← Back to jobs

Director, Detection Engineering and Automation

Location
Chicago, IL
Work type
Full Time · On-site
Posted
2026-08-30

Job description

The role partners closely with Threat Intelligence, Security Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams to strengthen proactive defense and improve operational response. This leader will drive the development of scalable detection and automation strategies that reduce cyber risk, enhance visibility, and accelerate threat identification and response across the enterprise. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

Role Overview and Core Responsibilities

Lead the Detection Engineering and Automation function, establishing the team as the authoritative center of excellence for prioritized, high-fidelity detections that reduce risk across endpoint, identity, network, and cloud environments.
Define and execute the detection engineering and automation strategy, ensuring detection priorities are aligned to the evolving threat landscape, enterprise risk, and organizational priorities.
Lead, develop, and scale a team of approximately 14 detection and automation engineers and one manager, building leadership capability, fostering a high-performance culture, and supporting continued team growth.
Own the end-to-end detection lifecycle, from ideation and prioritization through development, testing, deployment, tuning, and ongoing optimization to ensure detections remain relevant and actionable.
Drive automation and response workflow integration across SOAR, SIEM, and EDR platforms to increase detection coverage, reduce manual effort, and improve operational scalability.
Mature the detection platform by evaluating and adopting scalable tooling, simplifying detection authoring, and enabling faster turnaround on new detection capabilities.
Lead cloud detection capability development by closing current coverage gaps and building durable cloud-native detection capabilities in partnership with Cloud Infrastructure Security and Engineering.
Partner cross-functionally with SecOps, Threat Intelligence, SIRT, and Engineering to ensure detection outputs are actionable, response plans are current, and automation reduces manual response burden.
Define, track, and communicate key detection metrics, including detection coverage, detection effectiveness, false positive rates, mean time to detect, and automation throughput.
Represent Detection Engineering in senior leadership forums by providing clear, decision-oriented updates on detection posture, platform health, risk coverage, and team progress.

Original source