Detection Engineer Manager

Capital One Financial

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
McLean, VARichmond, VANew York, NYPlano, TX
Salary
$179,400–$204,700 / yr
Posted
5 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $205k
This role $192k
$142k most similar roles pay here $251k

This role pays less than 56% of similar roles. Most pay $170,000–$239,400 — the shaded band above. At the midpoint, this role pays about $192k versus about $205k for comparable roles.

Based on 240 similar postings.

Employer

About Capital One Financial

Capital One Financial is a bank holding company specializing in credit cards, auto loans, banking, and savings products, known for its data-driven approach to consumer and commercial finance. Industry: Financial Services & Banking

Capital One Financial currently has 1039 open roles on FindRole.

Listed pay typically runs $197,300–$225,100 across 1033 roles with salary data.

Most-posted roles

View all roles at Capital One Financial

At a glance

TL;DR · Detection Engineer Manager

Detection Engineer, Manager serves as a senior technical contributor within the Cyber Threat Detection team, focusing on end-to-end detection coverage for the endpoint domain. The role involves identifying coverage gaps, developing high-fidelity alerts, and managing telemetry requirements to protect assets from sophisticated threats. You will build and maintain detection rules using a Detection-as-Code methodology, utilizing YAML-based rules, GitHub version control, and CI/CD pipelines. Key responsibilities include leveraging LLMs and machine learning to automate logic, performing behavioral engineering to identify adversary TTPs via the MITRE ATT&CK framework, and conducting hypothesis-driven threat research. Required skills include expertise in EDR platforms like CrowdStrike Falcon or SentinelOne, proficiency in SQL, Python, and data science concepts such as anomaly detection. The role addresses the challenge of securing enterprise environments by translating offensive security insights into automated, scalable detections.

What you'll do

  • Own end-to-end detection coverage for the endpoint domain from telemetry requirements to high-fidelity alert deployment.
  • Develop and maintain detection rules using Detection-as-Code methodologies, including YAML-based rules and CI/CD pipelines.
  • Leverage LLMs and machine learning to automate detection logic and reduce false positives in the development lifecycle.
  • Build behavioral detections that identify adversary patterns, TTPs, and anomalous activity across endpoint environments.
  • Map the MITRE ATT&CK framework to identify and close coverage gaps while balancing fidelity and operational risk.
  • Conduct hypothesis-driven threat research by translating Red Team methodologies into actionable detection rules.
  • Mentor engineers on security concepts, AI-driven workflows, and best practices in detection engineering.
  • Ensure all monitoring documentation meets strict fintech compliance and audit standards for internal and external stakeholders.

What we're looking for

  • High School Diploma, GED, or equivalent certification.
  • At least 4 years of experience in cybersecurity or information technology.
  • At least 4 years of experience with endpoint and host logs including Windows Event Logs, Sysmon, and EDR telemetry.
  • At least 2 years of experience with EDR platforms such as CrowdStrike Falcon, SentinelOne, or Microsoft Defender.
  • At least 4 years of experience developing alerts for threat detection.
  • At least 2 years of experience with penetration testing, offensive security, or adversary emulation.
  • At least 1 year of experience with machine learning or data science applied to security.
  • Bachelor's Degree (preferred); 6+ years of experience in Threat Detection, Threat Hunting, or Security Engineering (preferred).

More like this

Similar roles

Senior Security Engineer, Detection Engineering

Nvidia

Remote 6 days ago $168,000$270,250
Splunk Microsoft Sentinel CrowdStrike Python SQL KQL SPL Git CI/CD Detection-as-Code Kubernetes Cloud Security Threat Hunting Incident Response
8+ yrs exp Remote

Senior Detection Engineer, AI-ML Focus

P&G

Cincinnati, OH 23 days ago $110,000$165,300
SIEM Python Git CI/CD MITRE ATT&CK LLM AI Agents Sigma YAML SOAR EDR Kubernetes Cloud-native Architecture Detection-as-Code
5+ yrs exp

Specialist, Cyber Detection Engineer

Prudential Financial

Newark, NJ 54 days ago $96,200$158,800
SIEM XDR Splunk KQL SQL Python PowerShell GraphQL MITRE ATT&CK Incident Response Threat Hunting
3+ yrs exp

Lead Detection Engineer, Cyber Defense & Response

Prudential Financial

Newark, NJ 61 days ago $123,700$204,100
Splunk Enterprise Security SPL KQL Python SOAR CI/CD MITRE ATT&CK Cyber Kill Chain Threat Hunting Incident Response Digital Forensics Security Automation Linux Windows macOS

Senior Detection Engineer

DoorDash, Inc

Remote 26 days ago $159,800$235,000
Detection Engineering Python Go SQL SPL KQL Snowflake Cortex Google SecOps MITRE ATT&CK D3FEND Data Pipelines Cloud Infrastructure Automation Threat Intelligence
7+ yrs exp Remote

Senior Detection Engineer II

Instacart

Remote 22 days ago $230,000$242,500
Detection-as-Code SOAR CI/CD Python Golang AWS Azure GCP macOS Threat Hunting SaaS Machine Learning
6+ yrs exp Remote