Sr. Lead Threat Detection Engineer

ADPRoseland, NJ
Hybrid

About The Position

ADP is hiring a Senior Lead Threat Detection Engineer. This role is for a technologist who champions secure development, builds diverse teams, and thrives in a dynamic, inclusive, and collaborative environment. The position involves protecting ADP assets by creating and driving threat detection strategies in collaboration with Global Security teams, including Critical Incident Response Center (CIRC), Threat Intelligence, Threat Hunting, Red Team, and AppDev. The engineer will lead efforts to design and define requirements for prevention, detection, and response capabilities within ADP's cybersecurity platforms, mentor other Detection Engineers, and promote the use of innovative technologies and best practices. The role requires strong analytical and communication skills, experience in solution design and enhancement, and the ability to troubleshoot Production issues with IT, Ops, and Engineering partners. The ideal candidate is an enthusiastic creator, stays current with threat detection optimization, and focuses on improving detection quality and business intelligence automation.

Requirements

  • Expert in threat detection and SOAR Development.
  • Strong knowledge and experience with detection engineering and SOAR development.
  • Bachelor's degree or equivalent.
  • 5-7+ years of experience in security, including threat detection, hunt, incident response and SOAR development.
  • 3+ years of threat detection project and program experience.
  • Strong knowledge and practical use working with SIEM and SOAR.
  • Experience with incident detection, response, analysis and security operations.
  • Experience with software, system and security architectures.
  • Strong knowledge and working experience with databases and data warehouse technologies and solutions.
  • Strong working experience with systems automation in a major scripting language (Python, PowerShell).
  • Strong experience building detection logic utilizing security logs to detect malicious activity with high fidelity across a broad set of detection use cases.
  • Creative thinker that leverages unconventional and innovative ideas to solve problems.
  • Ability to communicate security-related concepts to a broad range of technical and non-technical staff.
  • Must possess a high degree of integrity, be trustworthy, and have the ability to work independently.

Responsibilities

  • Work with Global Security teams (CIRC, Threat Intelligence, Threat Hunting, Red Team, AppDev) to create and drive threat detection to protect ADP assets.
  • Lead efforts to design/define/create requirements to develop prevention, detection, and response capabilities within ADP Cyber security platforms.
  • Lead, mentor, and collaborate with other Detection Engineers to design, build & maintain cyber alert catalogs.
  • Promote the use of innovative new technology and best practices for evolving security objectives.
  • Present ideas clearly and professionally in various formats (paper, in person, video calls, phone).
  • Analyze and define solutions, maintain and enhance existing solutions, and participate in project delivery.
  • Mentor, brainstorm new concepts, and provide guidance for team members.
  • Work with partners in IT, Ops, and Engineering to provide support for troubleshooting Production issues.
  • Develop and drive new detection workflows and alerting for our SOAR platform based on specific requests from stakeholders, threat intelligence, and threat hunting.
  • Provide technical mentorship and support to detection engineers.
  • Lead detection projects driven by groups both internal and external to GSO.
  • Lead technical relationships with assigned detection vendors, including troubleshooting and support requests, and driving feature requests.
  • Introduce innovation and ideas to improve current detection processes or develop new processes in-sync with Threat Hunt.
  • Co-develop a roadmap for the Threat Detection team aligned with the overall Hunt and Detection program and Threat Management's mission and objectives.
  • Maintain an expert-level understanding of attacks, vectors, and emergent threats and incorporate these into detections.
  • Analyze CIRC alert statistics and workflows to reduce false positives and focus engineering efforts.
  • Drive the creation and maintenance of detection CIRC playbooks, workflow automation, and use cases.
  • Act as a detection and SOAR subject matter expert.
  • Create, track, and iterate on metrics of the detection engineering process to show progress and track gaps in detection coverage.
  • Proactively develop new security detections to support daily operations and faster, more accurate identification of threats.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service