ForgeApply
Try it free

ForgeApply · Job listing

Manager, Detection Engineering (Rapid Response Team)

Sentinellabs

Remote · US

Apply in about a minute — without sacrificing quality.

ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.

About this role

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Manager, Detection Engineering , you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence. This is a hands-on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast-moving, reactive environment. You will partner closely with cross-functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage.

What Will You Do?

Primary responsibilities include:

• Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.

• Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.

• Own RRT's operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.

• Protect the team's focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times.

• Grow the cross-functional partnerships that extend RRT's reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.

• Own and evolve the team's roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.

• Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team's needs.

• Drive proactive, transparent communication of RRT's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

• Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.

• Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops.

• Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows.

• Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines.

• Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.

• Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns.

• A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.

• Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.

• Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.

• Familiarity with intake and triage workflows and detection automation tooling is a strong plus.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we

Ready to apply to Sentinellabs?

Apply in about a minute

Similar jobs

More like this: More jobs at Sentinellabs · Browse all jobs