Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Capital One

Detection Engineer – Manager

Capital One

Manager-level Detection Engineer at Capital One, securing customers through endpoint detection engineering. Building AI-assisted, Detection-as-Code alerts and closing threat coverage gaps across enterprise systems.

Posted 9/10/2026full-timeMcLean • New York, Texas, Virginia • 🇺🇸 United StatesMid-LevelSenior💰 $179,400 - $245,600 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in endpoint security and threat detection, leveraging machine learning and data science to enhance detection capabilities. Proficient in developing high-fidelity alerts and conducting threat research while ensuring compliance with fintech standards.

Highest-signal resume keywords
Endpoint Security ExpertiseDetection EngineeringMachine Learning Application in SecurityEDR Platform ExperienceThreat Detection Development

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
SQLData QueryingWindows Event LogsSysmonEDR TelemetryBehavioral AnalyticsAnomaly DetectionRoot Cause AnalysisPythonDetection-as-Code
Soft Skills
MentoringCommunicationCollaboration
Tools & Technologies
CrowdStrike FalconSentinelOneMicrosoft DefenderDatabricksApache SparkCI/CD WorkflowsYAML-based Detection Frameworks
Certifications & Qualifications
GCIAGCIHCISSPGMONGREMGCTDMLEAWS Cloud PractitionerAWS Security
Industry Keywords
MITRE ATT&CKThreat HuntingAdversary EmulationCybersecurityFintech Compliance

Tech Stack

Tools & technologies
ApacheAWSCloudCyber SecurityLinuxMacOSPythonSparkSQL

About the role

Key responsibilities & impact
  • Own end-to-end detection coverage for the Endpoint domain, from telemetry requirements and threat landscape awareness through coverage gap identification and high-fidelity alert deployment
  • Leverage LLMs and machine learning to automate detection logic, summarize attack chains, reduce false positives, and accelerate detection development
  • Lead the design, development, and maintenance of Detection-as-Code rules using GenAI-assisted workflows and CI/CD pipelines
  • Design and build behavioral detections identifying adversary patterns, TTPs, and anomalous endpoint activity
  • Use the MITRE ATT&CK framework to visualize, prioritize, and close endpoint coverage gaps
  • Conduct hypothesis-driven threat research across enterprise endpoint environments and translate attacker techniques into detections
  • Manage telemetry onboarding, alert deployment, tuning, and continuous coverage gap analysis
  • Partner with business leaders, CSOC, Cyber Threat Intelligence, Cyber Threat Hunt, and the Coverage Review Team
  • Ensure documentation meets fintech compliance and audit standards
  • Mentor engineers on security concepts, AI-driven workflows, and detection engineering best practices
  • Contribute to detections powering CSOC investigations and incident response across the enterprise SIEM

Requirements

What you’ll need
  • High School Diploma, GED, or equivalent certification
  • At least 4 years of experience working in cybersecurity or information technology
  • At least 4 years of experience with endpoint and host logs, including Windows Event Logs, Sysmon, and EDR telemetry
  • At least 2 years of experience with EDR platforms, including CrowdStrike Falcon, SentinelOne, or Microsoft Defender
  • At least 4 years of experience developing alerts for threat detection
  • At least 2 years of experience with penetration testing, offensive security, or adversary emulation
  • At least 1 year of experience with machine learning or data science applied to security
  • Deep expertise in endpoint security, EDR platforms, and Windows, Linux, and macOS telemetry analysis
  • Previous experience on a detection engineering, threat detection, or threat detection operations team focused on endpoint threat surfaces
  • Extensive experience with SQL and data querying at scale
  • Strong understanding of attacker TTPs, Red Team methodologies, and translating offensive security insights into high-fidelity detections
  • Experience with ML or data science concepts applied to security use cases, including anomaly detection, behavioral analytics, or risk scoring
  • Ability to perform independent root cause analysis and convey complex security risks to technical and executive audiences
  • Demonstrated ability to mentor engineers and contribute to continuous improvement
  • No employer-sponsored immigration support is available for new applicants
  • Preferred: Bachelor's Degree
  • Preferred: 6+ years of experience in Threat Detection, Threat Hunting, or Security Engineering
  • Preferred: 4+ years of experience with Python
  • Preferred: 4+ years of experience with data science concepts and techniques
  • Preferred: 2+ years of experience publishing code to GitHub using CI/CD workflows
  • Preferred experience with Databricks, Apache Spark, streaming data platforms, Detection-as-Code, YAML-based detection frameworks, CrowdStrike Falcon, Windows internals, endpoint forensics, malware triage, or adversary emulation
  • Preferred: 2 or more professional certifications such as GCIA, GCIH, CISSP, GMON, GREM, GCTD, MLE, AWS Cloud Practitioner, or AWS Security

Benefits

Comp & perks
  • Performance-based incentive compensation, which may include cash bonuses and/or long-term incentives (LTI)
  • Comprehensive, competitive, and inclusive health, financial, and other benefits supporting total well-being
  • Equal opportunity employer committed to non-discrimination
  • Reasonable accommodation support