1

Senior Threat Detection Engineer Jobs (NOW HIRING)

Conduct detection engineering activities aligned to the MITRE ATT&CK framework and known adversary behaviors. * Analyze threat intelligence, attack techniques, and emerging threats to identify new ...

Conduct detection engineering activities aligned to the MITRE ATT&CK framework and known adversary behaviors. * Analyze threat intelligence, attack techniques, and emerging threats to identify new ...

Conduct detection engineering activities aligned to the MITRE ATT&CK framework and known adversary behaviors. * Analyze threat intelligence, attack techniques, and emerging threats to identify new ...

Conduct detection engineering activities aligned to the MITRE ATT&CK framework and known adversary behaviors. * Analyze threat intelligence, attack techniques, and emerging threats to identify new ...

Conduct detection engineering activities aligned to the MITRE ATT&CK framework and known adversary behaviors. * Analyze threat intelligence, attack techniques, and emerging threats to identify new ...

Showing results 41-60

Senior Threat Detection Engineer information

See salary details

$59.5K

$126.6K

$183.5K

How much do senior threat detection engineer jobs pay per year?

As of Sep 6, 2026, the average yearly pay for senior threat detection engineer in the United States is $126,557.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,500.00 and $143,500.00 per year, depending on experience, location, and employer.

What does a senior threat detection engineer do?

A Senior Threat Detection Engineer is responsible for designing, implementing, and maintaining systems that identify and respond to cybersecurity threats within an organization's network. They analyze security alerts, develop detection logic, and work closely with incident response teams to mitigate risks. Their role often includes researching emerging threats, improving detection capabilities, and mentoring junior engineers. By proactively identifying potential security breaches, they help safeguard sensitive information and ensure the organization’s cyber resilience.

How does a senior threat detection engineer typically collaborate with other teams to enhance organizational security?

A Senior Threat Detection Engineer works closely with security operations, incident response, IT, and development teams to identify and mitigate threats. This often involves sharing intelligence, developing detection rules, and coordinating responses to security incidents. Regular collaboration ensures that detection strategies align with evolving threats and organizational priorities, fostering a proactive security posture. Effective communication and teamwork are essential, as these engineers often lead efforts to improve detection capabilities and mentor junior staff.

What are the key skills and qualifications needed to thrive as a senior threat detection engineer, and why are they important?

A Senior Threat Detection Engineer requires deep expertise in cybersecurity, threat analysis, and incident response, often backed by a degree in computer science or a related field and industry certifications like CISSP or GIAC. Proficiency with SIEM platforms (such as Splunk or QRadar), EDR solutions, scripting languages, and threat intelligence tools is crucial. Strong analytical thinking, problem-solving abilities, and effective communication skills distinguish top performers in this role. These competencies ensure accurate threat identification, swift mitigation, and robust organizational security in an ever-evolving threat landscape.

What is the difference between Senior Threat Detection Engineer vs Security Analyst?

AspectSenior Threat Detection EngineerSecurity Analyst
CertificationsGICSP, CISSP, GIAC certificationsCompTIA Security+, GIAC certifications
Work EnvironmentAdvanced threat detection, incident response, security architectureMonitoring, analyzing security alerts, reporting
Industry UsageUsed in cybersecurity teams focusing on threat detection and responseUsed across organizations for security monitoring and analysis

While both roles focus on cybersecurity, the Senior Threat Detection Engineer primarily develops and implements advanced detection strategies and handles complex incident responses. The Security Analyst monitors security alerts and performs initial analysis. The Senior Threat Detection Engineer typically requires more technical expertise and experience in threat hunting, whereas Security Analysts focus on alert management and reporting.

More about Senior Threat Detection Engineer jobs

What cities are hiring for Senior Threat Detection Engineer jobs?

Cities with the most Senior Threat Detection Engineer job openings:

What are the most commonly searched types of Threat Detection Engineer jobs?

The most popular types of Threat Detection Engineer jobs are:

What states have the most Senior Threat Detection Engineer jobs?

States with the most job openings for Senior Threat Detection Engineer jobs include:

Infographic showing various Senior Threat Detection Engineer job openings in the United States as of August 2026, with employment types broken down into 93% Full Time, 3% Part Time, and 4% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution, with an average salary of $126,557 per year, or $60.8 per hour.

