This job is no longer available
The position may have been filled or the posting has expired. Browse similar opportunities below.
Link copied to clipboard!
Back to Jobs
Manager, Threat Detection Engineering at Vanguard
Vanguard
No longer available
Posted 4 hours ago
JOB DESCRIPTION
The Manager, Threat Detection Engineering leads a team of threat detection engineers within the Vanguard CSOC, responsible for the strategy, execution, and continuous maturation of the organization's threat detection capabilities. This role sits at the intersection of people leadership, technical excellence, and security strategy to guide a high-performing engineering team that translates adversary behaviors into high-fidelity, scalable detections across the full security stack. The manager will set team direction, drive measurable outcomes, and serve as a key stakeholder and partner across the CSOC including Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management, to advance Vanguard's defensive posture against the evolving cybersecurity threat landscape.Core ResponsibilitiesPeople LeadershipLead, mentor, and develop a team of threat detection engineers, fostering a culture of technical excellence, continuous learning, and collaborationConduct regular 1:1s, performance reviews, and career development conversations to grow individual contributors and retain top talentIdentify skill gaps and build targeted training, development plans, and knowledge-sharing programs within the teamDrive hiring, onboarding, and team capacity planning in partnership with HR and senior leadershipStrategy & Program OwnershipDefine and own the detection engineering roadmap, aligning team priorities to the broader CSOC strategy and Vanguard's risk postureDevelop and maintain the team's detection engineering framework, methodology, and standards across all platforms and workflowsDrive the team's MITRE ATT&CK coverage strategy, establishing measurable goals and tracking progress over timeStay current on the evolving threat landscape and adversary tradecraft, ensuring the team's detection philosophy reflects emerging attacker behaviorsChampion detection-as-code adoption and engineering best practices across the CSOCExecution & DeliveryOversee the delivery of custom threat detection content across the full security stack, including SIEM, EDR, CNAPP, ITP, NIDS/NIPS, and SaaS security monitoringplatformsManage detection intake and prioritization from Purple Team and Red Team findings, threat intelligence, incident retrospectives, and investigation reviewsEnsure the team maintains structured development, review, and deployment pipelines for all detection contentDrive automation and orchestration initiatives using SOAR platforms, CI/CD pipelines, and AI-assisted tooling to improve team efficiency and detection velocityOversee development and maintenance of synthetic unit test frameworks for detection validationMetrics & ReportingDefine, track, and report on key detection engineering metrics including coverage, detection quality, false positive rates, mean time to detect (MTTD), and backloghealthProvide regular program updates to CSOC leadership and stakeholders on team performance, program health, and strategic initiativesMaintain visibility into detection gaps and remediation progress, driving accountability to measurable outcomesContribute to board and executive-level reporting on detection capability maturity as neededCross-Functional PartnershipPartner closely with Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management teams to ensure detection content reflects real-world threats and operational feedbackRepresent the detection engineering team in Red Team and Purple Team exercises, translating exercise outcomes into actionable detection improvementsCollaborate with platform and infrastructure teams to ensure detection tooling is properly maintained, scaled, and integratedQualificationsBachelor's degree in Cybersecurity, Information Technology, or a related field preferred7+ years of experience in security operations, detection engineering, threat hunting, incident response, or a closely related disciplinePeople management or formal team leadership experience in a security engineering contextHands-on experience writing and tuning detections in one or more SIEM platformsHands-on background with SOAR or security automation platformsExperience with endpoint detection and response (EDR) and/or asset visibility and control platformsStrong familiarity and working knowledge of MITRE ATT&CK, Cyber Kill Chain, or similar frameworks and their application to detection strategyFamiliarity with detection-as-code concepts, including version control, code review workflows, and CI/CD pipelinesDemonstrated ability to define team roadmaps, manage priorities, and deliver programs against measurable goalsExpert-level understanding of the threat landscape including adversary tools such as C2 frameworks, RMMs, credential theft utilities, proxy and tunneling tools, cloud attack tooling, data exfiltration utilities, malware loaders, ransomware, and post-exploitation frameworks, and the TTPs associated with their useStrong communication skills with the ability to translate technical concepts for both engineering audiences and senior leadershipExperience building or scaling a detection engineering program or practice from the ground upSpecial FactorsSponsorshipVanguard is not offering visa sponsorship for this position.About VanguardAt Vanguard, we don't just have a mission—we're on a mission.To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.How We WorkVanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.SummaryLocation: Malvern, PA; Dallas/Ft. Worth, TXType: Full time