Manager, Detection Engineering (Rapid Response Team)
As a Manager, Detection Engineering, you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence. This is a hands-on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast-moving, reactive environment. You will partner closely with cross-functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage.
What Will You Do?
Primary responsibilities include:
Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.
Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.
Own RRT's operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.
Protect the team's focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times.
Grow the cross-functional partnerships that extend RRT's reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.
Own and evolve the team's roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.
Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team's needs.
Drive proactive, transparent communication of RRT's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.
What Skills and Knowledge Will You Bring?
Ideal candidates will have:
Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.
Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops.
Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows.
Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines.
Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.
Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns.
A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.
Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.
Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.
Familiarity with intake and triage workflows and detection automation tooling is a strong plus.
Why SentinelOne?
AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.
We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:
Equity & Rewards
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
Flexible time off
Paid company holidays and paid sick time
Gender-neutral parental leave
Grandparent leave
Insurance & Financial Security
Medical, dental, and vision coverage
401(k) retirement plan with company match
Life and disability insurance
Health and dependent care FSA
Voluntary benefits (hospital, accident, critical illness)
Employee Assistance Program (EAP)
ARAG pre-paid legal
Nationwide pet insurance
Cancer Care program
Global business travel medical insurance
Work Perks & Flexibility
Home office allowance
Mobile phone reimbursement
Wellness & Lifestyle
Wellness coach
Wellness/gym reimbursement
Fertility coverage
Adoption & surrogacy reimbursement
This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply. If so, this range will be provided to you during the recruiting process. You can also reach out to the recruiter with any questions.
Base Salary Range
$164,000—$226,000 USD