Manager, Threat Detection Engineering

Vangard, Inc.

Dallas, TX • On-site

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

The Manager, Threat Detection Engineering leads a team of threat detection engineers within the Vanguard CSOC, responsible for the strategy, execution, and continuous maturation of the organization's threat detection capabilities. This role sits at the intersection of people leadership, technical excellence, and security strategy to guide a high-performing engineering team that translates adversary behaviors into high-fidelity, scalable detections across the full security stack. The manager will set team direction, drive measurable outcomes, and serve as a key stakeholder and partner across the CSOC including Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management, to advance Vanguard's defensive posture against the evolving cybersecurity threat landscape.

Core Responsibilities

People Leadership

  • Lead, mentor, and develop a team of threat detection engineers, fostering a culture of technical excellence, continuous learning, and collaboration
  • Conduct regular 1:1s, performance reviews, and career development conversations to grow individual contributors and retain top talent
  • Identify skill gaps and build targeted training, development plans, and knowledge-sharing programs within the team
  • Drive hiring, onboarding, and team capacity planning in partnership with HR and senior leadership

Strategy & Program Ownership

  • Define and own the detection engineering roadmap, aligning team priorities to the broader CSOC strategy and Vanguard's risk posture
  • Develop and maintain the team's detection engineering framework, methodology, and standards across all platforms and workflows
  • Drive the team's MITRE ATT&CK coverage strategy, establishing measurable goals and tracking progress over time
  • Stay current on the evolving threat landscape and adversary tradecraft, ensuring the team's detection philosophy reflects emerging attacker behaviors
  • Champion detection-as-code adoption and engineering best practices across the CSOC

Execution & Delivery

  • Oversee the delivery of custom threat detection content across the full security stack, including SIEM, EDR, CNAPP, ITP, NIDS/NIPS, and SaaS security monitoring
  • platforms
  • Manage detection intake and prioritization from Purple Team and Red Team findings, threat intelligence, incident retrospectives, and investigation reviews
  • Ensure the team maintains structured development, review, and deployment pipelines for all detection content
  • Drive automation and orchestration initiatives using SOAR platforms, CI/CD pipelines, and AI-assisted tooling to improve team efficiency and detection velocity
  • Oversee development and maintenance of synthetic unit test frameworks for detection validation

Metrics & Reporting

  • Define, track, and report on key detection engineering metrics including coverage, detection quality, false positive rates, mean time to detect (MTTD), and backlog
  • health
  • Provide regular program updates to CSOC leadership and stakeholders on team performance, program health, and strategic initiatives
  • Maintain visibility into detection gaps and remediation progress, driving accountability to measurable outcomes
  • Contribute to board and executive-level reporting on detection capability maturity as needed

Cross-Functional Partnership

  • Partner closely with Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management teams to ensure detection content reflects real-world threats and operational feedback
  • Represent the detection engineering team in Red Team and Purple Team exercises, translating exercise outcomes into actionable detection improvements
  • Collaborate with platform and infrastructure teams to ensure detection tooling is properly maintained, scaled, and integrated


Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred
  • 7+ years of experience in security operations, detection engineering, threat hunting, incident response, or a closely related discipline
  • People management or formal team leadership experience in a security engineering context
  • Hands-on experience writing and tuning detections in one or more SIEM platforms
  • Hands-on background with SOAR or security automation platforms
  • Experience with endpoint detection and response (EDR) and/or asset visibility and control platforms
  • Strong familiarity and working knowledge of MITRE ATT&CK, Cyber Kill Chain, or similar frameworks and their application to detection strategy
  • Familiarity with detection-as-code concepts, including version control, code review workflows, and CI/CD pipelines
  • Demonstrated ability to define team roadmaps, manage priorities, and deliver programs against measurable goals
  • Expert-level understanding of the threat landscape including adversary tools such as C2 frameworks, RMMs, credential theft utilities, proxy and tunneling tools, cloud attack tooling, data exfiltration utilities, malware loaders, ransomware, and post-exploitation frameworks, and the TTPs associated with their use
  • Strong communication skills with the ability to translate technical concepts for both engineering audiences and senior leadership
  • Experience building or scaling a detection engineering program or practice from the ground up

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission-we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.