Skip to main content
Apollo.io

Engineering Manager, Security Detection & Response

RemoteUnited States only
Published
Role
Engineering Management
Experience
Senior
Employment
Full-time
Company size
Startup
$225.4k–$281.8k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Engineering manager for a US-remote Security Detection & Response team. Needs 5+ years in detection/response/security engineering, 2+ years people management, Python, SIEM, Git/CI/CD, cloud/SaaS security, and hands-on detection-system delivery.

Core skills

PantherPythonSecurity Detection & Response

Required skills

SIEMGitCI/CD

Optional skills

GCPGoogle WorkspaceOktaGitHubSlackAtlassianCloudflareCrowdStrike

What you'll do

  • Build, lead, and retain a high-performing remote Security Detection & Response team with clear expectations, strong onboarding, documentation, and knowledge-sharing practices.
  • Coach engineers to grow in technical depth, operational ownership, and leadership capability while prioritizing shipping velocity and iteration over perfection.
  • Define team culture around experimentation: ship detection rules quickly, measure effectiveness, and iterate based on signal.
  • Partner with Engineering, Infrastructure, IT, Fraud, Legal, People, Support, and Product to translate security risk into business decisions and communicate impact to technical and non-technical stakeholders.
  • Define and evolve the Security Detection & Response strategy, including what to build, when, and why.
  • Prioritize detection work ruthlessly, recognizing not every threat gets a detection.
  • Lead the team in shipping detection rules, MITRE ATT&CK-aligned use cases, investigation playbooks, and response automations with measurement and validation loops.
  • Oversee Panther detections and AI-assisted workflows for triage, enrichment, and response.
  • Continuously measure coverage, precision, latency, and tuning effectiveness through safe rollout and attack simulation.
  • Drive Python-based tooling, Git-based workflows, and CI/CD practices to enable fast shipment of detection content.
  • Stay close to technical work through code reviews, architecture decisions, and hands-on problem-solving alongside the team.
  • Own end-to-end security observability, including telemetry onboarding, signal quality, threat intelligence inputs, and alert tuning.
  • Lead complex and high-severity incidents with clear decision-making and effective communication.
  • Translate incident learnings into detection and response priorities for the next sprint.
  • Stay technically engaged in investigations across cloud infrastructure, SaaS platforms, corporate systems, and user behavior.
  • Use incidents as teaching moments for the team and validation for detection strategy.
  • Work with Engineering and Infrastructure on telemetry pipelines and operational readiness.
  • Ensure the team has the data needed to ship fast.
  • Define and own strategy-aligned metrics such as detection latency, coverage gaps, false positive rates, and team velocity.
  • Use data to inform priorities and stakeholder decisions.
  • Communicate security impact in business terms, including what risks are being prevented and the cost of being wrong.

What they require

  • 5+ years in Security Detection & Response, Security Engineering, or Incident Response, with hands-on experience building and shipping detection systems, not just managing incidents.
  • 2+ years of people management, including hiring, coaching, and performance management, ideally in a remote-first environment.
  • Strong technical foundation in modern SIEM platforms, detection engineering, log analysis, and threat intelligence workflows.
  • Python proficiency for automation, analysis, and internal tooling; must remain technically credible with engineers and review code.
  • Comfort with startup velocity: able to make sound decisions with incomplete information, ship fast, iterate based on feedback, and know when good enough is good enough.
  • Experience with Git workflows, CI/CD practices, and building security content and automation pipelines as code.
  • Cloud-native and SaaS expertise.
  • Excellent communication: able to translate technical security work into business impact for executives and explain engineering trade-offs to non-technical stakeholders.
  • Role operates in a fully remote environment and requires excellent asynchronous communication, comfort with ambiguity, and the ability to ship fast and learn from what sticks.
  • Preferred: Experience leading Detection Engineering or Security Engineering teams in a high-growth cloud or SaaS startup environment, not just enterprises or government.
  • Preferred: Experience using AI for triage, investigation, or response in production and understanding its limitations.
  • Preferred: MITRE ATT&CK, threat intelligence workflows, and vulnerability management SLAs with a bias toward automation and shipping, not just compliance.
  • Preferred: Relevant certifications such as CISSP, GCIA, GCIH, GCED, or cloud security certifications.
  • Preferred: Track record of leading teams that iterate weekly and measure success by velocity plus signal.
  • Energized by finding smarter, faster ways to get things done using AI and automation.

Benefits

  • Equity.
  • Company bonus or sales commissions/bonuses.
  • 401(k) plan.
  • At least 10 paid holidays per year.
  • Flex PTO.
  • Parental leave.
  • Employee assistance program and wellbeing benefits.
  • Global travel coverage.
  • Life insurance.
  • AD&D insurance.
  • Short-term disability insurance.
  • Long-term disability insurance.
  • FSA/HSA.
  • Medical benefits.
  • Dental benefits.
  • Vision benefits.
  • Resources, support, and autonomy to own the role and make an impact.
  • Team collaboration across departments.
  • Freedom to experiment, take smart risks, and drive big wins.

Apollo.io is a go-to-market solution for revenue teams, providing verified B2B contact data and tools to engage and convert prospects in one unified platform.

SaaSEnterpriseapollo.io/

Details

Apply routeGreenhouse
$225.4k–$281.8k/yr