1

Threat Detection Engineer Jobs (NOW HIRING)

Position Summary The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and ...

Sr. Lead Threat Detection Engineer

Roseland, NJ · On-site

$110K - $145K/yr

ADP is hiring a Senior Lead Threat Detection Engineer. * Are you a technologist, first and foremost, who approaches every problem wearing that hat while going out of your way to champion secure ...

Sr. Lead Threat Detection Engineer

Roseland, NJ · On-site

$123K - $169K/yr

ADP is hiring a Senior Lead Threat Detection Engineer. * Are you a technologist, first and foremost, who approaches every problem wearing that hat while going out of your way to champion secure ...

Senior Threat Detection Engineer

Bellevue, WA · On-site

$129K - $177K/yr

As a Senior Threat Detection Engineer, you will take on complete ownership of a technical area, responsible for delivering all necessary research and features to achieve our team's goals in that area.

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

Lead Threat Detection Engineer

Irving, TX · On-site +1

$139K - $231K/yr

McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection ...

next page

Showing results 1-20

Threat Detection Engineer information

What does a threat detection engineer do?

A Threat Detection Engineer is responsible for identifying, analyzing, and mitigating potential security threats within an organization’s systems and networks. They develop and implement detection strategies, create alerts for suspicious activities, and fine-tune security tools to improve threat visibility. Additionally, they collaborate with security teams to investigate incidents and enhance overall cybersecurity defenses. Their goal is to ensure early detection and response to cyber threats, minimizing potential damage.

What does a typical workday look like for a threat detection engineer?

A typical day for a Threat Detection Engineer involves monitoring security alerts, analyzing network and endpoint data, performing threat hunting activities, and triaging incidents for further investigation. You’ll regularly collaborate with other cybersecurity team members to develop detection rules, improve automated response processes, and stay up-to-date with emerging threat trends. Expect to participate in incident response drills and contribute to documentation and knowledge sharing within your organization. The environment is often fast-paced and requires a mix of independent analysis and teamwork to protect critical assets effectively.

What are the key skills and qualifications needed to thrive as a threat detection engineer?

To thrive as a Threat Detection Engineer, you need a solid understanding of network security, cybersecurity frameworks, threat analysis, and incident response, often backed by a degree in computer science or a related field. Hands-on experience with SIEM tools (such as Splunk or QRadar), intrusion detection/prevention systems, malware analysis platforms, and certifications like CISSP or GIAC are highly valued. Strong analytical thinking, effective communication skills, and a proactive mindset make someone stand out in this role. These skills are crucial for accurately identifying and responding to cyber threats in a timely manner while collaborating with security teams.

More about Threat Detection Engineer jobs

What cities are hiring for Threat Detection Engineer jobs?

Cities with the most Threat Detection Engineer job openings:

What are the most commonly searched types of Threat Detection Engineer jobs?

The most popular types of Threat Detection Engineer jobs are:

What states have the most Threat Detection Engineer jobs?

States with the most job openings for Threat Detection Engineer jobs include:

What are popular job titles related to Threat Detection Engineer jobs?

For Threat Detection Engineer jobs, the most frequently searched job titles are:

Infographic showing various Threat Detection Engineer job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 89% Full Time, 7% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution.

Manager, Threat Detection Engineer

Washington, DC • On-site

Carlyle
Furniture Manufacturing • 11 - 50 employees

Full-time

Medical, Life, Retirement, PTO

Re-posted 13 days ago


Key responsibilities

  • Own the detection content lifecycle, including tuning, improving, or retiring detection rules based on analyst feedback, coverage, alert quality, data quality, and operational factors.

  • Develop high-fidelity detections across various telemetry sources, translating threat intelligence and adversary behaviors into testable detection hypotheses and production analytics.

  • Coordinate and support threat hunts, review technical work, establish detection standards, and coach contributors on detection design, testing, and usability.


Job description

Position Summary

The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and Intelligence Lead, the Threat Detection Engineer leads assigned detection engineering and threat intelligence processes, turns intelligence into production detections and works with security partners to improve operational outcomes.

