Engineering Manager, Security Detection & Response
Role Overview
Apollo is looking for a startup-minded Engineering Manager to lead our Security Detection & Response team. You'll build and scale a team that ships detection systems, automations, and investigation tools at startup velocity—moving from concept to production in weeks, not months. This is a hands-on leadership role for someone who can coach engineers, make fast decisions with incomplete information, and stay close to the technical details while balancing speed with rigor.
This role operates in a fully remote environment and requires excellent asynchronous communication, comfort with ambiguity, and the ability to ship fast and learn from what sticks.
Key Responsibilities
Team Leadership & Engineering Culture
Build, lead, and retain a high-performing remote Security Detection & Response team with clear expectations, strong onboarding, documentation, and knowledge-sharing practices.
Coach engineers to grow in technical depth, operational ownership, and leadership capability while prioritizing shipping velocity and iteration over perfection.
Define team culture around experimentation: ship detection rules quickly, measure effectiveness, iterate based on signal.
Partner closely with Engineering, Infrastructure, IT, Fraud, Legal, People, Support, and Product—translating security risk into business decisions and communicating impact clearly to both technical and non-technical stakeholders.
Shipping Detection Systems & Content at Startup Velocity
Define and evolve the Security Detection & Response strategy: what to build, when, and why. Prioritize ruthlessly; not every threat gets a detection.
Lead the team in shipping detection rules, MITRE ATT&CK-aligned use cases, investigation playbooks, and response automations with measurement and validation loops—but ship first, perfect later.
Oversee Panther detections and AI-assisted workflows for triage, enrichment, and response. Continuously measure coverage, precision, latency, and tuning effectiveness through safe rollout and attack simulation.
Drive Python-based tooling, Git-based workflows, and CI/CD practices to enable the team to ship detection content in days, not quarters.
Stay close to the technical work: code reviews, architecture decisions, and hands-on problem-solving alongside the team.
Security Observability & Incident Response as Outcome
Own end-to-end security observability: telemetry onboarding, signal quality, threat intelligence inputs, and alert tuning. Good detections prevent incidents.
Lead complex and high-severity incidents with clear decision-making and effective communication. Translate incident learnings into detection and response priorities for the next sprint.
Stay technically engaged in investigations across cloud infrastructure, SaaS platforms, corporate systems, and user behavior. Use incidents as teaching moments for the team and validation for detection strategy.
Work with Engineering and Infrastructure on telemetry pipelines and operational readiness. Ensure the team has the data they need to ship fast.
Metrics & Impact
Define and own strategy-aligned metrics: detection latency, coverage gaps, false positive rates, team velocity. Use data to inform priorities and stakeholder decisions.
Communicate security impact in business terms: what risks are you preventing, and what's the cost of being wrong?
Required Skills & Experience
5+ years in Security Detection & Response, Security Engineering, or Incident Response—hands-on experience building and shipping detection systems, not just managing incidents.
2+ years of people management, including hiring, coaching, and performance management, ideally in a remote-first environment.
Strong technical foundation: modern SIEM platforms, detection engineering, log analysis, threat intelligence workflows. Panther experience highly valued.
Python proficiency for automation, analysis, and internal tooling. You need to remain technically credible with your engineers and review code.
Comfort with startup velocity: able to make sound decisions with incomplete information, ship fast, iterate based on feedback, and know when "good enough" is good enough.
Git workflows, CI/CD practices, and experience building security content and automation pipelines as code.
Cloud-native and SaaS expertise: GCP preferred. Familiarity with Apollo's toolsets (Google Workspace, Okta, GitHub, Slack, Atlassian, Cloudflare, CrowdStrike, Kandji, Panther, Snowflake) strongly valued.
Excellent communication: You'll translate technical security work into business impact for executives and explain engineering trade-offs to non-technical stakeholders.
Preferred Qualifications
Experience leading Detection Engineering or Security Engineering teams in a high-growth cloud or SaaS startup environment (not just enterprises or government).
AI-assisted security workflows: You've used AI for triage, investigation, or response in production and know the limitations.
MITRE ATT&CK, threat intelligence workflows, and vulnerability management SLAs—but with a bias toward automation and shipping, not just compliance.
Relevant certifications such as CISSP, GCIA, GCIH, GCED, or cloud security certifications.
Track record of shipping fast: you've led teams that iterate weekly and measure success by velocity + signal.
The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process.
Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits.
Pay Transparency Range
$225,400—$281,800 USD