Manager, Threat Detection Engineering

Posted 19 Days Ago
Be an Early Applicant
3 Locations
In-Office
Senior level
Fintech
The Role
Lead and grow a threat detection engineering team to design, deliver, and mature scalable detections across SIEM, EDR, CNAPP, and related platforms. Define detection strategy, roadmap, metrics, and processes; partner with hunting, red/purple teams, and Intel; drive detection-as-code, automation (SOAR/CI-CD), validation frameworks, and executive reporting.
Summary Generated by Built In

The Manager, Threat Detection Engineering leads a team of threat detection engineers within the Vanguard CSOC, responsible for the strategy, execution, and continuous maturation of the organization's threat detection capabilities. This role sits at the intersection of people leadership, technical excellence, and security strategy to guide a high-performing engineering team that translates adversary behaviors into high-fidelity, scalable detections across the full security stack. The manager will set team direction, drive measurable outcomes, and serve as a key stakeholder and partner across the CSOC including Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management, to advance Vanguard's defensive posture against the evolving cybersecurity threat landscape.

Core Responsibilities

People Leadership

  • Lead, mentor, and develop a team of threat detection engineers, fostering a culture of technical excellence, continuous learning, and collaboration
  • Conduct regular 1:1s, performance reviews, and career development conversations to grow individual contributors and retain top talent
  • Identify skill gaps and build targeted training, development plans, and knowledge-sharing programs within the team
  • Drive hiring, onboarding, and team capacity planning in partnership with HR and senior leadership

Strategy & Program Ownership

  • Define and own the detection engineering roadmap, aligning team priorities to the broader CSOC strategy and Vanguard's risk posture
  • Develop and maintain the team's detection engineering framework, methodology, and standards across all platforms and workflows
  • Drive the team's MITRE ATT&CK coverage strategy, establishing measurable goals and tracking progress over time
  • Stay current on the evolving threat landscape and adversary tradecraft, ensuring the team's detection philosophy reflects emerging attacker behaviors
  • Champion detection-as-code adoption and engineering best practices across the CSOC

Execution & Delivery

  • Oversee the delivery of custom threat detection content across the full security stack, including SIEM, EDR, CNAPP, ITP, NIDS/NIPS, and SaaS security monitoring
  • platforms
  • Manage detection intake and prioritization from Purple Team and Red Team findings, threat intelligence, incident retrospectives, and investigation reviews
  • Ensure the team maintains structured development, review, and deployment pipelines for all detection content
  • Drive automation and orchestration initiatives using SOAR platforms, CI/CD pipelines, and AI-assisted tooling to improve team efficiency and detection velocity
  • Oversee development and maintenance of synthetic unit test frameworks for detection validation

Metrics & Reporting

  • Define, track, and report on key detection engineering metrics including coverage, detection quality, false positive rates, mean time to detect (MTTD), and backlog
  • health
  • Provide regular program updates to CSOC leadership and stakeholders on team performance, program health, and strategic initiatives
  • Maintain visibility into detection gaps and remediation progress, driving accountability to measurable outcomes
  • Contribute to board and executive-level reporting on detection capability maturity as needed

Cross-Functional Partnership

  • Partner closely with Threat Hunting, Adversary Emulation, Cyber Threat Intelligence, and Incident Management teams to ensure detection content reflects real-world threats and operational feedback
  • Represent the detection engineering team in Red Team and Purple Team exercises, translating exercise outcomes into actionable detection improvements
  • Collaborate with platform and infrastructure teams to ensure detection tooling is properly maintained, scaled, and integrated