This role oversees detection content from requirements and design through testing, deployment, tuning and retirement. It also develops intelligence that supports security operations and risk decisions and partners on threat hunting, external-risk response, digital-risk support for executive protection, automation, SOC interaction and platform reliability. The Threat Detection Engineer chooses among AI-assisted methods, deterministic automation and process changes based on the problem, risk and expected value.

This is a hands-on technical leadership role that prioritizes assigned services, reviews technical work, coaches contributors and works across teams to carry out Carlyle's Threat Detection and Intelligence strategy.

In-Office Requirement: 4 days per week

Primary Responsibilities

Detection Engineering and Coverage - 30%

  • Own the detection content lifecycle and use analyst feedback, detection coverage, alert quality, data quality, delivery time and cost to decide what should be tuned, improved or retired.
  • Develop high-fidelity detections across endpoint, identity, email, network, cloud and business-critical application telemetry, identifying visibility and data gaps and ensuring alerts contain the context analysts need to investigate and act.
  • Translate adversary behaviors, threat intelligence, incident learnings and control gaps into testable detection hypotheses and production-ready analytics.
  • Implement approved quality gates for detection content, including data validation, expected-behavior testing, false-positive tolerance, investigation guidance and rollback plans. Use detection-as-code for internally managed content and supported tuning, compensating analytics or provider escalation for vendor-managed content.
  • Coordinate and support targeted threat hunts with incident response and other security partners to validate hypotheses, uncover gaps and convert repeatable findings into durable detections or response logic.
  • Review technical work, establish reusable standards and coach contributors on detection design, testing and investigative usability.

Threat Intelligence and External Risk - 30%

  • Manage intelligence requirements based on Carlyle's threat profile, critical assets, executives and business priorities, including portfolio-related risks relevant to Carlyle.
  • Collect, assess and synthesize strategic, operational and tactical intelligence concerning relevant threat actors, campaigns, vulnerabilities, techniques and emerging risks.
  • Produce timely assessments and briefings tailored to security operations, incident response, technology leaders, executives and other stakeholders.
  • Turn intelligence into prioritized detection, hunting, hardening and response requirements. Measure whether the intelligence was timely, useful and acted on, including how quickly it led to a detection or decision.
  • Govern indicator and intelligence-data lifecycles, including sourcing, validation, normalization, enrichment, confidence, aging, pruning and benign-pattern review; maintain trusted information-sharing relationships and evaluate source relevance and reliability.
  • Coordinate monitoring for dark-web activity, lookalike domains, social-media threats, impersonation, exposed information and other digital risks. Provide cyber and digital-risk support to executive protection. Work with Legal, Communications, service providers and relevant business stakeholders on assessments, escalations and takedowns.

Automation, Quality and Platform Enablement - 30%

  • Use AI-assisted and analytical tools to accelerate detection-rule development, translation, testing and documentation. Ensure generated content is reviewed, traceable and handled in accordance with data requirements.
  • Partner with analysts and platform owners to build, pilot and maintain automation playbooks that enrich alerts, correlate evidence, summarize investigations, prioritize and route work, and recommend next steps. Combine model-assisted and deterministic steps, with human approval for consequential actions.
  • Develop reusable scripts, integrations and data transformations that connect detection, intelligence, case-management and response workflows through supported APIs and structured data contracts.
  • Validate generated rules and automated workflows through analyst review, regression testing, failure-mode assessment and rollback criteria. Pilot material workflow changes with affected analysts, provide training and measure adoption, investigation time, quality and rework.
  • Partner with platform owners and architects to improve telemetry coverage, data quality, integration reliability, scalability and cost effectiveness, and provide ongoing production support for assigned detection, intelligence and automation capabilities.

