Head of Detection Engineering - VP
State Street · Quincy, MA · 2 wk ago
Engineering$120k–$218k/yrFull-time
About the role
We are seeking a Head of Detection Engineering to report to the Managing Director of Cybersecurity Platform Engineering. You will employ the firm’s cyber detection capabilities within the Continuous Security Monitoring program to detect adverse cybersecurity events. You will ensure that State Street can effectively analyze security relevant logs to detect adverse cybersecurity events. This person owns detection related controls within the Continuous Security Monitoring program. This role is responsible for a mature detection engineering capability that requires continuous evolution.
Responsibilities
- Own the development of the global detection engineering strategy.
- Own the logging and monitoring standard and ensure it aligns to requirements.
- Ensure detection capabilities satisfy requirements from multiple sources.
- Ensure that detection engineering capabilities are effectively employed to detect adverse cyber events.
- Govern the development, modification and performance monitoring of Detection Rules.
- Maintain governance processes for detection rule development, modification, and retirement.
- Serve as the approval authority for changes to Detection capabilities.
- Influence the design and implementation of Continuous Security Monitoring.
- Govern the charter, planning, execution, reporting, and close-out detection engineering projects.
- Own the Detection Engineering’s portfolio of work.
- Ensure detection engineering maintains detailed documentation.
- Provide evidence to risk management, corporate audit, and others.
Qualifications
- Bachelor’s degree in a relevant field, or +15 years of experience in lieu of a bachelor's degree.
- 10+ years of managerial experience in cybersecurity.
- 4+ years of experience performing or managing detection engineering or similar activities.
- Knowledge of Security Information and Event Management (SIEM), and Endpoint Detection and Response (EDR) platforms; detection engineering processes.
- Knowledge of adversary tactics and techniques.
- Knowledge of networks, infrastructure, computing, identity and access management (IAM), data engineering, relevant software languages, and telemetry.
- Knowledge of anomaly and behavior analytics, statistics, probability, and social threat detection mechanisms.
- Excellent verbal and written business communication in English.
Additional Preferences
- Has led teams of 10 or more people.
- Written articles, researched, and presented on cybersecurity topics.
- Theoretical approach, backed by evidence, how to employ detection capabilities to secure an organization.
- Experience using artificial intelligence, including machine learning and large language models, to detection and respond to adverse cyber events.
- Able to travel domestically and internationally up to 20% of the time.
What we value
- You stick with problems longer, driving the organization to clarity.
- You identify strategic problems and take initiative to solve them for the organization.
- You visualize and act at multiple contextual levels (e.g., enterprise, code snippets).
- You build long-term, mutually beneficial relationships across the organization and beyond.
Pay
$120,000 - $217,500 Annual
Schedule
Hybrid role First Shift