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, or a related field preferred
  • 7+ years of experience in security operations, detection engineering, threat hunting, incident response, or a closely related discipline
  • People management or formal team leadership experience in a security engineering context
  • Hands-on experience writing and tuning detections in one or more SIEM platforms
  • Hands-on background with SOAR or security automation platforms
  • Experience with endpoint detection and response (EDR) and/or asset visibility and control platforms
  • Strong familiarity and working knowledge of MITRE ATT&CK, Cyber Kill Chain, or similar frameworks and their application to detection strategy
  • Familiarity with detection-as-code concepts, including version control, code review workflows, and CI/CD pipelines
  • Demonstrated ability to define team roadmaps, manage priorities, and deliver programs against measurable goals
  • Expert-level understanding of the threat landscape including adversary tools such as C2 frameworks, RMMs, credential theft utilities, proxy and tunneling tools, cloud attack tooling, data exfiltration utilities, malware loaders, ransomware, and post-exploitation frameworks, and the TTPs associated with their use
  • Strong communication skills with the ability to translate technical concepts for both engineering audiences and senior leadership
  • Experience building or scaling a detection engineering program or practice from the ground up

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission—we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.

Skills Required

  • 7+ years experience in security operations, detection engineering, threat hunting, incident response, or related discipline
  • People management or formal team leadership experience in a security engineering context
  • Hands-on experience writing and tuning detections in one or more SIEM platforms
  • Hands-on background with SOAR or security automation platforms
  • Experience with endpoint detection and response (EDR) and/or asset visibility and control platforms
  • Strong familiarity and working knowledge of MITRE ATT&CK, Cyber Kill Chain, or similar frameworks
  • Familiarity with detection-as-code concepts, including version control, code review workflows, and CI/CD pipelines
  • Demonstrated ability to define team roadmaps, manage priorities, and deliver programs against measurable goals
  • Expert-level understanding of adversary tools and TTPs (C2 frameworks, RMMs, credential theft, proxy/tunneling, ransomware, malware loaders, post-exploitation frameworks)
  • Strong communication skills to translate technical concepts for engineering audiences and senior leadership
  • Experience building or scaling a detection engineering program or practice from the ground up
  • Bachelor's degree in Cybersecurity, Information Technology, or a related field

Vanguard Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Vanguard and has not been reviewed or approved by Vanguard.

  • Retirement Support Retirement support appears unusually strong through a 401(k) design that includes a match plus an additional employer contribution, which can materially lift long-term total rewards. HSA seeding and an enhanced employer match further strengthen the savings-and-benefits value of the package.
  • Wellbeing & Lifestyle Benefits Wellbeing and lifestyle support is reinforced by a sizable annual FlexFund stipend that can be applied across many day-to-day categories such as fitness, childcare, and other personal expenses. On-site or virtual clinics and fitness options add practical health and wellness convenience.
  • Affordable Benefits Healthcare and related benefits are positioned as comparatively affordable via heavily subsidized medical plans and broad coverage options. This affordability can offset moderate base pay for employees who place higher value on out-of-pocket cost reductions.

Vanguard Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Malvern, PA
20,252 Employees
Year Founded: 1975

What We Do

We are a community of 30 million who think – and feel – differently about investing. Together, we’re changing the way the world invests. Since our founding in 1975, helping our investors achieve their goals is our sole reason for existence. With no other parties to answer to and therefore no conflicting loyalties, we make every decision—like keeping investing costs as low as possible—with only your needs in mind. Vanguard is one of the world's largest investment companies, offering a large selection of high-quality low-cost mutual funds, ETFs, advice, and related services. Individual and institutional investors, financial professionals, and plan sponsors can benefit from the size, stability, and experience Vanguard offers. As of April 30, 2019, we managed more than $5.6 trillion in global assets. In addition, we have 189 funds in the United States and 225 funds in global markets. For Commenting Guidelines & Important information, visit here: http://vanguard.com/linkedin Vanguard Marketing Corporation, Distributor.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Support Associate II

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
San Marcos, TX, USA
16000 Employees
15-20 Hourly

Samsara Logo Samsara

Analytics Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
119K-180K Annually

Spectrum Logo Spectrum

Sales Representative

Information Technology • Internet of Things • Mobile • On-Demand • Software
In-Office
Corpus Christi, TX, USA
100000 Employees
100K-100K Annually

Spectrum Logo Spectrum

Manager, Business Sales

Information Technology • Internet of Things • Mobile • On-Demand • Software
In-Office
Austin, TX, USA
100000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account