Skip to main content
SentinelOne

Manager, Detection Engineering (Rapid Response Team)

RemoteUnited States only
Published
Role
Engineering Management
Employment
Full-time
$164k–$226k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Hands-on detection engineering manager for a U.S. remote Rapid Response Team. Must lead/mentor senior detection engineers while personally writing, reviewing, and tuning detection rules with GitHub/detection-as-code workflows. Needs threat detection/SOC-adjacent background, MITRE ATT&CK/adversary knowledge, and ability to handle emerging threat response outside a traditional schedule.

Core skills

GitHubDetection EngineeringDetection-as-code

Required skills

YARAMITRE ATT&CK

What you'll do

  • Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.
  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.
  • Own RRT's operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.
  • Protect the team's focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times.
  • Grow the cross-functional partnerships that extend RRT's reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.
  • Own and evolve the team's roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.
  • Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team's needs.
  • Drive proactive, transparent communication of RRT's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.

What they require

  • Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team.
  • Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.
  • Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops.
  • Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows.
  • Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines.
  • Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.
  • Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns.
  • A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.
  • Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.
  • Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.
  • Preferred: Familiarity with intake and triage workflows and detection automation tooling is a strong plus.

Benefits

  • Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Its AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response.

CybersecurityEnterprisesentinelone.com/

What people say about this company

3.3/ 5

  • Employees appreciate the innovative technology and products offered by SentinelOne.
  • The company has a collaborative work culture that fosters teamwork.
  • Some employees report issues with management and communication.

Details

Apply routeGreenhouse
$164k–$226k/yr