Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Thomson Reuters

Lead Cyber Threat Management Analyst

Thomson Reuters

. Architect, develop, implement, and maintain scalable threat detection logic across SIEM, EDR, cloud-native security platforms, and enterprise security data sources .

Posted 9/21/2026full-timeRichmond • Virginia • United StatesSenior💰 $118,400 - $219,800 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in threat detection engineering, including the development and tuning of detection logic across various security platforms. Proficient in operationalizing threat intelligence and collaborating with cross-functional teams to enhance security response workflows.

Highest-signal resume keywords
Threat Detection EngineeringMITRE ATT&CK FrameworkSecurity Log AnalysisDetection AutomationCloud Security Platforms

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Detection Logic DevelopmentSecurity OperationsIncident ResponseThreat IntelligenceScripting with PythonAutomation with PowerShellData EnrichmentDetection-as-Code WorkflowsThreat HuntingAdversary Simulation
Soft Skills
Technical LeadershipMentoringCollaborationCommunication
Tools & Technologies
SIEMEDRSOARXDRCloud Security ServicesAI-Enabled Security ToolsSecurity Data Integration
Certifications & Qualifications
GCIAGCTIGCEDOSCP
Industry Keywords
Cyber DefenseAdversary TacticsIndicators of CompromiseBehavioral IndicatorsFalse Positive Analysis

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud PlatformPython

About the role

Key responsibilities & impact
  • Architect, develop, implement, and maintain scalable threat detection logic across SIEM, EDR, cloud-native security platforms, and enterprise security data sources
  • Design and tune detection content for emerging threats, suspicious activity, adversary behaviors, and indicators of compromise while minimizing false positives and alert fatigue
  • Map detections to the MITRE ATT&CK framework to assess defensive coverage, identify detection gaps, and prioritize improvements
  • Operationalize threat intelligence into actionable detection and monitoring strategies
  • Collaborate with Threat Intelligence, Incident Response, Security Operations, and Security Engineering teams to validate detection effectiveness and improve response workflows
  • Analyze security logs, alerts, telemetry, and behavioral data to identify patterns, anomalies, and potential malicious activity
  • Lead detection workflows, enrichment pipelines, and automation to improve investigation speed, alert context, and analyst efficiency
  • Use AI-enabled security tools responsibly for detection development, alert triage, threat research, documentation, and hypothesis generation, validating outputs before operational use
  • Evaluate detection performance through analytics, testing, threat simulations, incident findings, red team results, and operational metrics
  • Incorporate incident, threat hunt, vulnerability intelligence, vendor, and adversary research findings into detection strategies
  • Partner with Incident Response teams to investigate detection gaps, validate alerts, improve escalation criteria, and strengthen containment and remediation workflows
  • Develop and maintain documentation for detection logic, data sources, use cases, tuning decisions, investigation procedures, and coverage assessments
  • Mentor junior detection engineers and analysts
  • Contribute to the strategic direction, operational maturity, and roadmap of the Threat Detection program
  • Participate in cross-functional security initiatives, design reviews, and operational-readiness discussions

Requirements

What you’ll need
  • 5+ years of experience in threat detection engineering, security operations, incident response, threat intelligence, cyber defense, or a related cybersecurity discipline
  • Demonstrated experience developing, tuning, and maintaining detection logic across multiple security platforms, including SIEM, EDR, cloud-native security tools, or similar technologies
  • Strong experience analyzing security logs, alerts, telemetry, and event data from endpoint, identity, network, cloud, application, and infrastructure environments
  • Deep understanding of adversary tactics, techniques, and procedures
  • Strong proficiency with the MITRE ATT&CK framework, including detection mapping, coverage analysis, and identification of defensive gaps
  • Experience operationalizing threat intelligence, including indicators of compromise, behavioral indicators, and adversary tradecraft
  • Experience scripting or automating security workflows using Python, PowerShell, or comparable languages
  • Ability to develop and improve data enrichment, detection automation, alert triage, and investigation workflows
  • Experience collaborating with Incident Response, Threat Intelligence, Security Engineering, cloud, and other technical teams
  • Ability to evaluate detection quality using testing, analytics, false-positive analysis, alert trends, incident findings, and coverage metrics
  • Strong written and verbal communication skills
  • Demonstrated technical leadership skills, including mentoring team members or leading cross-functional security initiatives
  • Experience with cloud platforms and security services across Azure, AWS, GCP, or hybrid environments
  • Experience with SIEM, EDR, SOAR, XDR, cloud security, identity security, network security, or threat intelligence platforms
  • Experience conducting threat hunting, purple-team exercises, detection validation, adversary simulation, or red-team detection analysis
  • Experience designing or maintaining detection-as-code workflows, detection engineering standards, content lifecycle processes, or automated testing frameworks
  • Experience integrating security data sources and developing enrichment pipelines
  • Familiarity with AI-enabled security operations, detection engineering, threat intelligence, or investigation tools
  • Relevant security certifications such as GCIA, GCTI, GCED, OSCP, or comparable certifications are beneficial but not required

Benefits

Comp & perks
  • Flexible hybrid working environment
  • Flexible work arrangements, including work from anywhere for up to 8 weeks per year
  • Continuous learning and skill development through Grow My Way programming
  • Flexible vacation
  • Two company-wide Mental Health Days off
  • Headspace app access
  • Retirement savings
  • Tuition reimbursement
  • Employee incentive programs
  • Mental, physical, and financial wellbeing resources
  • Two paid volunteer days off annually
  • Opportunities for pro-bono consulting projects and ESG initiatives
  • Health, dental, vision, disability, and life insurance programs
  • Competitive 401(k) plan with company match
  • Competitive vacation, sick and safe paid time off
  • Paid holidays, including two company mental health days off
  • Parental leave
  • Sabbatical leave
  • Optional hospital, accident and sickness insurance
  • Optional life and AD&D insurance
  • Flexible Spending and Health Savings Accounts
  • Fitness reimbursement
  • Employee Assistance Program
  • Group Legal Identity Theft Protection benefit
  • 529 Plan access
  • Commuter benefits
  • Adoption & Surrogacy Assistance
  • Employee Stock Purchase Plan