Cybersecurity Threat Detection & Automation Manager
Sign up free to see how well your resume matches this role.
About this role
The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
This is a hands-on player/coach leadership role. The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes.
The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.
The Impact You Will Make
In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.
You will directly influence:
- Detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments
- Alert fidelity and false-positive reduction
- Investigation speed and analyst consistency
- SOAR automation maturity and response scalability
- Detection lifecycle governance, testing, validation, and documentation
- SecOps modernization across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms
- Reduced manual triage and improved operational repeatability
- Stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams
Company
Company facts come from this company's own listings. We only show what the postings themselves carry.