, user workstations, and AWS. You'll have the opportunity to coach and grow your team while also being hands-on in detections, pipelines, and investigations. This is a chance to take an established function and mature it, bringing automation and AI into security operations. You'll also have access to generous benefits, including unlimited PTO, competitive health care plans, 401(k) matching, and more.

  • Ownership of detection and response for the environment, including monitoring, triage, and incident response across various platforms.
  • Coaching and growing the team while actively participating in detections, pipelines, and investigations.
  • Building and maturing the detection and response function, including the implementation of automation and AI in security operations.
  • You can take a broad roadmap and prioritize independently, breaking the big picture into concrete, sequenced work for you and the team
  • Depth in SIEM, EDR, and SOAR; we use Datadog Cloud SIEM, ingesting logs from across our platforms, including AWS
  • A track record of taking projects from prototype to production, including the architecture and the hands-on build
  • Experience mentoring or leading engineers or analysts; formal management tenure is not required
  • You can identify which KPIs apply where and set acceptable thresholds for each, across measures such as detection coverage, false-positive rate, MTTR, and automation rate
  • You write your own scripts and build detection logic as code
  • 7+ years in security operations, detection, or incident response
  • Experience securing cloud-native and containerized environments
  • Fintech or other regulated-industry experience, and familiarity with PCI DSS, SOC 2, or GLBA
  • Purple teaming or adversary emulation to validate detections
  • Hands-on threat hunting experience
  • Awareness of AI-specific risks such as prompt injection and agent trust boundaries
  • Experience applying AI or LLMs to security work
  • Certifications such as CISSP, the GIAC detection/IR family, or OSCP

This is an external listing. JobSpring does not represent or verify the employer. Report this listing