About the role
-
As a Manager, Detection Engineering, you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence
-
This is a hands-on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast-moving, reactive environment
-
You will partner closely with cross-functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage
-
Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against
-
Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations
-
Own RRT’s operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats
-
Protect the team’s focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times
-
Grow the cross-functional partnerships that extend RRT’s reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership
-
Own and evolve the team’s roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible
-
Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team’s needs
-
Drive proactive, transparent communication of RRT’s work, coverage, and outcomes to stakeholders, partner teams, and detection leadership
Benefits
-
Medical, dental, and vision coverage
-
Employee assistance program
-
Gym reimbursement
-
Incentive-based challenges
-
Mental health and mindfulness
-
Unlimited Time Off
-
Grandparent Leave
-
Volunteer Time Off
-
Paid Sick Time
-
Paid Holidays
-
16 weeks Gender-Neutral Parental Leave
-
Restricted Stock Unit Program
-
Flexible Spending Accounts
-
Life Insurance
-
Short and Long Term Disability Insurance
-
401K
-
Team building activities
-
Celebrations and social gatherings
-
Community volunteering events
-
Global all hands and local town hall events
-
Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on
-
Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns
-
Familiarity with intake and triage workflows and detection automation tooling is a strong plus
-
Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical
-
Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization
-
Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows
-
A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day
-
Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines
-
Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams
-
Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at SentinelOne was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