Program Leadership and Partnerships - 10%

  • Translate the Threat Detection and Intelligence strategy into an actionable roadmap and prioritized backlog. Make day-to-day decisions for assigned work and escalate significant risks.
  • Build effective partnerships with incident response, vulnerability management, engineering, infrastructure, cloud, identity and Communications stakeholders. Define operating handoffs, ownership boundaries and escalation paths that support effective response.
  • Present concise metrics, risks, recommendations and progress updates to technical and non-technical audiences, connecting detailed findings to Carlyle's broader objectives.
  • Monitor day-to-day service-provider performance and resolve delivery, handoff and escalation issues with the appropriate owners.

Requirements

Education & Certificates

  • Bachelor's degree, required.
  • Concentration in cybersecurity, computer science, information systems, engineering or a related discipline strongly preferred, or equivalent relevant professional experience.
  • Advanced degree in a related discipline is preferred.
  • Relevant certifications in security operations, incident response, threat intelligence, cloud security or information security are preferred.

Professional Experience

  • 5-7 years of relevant information-security or cybersecurity experience.
  • 4+ years of hands-on experience spanning threat detection engineering and cyber threat intelligence. Candidates must have developed production detections and used intelligence to improve detection, hunting or response.
  • Demonstrated ownership of complex security processes or services and experience leading cross-functional technical initiatives from definition through measurable operational adoption.
  • Hands-on experience creating, testing, deploying and tuning production detection logic via structured query, rule or analytic language, required.
  • Experience working with security telemetry from multiple domains and diagnosing data-quality or schema issues that affect detection outcomes; experience with cloud security telemetry and controls is preferred.
  • Experience developing automation with a general-purpose language and integrating systems through APIs, structured data formats and version-controlled workflows.
  • Demonstrated use of AI-assisted or analytical techniques in a production security workflow, including testing generated content, measuring results and recognizing when traditional automation or process changes are the better approach.
  • Experience with dark-web analysis, domain impersonation, cyber or digital-risk support for executive protection, or takedown coordination is preferred.
  • Experience creating detection logic in multiple languages or translating analytics across platforms is strongly preferred. Examples may include Sigma, KQL, SPL, XQL, YARA-L, EQL, SQL, YARA or comparable languages.

Competencies & Attributes

  • Deep knowledge of adversary behavior, detection engineering methods and the practical use of MITRE ATT&CK to organize requirements and assess coverage.
  • Working knowledge of SIEM, EDR/XDR, SOAR, threat intelligence, case-management and digital-risk capabilities, with the ability to work across platforms rather than depend on one vendor.
  • Strong understanding of detection testing, data validation, alert fidelity, false-positive reduction, lifecycle governance, intelligence standards, indicator confidence and aging, and structured analytical techniques.
  • Ability to write clear technical requirements, detection documentation, intelligence assessments, executive summaries, operating procedures and decision-ready recommendations, and to adapt technical depth to the audience.
  • Strong prioritization, problem-solving and collaboration skills, with the ability to make progress through ambiguity and adjust as threat conditions and business needs evolve.
  • Demonstrated ability to review technical work, coach others and improve team practices without formal reporting authority. Acts with integrity, discretion, accountability and respect for others.

Benefits/Compensation

The compensation range for this role is specific to Washington, DC, and New York, NY and takes into account a wide range of factors including but not limited to the skill sets required/preferred; prior experience and training; licenses and/or certifications.

The anticipated base salary range for this role is $160,000 to $180,000.

In addition to the base salary, the hired professional will enjoy a comprehensive benefits package spanning retirement benefits, health insurance, life insurance and disability, paid time off, paid holidays, family planning benefits and various wellness programs. Additionally, the hired professional may also be eligible to participate in an annual discretionary incentive program, the award of which will be dependent on various factors, including, without limitation, individual and organizational performance.

Due to the high volume of candidates, please be advised that only candidates selected to interview will be contacted by Carlyle.


Who We Are


When people, ideas, and capital come together, opportunity expands across private markets. At Carlyle, this belief has shaped how we invest for decades, fueling growth for companies and delivering performance for investors.

Visit our website to learn more about our firm and the ways our platform is shaping private markets.