InfoSec - Senior Manager, Threat Detection

2 days ago


Denver CO United States Elastic Full time

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter.

What is The Role:

As the Sr. Manager, Threat Detection at Elastic you are helping Elastic deliver safe and secure products and services to our customers, users, and fellow Elasticians. You'll partner with teams company-wide to learn about Elastic's threat landscape and adapt our monitoring as a result. You will be responsible for assessing and improving Elastic's threat defense coverage and processes for the entire organization, developing and tuning detections across a wide variety of sources that include multiple cloud providers, CI/CD environments, SaaS services, user workstations, and more. You'll also help support incident response activities by providing expertise in log analysis during security events.

What You Will Be Doing:

  • Review existing detection lifecycle and develop plans for continuous improvement
  • Partner with the Distributed Security Response Team (DSRT) to review and enhance alerting and alert strategy on a regular basis
  • Enhance dynamic / risk-based detection strategy, identifying opportunities for and creating UEBA and machine learning based detections
  • Identify areas for workflow automation, context enrichment, and other enhancements to the alerting workflow leveraging our SOAR platform or Elastic Stack native capabilities
  • Partner with the product team on new features, bug fixes, and detection ideas to transfer ideas into features
  • Evolve and grow our existing threat detection practice by working with our threat detection engineering team and our partners developing threat detection resources for our customers and community
  • Share with our community how we leverage the Elastic Stack to keep Elastic safe through blog posts, webinars, meetups, and other opportunities
  • Mentor and coach team members to help them unlock the best version of themselves

What You Bring:

  • At least 8 years of experience designing, implementing, and performing monitoring and detection in a complex, global environment
  • Demonstrated ability to think innovatively about solving critical security problems
  • Curiosity for research and uncovering the unknown about cyber behavior
  • Experience leading a team of detection engineers or related professionals
  • Experience with machine learning is a plus

Additional Information:

As a distributed company, diversity drives our identity. Whether you're looking to launch a new career or grow an existing one, Elastic is the type of company where you can balance great work with great life. We strive to have parity of benefits across regions, and while regulations differ from place to place, we believe taking care of our people is the right thing to do.

  • Competitive pay based on the work you do here and not your previous salary
  • Health coverage for you and your family in many locations
  • Ability to craft your calendar with flexible locations and schedules for many roles
  • Generous number of vacation days each year
  • Increase your impact - We match up to $2000 (or local currency equivalent) for financial donations and service
  • Up to 40 hours each year to use toward volunteer projects you love
  • Embracing parenthood with a minimum of 16 weeks of parental leave

Different people approach problems differently. We need that. Elastic is an equal opportunity/affirmative action employer committed to diversity, equity, and inclusion.

We welcome individuals with disabilities and strive to create an accessible and inclusive experience for all individuals. To request an accommodation during the application or the recruiting process, please email

#J-18808-Ljbffr

  • Boston, MA, United States Elastic Full time

    Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the...


  • Austin, TX, United States Synopsys, Inc. Full time

    We Are: At Synopsys, we drive the innovations that shape the way we live and connect. Our technology is central to the Era of Pervasive Intelligence, from self-driving cars to learning machines. We lead in chip design, verification, and IP integration, empowering the creation of high-performance silicon chips and software content. Join us to transform the...


  • Houston, TX, United States Harrington Starr Full time

    The role will involve working in their global security team and will be responsible of helping develop effective security controls.Key responsibilities will include:Working closely with the in-house security operations team to drive world class threat detectionBuilding effective detection use cases within the chosen SIEM while minimizing false...


  • Washington, DC, United States Capgemini Government Solutions Full time

    Capgemini Government Solutions (CGS) is seeking a highly motivated Cyber Security Content Developer/ Cyber Threat Detection Developer (Threat Detection Developer) for User Activity Monitoring (UAM) to join our team to support our government clients. This role requires a Content Developer to provide support for onsite Insider Threat support services providing...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented **Cyber Security Engineer, Detections** to join our team in **Denver, CO area** , to provide unparalleled support to our customer and to begin an exciting and rewarding career within ManTech. **Responsibilities include, but are not limited to:** + Support Cyber Operations Squadron (COS)...

  • Insider Threat Analyst

    21 hours ago


    , MD, United States Pueo Business Solutions LLC Full time

    OVERVIEW: This role is responsible for overseeing the design and implementation of comprehensive security strategies and capabilities to mitigate and manage insider threats (InT)/User Activity Monitoring (UAM). This individual will work closely with cybersecurity teams, other technical teams, and business stakeholders to maintain and advanced insider threat...


