Skip to content
NEXTMOVEFDE careers · United States

Manager, Threat Detection Engineer

AI summary of the role

The Threat Detection Engineer is a hands-on technical leader at Carlyle, responsible for leading detection engineering and threat intelligence processes.

What you’ll do

  • Own the detection content lifecycle, from requirements and design through testing, deployment, tuning, and retirement.
  • Develop high-fidelity detections across endpoint, identity, email, network, cloud, and business-critical application telemetry.
  • Translate adversary behaviors and threat intelligence into testable detection hypotheses and production-ready analytics.
  • Manage intelligence requirements and produce timely assessments and briefings for security operations and executives.

What you’ll bring

  • 5-7 years of relevant information-security or cybersecurity experience.
  • 4+ years of hands-on experience in threat detection engineering and cyber threat intelligence.
  • Hands-on experience creating, testing, deploying, and tuning production detection logic via structured query, rule, or analytic language.
  • Experience developing automation with a general-purpose language and integrating systems through APIs.

Technologies

Sigma · KQL · SPL · XQL · YARA-L · EQL · SQL · YARA · SIEM · EDR/XDR · SOAR · MITRE ATT&CK

Source and classification

Internal deployment & tooling · Evidence for this classification:

Position Summary The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and Intelligence Lead, the Threat Detection Engineer leads assigned detection engineering and threat intelligence processes, turns intelligence into production detections and works with security partners to improve operational outcomes. This role oversees detection content from requirements and design through testing, deployment, tuning and retirement. It also develops intelligence that supports security operations and risk decisions and partners on threat hunting, external-risk response, digital-risk support for executive protection, automation, SOC interaction and platform reliability. The Threat Detection Engineer chooses among AI-assisted methods, deterministic automation and process
More from the job description

Position Summary The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and Intelligence Lead, the Threat Detection Engineer leads assigned detection engineering and threat intelligence processes, turns intelligence into production detections and works with security partners to improve operational outcomes. This role oversees detection content from requirements and design through testing, deployment, tuning and retirement. It also develops intelligence that supports security operations and risk decisions and partners on threat hunting, external-risk response, digital-risk support for executive protection, automation, SOC interaction and platform reliability. The Threat Detection Engineer chooses among AI-assisted methods, deterministic automation and process changes based on the problem, risk and expected value. This is a hands-on technical leadership role that prioritizes assigned services, reviews technical work, coaches contributors and works across teams to carry out Carlyle’s Threat Detection and Intelligence strategy. In-Office Requirement: 4 days per week Primary Responsibilities Detection Engineering and Coverage - 30% Own the detection content lifecycle and use analyst feedback, detection coverage, alert quality, data quality, delivery time [... source excerpt omitted ...] n the context analysts need to investigate and act. Translate adversary behaviors, threat intelligence, incident learnings and control gaps into testable detection hypotheses and production-ready analytics. Implement approved quality gates for detection content, including data validation, expected-behavior testing, false-positive tolerance, investigation guidance and rollback plans. Use detection-as-code for internally managed content and supported tuning, compensating analytics or provider escalation for vendor-managed content. Coordinate and support targeted threat hunts with incident response and other security partners to validate hypotheses, uncover gaps and convert repeata [... source excerpt omitted ...] rk, establish reusable standards and coach contributors on detection design, testing and investigative usability. Threat Intelligence and External Risk - 30% Manage intelligence requirements based on Carlyle's threat profile, critical assets, executives and business priorities, including portfolio-related risks relevant to Carlyle. Collect, assess and synthesize strategic, operational and tactical intelligence concerning relevant threat actors, campaigns, vulnerabilities, techniques and emerging risks. Produce timely assessments and briefings tailored to security operations, incident response, technology leaders, executives and other stakeholders. Turn intelligence into prioriti

How jobs are selected

Employer postings · Data from · Sources