This is a senior individual-contributor role responsible for building and leading a modern detection and response practice within a lean, globally distributed security function. You will own the strategy for security detections across identity, cloud, endpoint, email, and other critical attack surfaces. The role combines detection engineering, incident response, threat hunting, automation, telemetry strategy, and managed security provider oversight. You will lead significant incidents from escalation through containment, investigation, root-cause analysis, evidence handling, and executive-ready reporting. A major focus will be improving signal quality, strengthening threat-model-based coverage, and ensuring that managed SOC escalations meet a consistently high standard. You will also shape the responsible use of AI and automation across detection, enrichment, investigation, and response workflows. This is an opportunity to define how a growing security organization detects, investigates, and responds to real-world threats rather than simply inheriting an existing queue of alerts.
Own the overall strategy and catalog for security detection use cases across identity and authentication abuse, privileged access, Azure and AWS cloud activity, endpoint and email threats, and relevant internal attack paths.
Build, validate, test, version, review, and continuously improve detections using modern SIEM capabilities and real organizational telemetry.
Treat detections as engineering assets, documenting the reasoning behind changes and ensuring coverage is measured against a defined threat model rather than simply counting vendor rules.
Own signal quality end to end by tuning noisy detections, retiring ineffective rules, identifying coverage gaps, and documenting deliberate detection exclusions.
Establish telemetry requirements for incident investigation, including what data should be collected and retained, and advocate for the resources required to meet those standards.
Lead incident response from initial escalation through scoping, containment, evidence handling, root-cause analysis, remediation, closure, and executive-quality reporting.
Direct the relationship with the managed security provider, defining escalation criteria, quality expectations, response standards, and feedback loops.
Review provider escalations and identify missed detections or weaknesses in monitoring, ensuring corrective actions are implemented.
Conduct tabletop exercises with engineering and leadership teams and maintain practical incident-response runbooks that support effective decisions during high-pressure events.
Own the incident notification process, ensuring contractual and regulatory obligations are identified and that relevant stakeholders understand notification timelines.
Collaborate with Product Security when incidents have implications for products or customer-facing security concerns, maintaining appropriate separation between internal response and external disclosure.
Determine where AI-assisted and agentic workflows should be used across detection and response, defining appropriate boundaries between autonomous action, recommendations, and human verification.
Automate investigation and response workflows, with a focus on completing enrichment, correlation, and first-pass investigation before an analyst begins manual review.
Incorporate threat intelligence into operational security by translating adversary behavior into detection use cases, threat hunts, or control improvements.
Establish and improve program metrics covering threat-model coverage, provider escalation quality, time to detect, time to respond, and time to close.
Conduct structured threat hunts based on defined hypotheses and ensure findings are converted into detections, control improvements, or documented risk decisions.
Provide functional direction to SOC analysts while collaborating closely with security and engineering leadership.
Produce incident documentation and reports that are clear, technically rigorous, and suitable for executive and audit-level review.