Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Capital One

Detection Engineer Manager, Cyber Security

Capital One

. Leverage LLMs and machine learning to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development .

Posted 9/29/2026full-timeUnited StatesMid-LevelSenior💰 $179,400 - $245,600 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Threat Detection and Cybersecurity Engineering, leveraging Machine Learning and Detection-as-Code methodologies to enhance endpoint security. Proficient in using the MITRE ATT&CK framework and EDR platforms to identify and mitigate cyber threats effectively.

Highest-signal resume keywords
Threat DetectionMachine Learning Applied to SecurityEndpoint ForensicsDetection-as-Code MethodologiesEDR Platforms

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
CybersecurityThreat HuntingBehavioral AnalyticsAnomaly DetectionPythonEndpoint Logs AnalysisDetection Rule DevelopmentTelemetry AnalysisSecurity Incident AnalysisAdversary Emulation
Soft Skills
MentoringCollaborationCommunication
Tools & Technologies
CrowdStrike FalconSentinelOneMicrosoft DefenderSplunkQualysAWS Security Hub
Certifications & Qualifications
GCIAGCIHCISSPGMONGREMGCTDMLE
Industry Keywords
MITRE ATT&CKNIST CSFCMMCFedRAMPFintech Compliance

Tech Stack

Tools & technologies
AWSCloudCyber SecurityPythonSplunk

About the role

Key responsibilities & impact
  • Leverage LLMs and machine learning to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development
  • Lead design, development, and maintenance of detection rules using Detection-as-Code methodologies, GenAI-assisted workflows, and CI/CD pipelines
  • Design and build behavioral detections identifying adversary patterns, TTPs, and anomalous endpoint activity
  • Use user and entity behavior signals, process telemetry, and correlation logic to distinguish malicious from benign activity at scale
  • Use the MITRE ATT&CK framework to visualize, prioritize, and close endpoint coverage gaps
  • Drive detection architecture decisions balancing fidelity, volume, and operational risk
  • Conduct hypothesis-driven threat research across enterprise endpoint environments using Red Team methodologies and adversary TTPs
  • Translate attacker techniques into high-fidelity detections and proactively identify coverage gaps
  • Own end-to-end detection coverage for the Endpoint threat surface, from telemetry onboarding through alert deployment, tuning, and continuous coverage analysis
  • Partner with business leaders, CSOC, Cyber Threat Intelligence, and Cyber Threat Hunt
  • Ensure documentation meets fintech compliance and audit standards
  • Mentor engineers on security concepts, AI-driven workflows, and detection engineering best practices

Requirements

What you’ll need
  • Bachelor's Degree
  • At least 5 years of experience in cybersecurity or information technology
  • At least 4 years of experience evaluating, contributing to, or supporting development of cybersecurity capabilities
  • At least 4 years of experience with endpoint or host logs, including Windows Event Logs, Sysmon, and EDR telemetry
  • At least 2 years of experience with EDR platforms, including CrowdStrike Falcon, SentinelOne, and Microsoft Defender
  • At least 1 year of experience with machine learning or data science applied to security
  • 6+ years of experience in Threat Detection, Threat Hunting, or Security Engineering preferred
  • 5+ years of experience with cybersecurity frameworks and concepts such as NIST CSF, MITRE ATT&CK, CMMC, and FedRAMP preferred
  • 5+ years of experience analyzing or developing solutions for cyber threats, vulnerabilities, risks, or events preferred
  • 5+ years of experience working on teams and presenting cybersecurity information to stakeholders preferred
  • 4+ years of experience with Python preferred
  • 4+ years of experience using security tools such as Splunk, CrowdStrike, Qualys, or AWS Security Hub preferred
  • 4+ years of experience with data science concepts and techniques such as anomaly detection and behavioral analytics preferred
  • Ability to perform security incident analysis and assist with resolution
  • Experience with CrowdStrike Falcon, including custom IOAs, detection tuning, and telemetry analysis
  • Experience with endpoint forensics, malware triage, or adversary emulation exercises targeting endpoint environments
  • GCIA, GCIH, CISSP, GMON, GREM, GCTD, MLE, or Cloud certifications preferred
  • Capital One will not sponsor a new applicant for employment authorization or provide immigration-related support

Benefits

Comp & perks
  • Performance-based incentive compensation, including cash bonus(es) and/or long-term incentives (LTI)
  • Comprehensive health, financial, and other benefits supporting total well-being
  • Reasonable workplace accommodations
  • Drug-free workplace