About The Position

The Cybersecurity Threat Detection & Automation Manager will lead a team responsible for designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments. This is a hands-on player/coach leadership role. The successful candidate will not only manage, mentor, and set direction for a team of detection engineering and automation professionals, but will also remain deeply involved in technical delivery. This includes reviewing detection logic, shaping automation workflows, validating use cases, improving alert fidelity, and ensuring the program produces measurable security outcomes. The role is critical to reducing attacker dwell time, improving investigation quality, scaling response through automation, and strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline. The ideal candidate combines deep detection engineering expertise, automation experience, incident response knowledge, strong leadership ability, and the program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment. In this role, you will help modernize and mature the organization’s threat detection and response capabilities. You will lead the team responsible for turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.

Requirements

  • Deep detection engineering expertise.
  • Automation experience.
  • Incident response knowledge.
  • Strong leadership ability.
  • Program management discipline needed to build scalable cybersecurity capabilities in a complex enterprise environment.

Responsibilities

  • Designing, developing, automating, tuning, and continuously improving advanced threat detection and response capabilities across enterprise, cloud, identity, endpoint, email, network, SaaS, and manufacturing/OT environments.
  • Managing, mentoring, and setting direction for a team of detection engineering and automation professionals.
  • Remaining deeply involved in technical delivery, including reviewing detection logic, shaping automation workflows, validating use cases, and improving alert fidelity.
  • Ensuring the program produces measurable security outcomes.
  • Reducing attacker dwell time.
  • Improving investigation quality.
  • Scaling response through automation.
  • Strengthening the organization’s overall SecOps maturity through SIEM, SOAR, detection lifecycle governance, and engineering discipline.
  • Turning adversary behavior, threat intelligence, incident lessons learned, red team findings, and business risk into actionable detections, automation workflows, analyst guidance, and measurable security outcomes.
  • Improving detection coverage across enterprise, cloud, identity, endpoint, email, network, OT, and SaaS environments.
  • Improving alert fidelity and false-positive reduction.
  • Improving investigation speed and analyst consistency.
  • Improving SOAR automation maturity and response scalability.
  • Improving detection lifecycle governance, testing, validation, and documentation.
  • Modernizing SecOps across SIEM, SOAR, EDR, threat intelligence, and telemetry platforms.
  • Reducing manual triage and improving operational repeatability.
  • Building stronger partnerships across SOC, Incident Response, Threat Intelligence, IT, Cloud, Identity, Network, OT, and business teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service