  • , MA, United States General Dynamics Corporation Full time

    Responsibilities for this Position Location: USA AZ Fort Huachuca - Fort Huachuca (AZC001)Full Part/Time: Full timeJob Req: RQ183608Type of Requisition: RegularClearance Level Must Currently Possess: Top Secret/SCIClearance Level Must Be Able to Obtain: Top Secret/SCISuitability: Public Trust/Other Required: NoneJob Family: Information SecurityJob...


  • , LA, United States Ankura Full time

    Ankura Senior Managing Director, Incident Response & Managed Detection & Response (MDR) Business Development Executive Louisiana Apply Now Ankura is a team of excellence founded on innovation and growth. Practice Overview Ankura’s well-regarded and fast-growing Cybersecurity and Data Privacy practice offers a full-service suite of information security and...

  • INFOSEC Specialist

    21 hours ago


    San Diego, CA, United States Prosync Tecnology Group Full time

    ProSync Technology Group, LLC | Full time INFOSEC Specialist San Diego, United States | Posted on 07/10/2024 ProSync is seeking passionate INFOSEC Specialists to help ensure security and intelligence compliance with policies and regulations, drawing on some of the nation's leading personnel and cybersecurity thought leaders for enhancing, accelerating, and...

  • Threat Analyst

    4 weeks ago


    Orlando, FL, United States ThreatLocker Full time

    ThreatLocker is a global leader in Zero Trust endpoint security. The ThreatLocker Zero Trust Endpoint Protection Platform combines Application Allowlisting, Ringfencing, Network Control, Storage Control, Elevation Control, and Endpoint Detection and Response solutions in ways that make security simple for the IT professional. ThreatLocker utilizes a deny by...


  • Denver, United States ManTech Full time

    ManTech is seeking a motivated, career and customer-oriented Cyber Security Engineer, Detections to join our team in Denver, CO area , to provide unparalleled support to our customer and to begin an exciting and rewarding career within ManTech. Responsibilities include, but are not limited to: Support Cyber Operations Squadron (COS) activities to publish...


  • New York, NY, United States Cisco Systems, Inc. Full time

    Senior Product Manager, Firewall Threat Prevention Location: Offsite, Fulton, Maryland, US Alternate Location: RTP, NC; Austin, TX Compensation Range: 146000 USD - 205400 USD Job Type: Professional Job Id: 1428382 Application deadline expected to be October 25th. We are seeking a driven and knowledgeable Senior Product Manager to lead our Firewall Threat...


  • Whippany, NJ, United States Barclays Full time

    This exciting opportunity within the Chief Security Office focuses on the understanding, preparedness, detection and response to cyber threats and incidents to keep the bank, customers, clients and colleagues safe, secure and always on. Cyber Operations provides a global toolset to ensure confidentiality, integrity and availability of our information assets,...


  • Plano, TX, United States Celebree School of East Louisville Full time

    DUTIES AND RESPONSIBILITIES:• Develops and maintains a complete understanding of Aligned’s technologyand information systems.• Directs the development and maintenance of Incident Response Plans andCybersecurity procedures for information technology.• Maintains current knowledge of the cyber security industry, digital privacyregulations, and standards...


  • Denver, United States Disability Solutions Full time

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.One of the keys to driving Responsible Growth is being a great place to work for our...


  • Miami, FL, United States Carnival Corporation & plc Full time

    Job Description The Director of Insider Risk Management is responsible for developing, implementing, and overseeing a comprehensive insider risk management program across our global environment. This role involves identifying, assessing, and mitigating risks posed by insiders, including employees, contractors, and business partners, to protect the...


  • San Francisco, CA, United States ADVANCED ENGINEERING GROUP PC Full time

    Anthropic is an AI safety and research company that’s working to build reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our customers and for society as a whole. Our interdisciplinary team has experience across ML, physics, policy, business and product. Responsibilities: Lead a team of engineers building systems...


  • Denver, United States Disability Solutions Full time

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.One of the keys to driving Responsible Growth is being a great place to work for our...


  • Washington, DC, United States Trustwave Full time

    Posted Tuesday, October 8, 2024 at 11:00 PM Trustwave is a leading cybersecurity and managed security services provider focused on threat detection and response. We uncover threats that others can’t and respond quicker than others can to protect against the devastating impacts of cyberattacks. We’re a world-class team of cyber consultants, threat hunters...


  • Chicago, IL, United States Bank of America Full time

    Cyber Crime Threat Evaluation Manager Denver, Colorado; Washington, District of Columbia; Chicago, Illinois Job Description: The Cyber Crime Threat Evaluation Manager is responsible for identifying and assessing cyber threats across the cyber crime threat landscape, specifically evaluating emerging cyber crime trends and AI threats. The role involves...