Senior Manager, Detection & Response (Security Engineering)

Manager · Manager · Full Time · Remote

Remote, United States · RemoteUSD 242k – 319k2d ago
Apply for this role

Opens Confluent's application page

Role

What you'll do.

Senior Manager leading Confluent's Detection & Response organization within Infrastructure Security, responsible for defining strategic vision, technical roadmap, and operational execution for detecting, investigating, and responding to security threats across multi-cloud environments. Lead a distributed, high-performing engineering team across North America and India, building real-time security automation using Kafka, Kubernetes, and AI-assisted workflows with 12+ years of experience and proven team leadership capabilities.

Responsibilities

  • Strategic Vision & Roadmap Execution: Own the strategic vision and roadmap execution for Confluent's Detection & Response program across multi-cloud infrastructure environments (AWS, GCP, Azure). Define technical direction and ensure alignment with organizational security objectives and incident response maturity goals.
  • Team Leadership & Development: Build, scale, and mentor a distributed, global team of high-performing security engineers across North America and India. Foster professional development, drive hiring initiatives, and create an engineering-centric security culture that emphasizes automation and continuous improvement.
  • Detection Engineering & Incident Response Operations: Drive the evolution of detection engineering and incident response capabilities by leveraging modern software practices with emphasis on large-scale automation. Oversee security incident response operations, serve as escalation point and Incident Commander during high-severity security events, and lead comprehensive post-incident reviews.
  • Operational Metrics & Program Maturity: Establish and improve operational metrics to continuously evaluate and enhance program maturity. Track detection coverage, mean time to detect (MTTD), mean time to respond (MTTR), and other KPIs. Implement data-driven approaches to minimize operational toil and improve responder efficiency.
  • Cross-Functional Collaboration: Partner closely with Engineering, Legal, and Compliance teams to integrate detection telemetry and proactive response mechanisms across the company. Translate complex security risks into clear strategic priorities for engineering leadership and drive alignment across organizational stakeholders.
  • Security Automation & Platform Development: Champion development of real-time, high-throughput security automation systems utilizing Confluent's Kafka platform as central transport. Leverage scalable Kubernetes pipelines, custom ETL jobs, and AI-assisted triage workflows to reduce alert fatigue and improve threat detection accuracy.

Qualifications

What we look for.

Technical

  • Detection Engineering & Threat Intelligence

    Deep technical expertise in detection engineering, incident response workflows, and threat intelligence practices. Proven ability to design and implement detection strategies, build alert hierarchies, and develop threat models across enterprise environments.

  • Scalable Data Pipelines & Stream Processing

    Hands-on experience building or operating scalable data and event pipelines, modern telemetry stacks, or stream-processing architectures. Proficiency with Apache Kafka, event-driven architectures, and real-time data processing frameworks essential for modern security operations.

  • Multi-Cloud Security Infrastructure

    Technical knowledge across AWS, GCP, and Azure cloud environments. Understanding of cloud-native security posture, identity management, network security, and cloud-specific threat vectors across heterogeneous infrastructure.

  • Security Automation & Orchestration

    Experience designing and implementing security automation platforms, including SOAR (Security Orchestration, Automation and Response) concepts, custom ETL workflows, and AI-assisted triage systems. Familiarity with Infrastructure as Code and containerized environments (Kubernetes).

  • Incident Response & Crisis Management

    Demonstrated ability to lead complex, high-severity security incidents with composure, clarity, and cross-functional leadership. Experience with incident classification, response playbooks, post-incident review processes (blameless postmortems), and continuous improvement methodologies.

Education

  • Bachelor's Degree in Computer Science, Cybersecurity, or Engineering

    Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related technical field, or equivalent hands-on experience. Foundation in computer science principles and formal training in security domains strongly preferred.

  • Advanced Degree (Preferred)

    Master's degree in Computer Science, Cybersecurity, or related discipline is preferred and demonstrates commitment to continuous learning in rapidly evolving security domains. Advanced certifications in security engineering or incident response also valued.

Experience

  • Overall Software Engineering & Security Experience

    12+ years of experience in software development, security engineering, or security operations. Deep background in building resilient systems, understanding application security principles, and translating engineering practices into security contexts.

  • Engineering & Security Management

    5+ years in direct engineering or security management roles with proven track record of building, coaching, and scaling engineering teams across multiple time zones and distributed locations. Experience mentoring technical engineers and fostering high-performance team cultures.

  • Enterprise Security Operations

    Significant experience operating security programs at scale within enterprise organizations. Background in managing security operations centers (SOCs), detection platforms, or incident response capabilities serving large, complex infrastructure environments.

  • Stakeholder & Executive Communication

    Proven ability to communicate with diverse stakeholders including engineering leadership, Legal, Compliance, and executive management. Experience translating complex security risks into actionable strategic priorities and influencing organizational decision-making.

Skills

Required

  • Engineering Leadership

    Proven ability to lead, mentor, and scale distributed engineering teams across geographies. Experience building high-performance cultures, conducting performance reviews, succession planning, and fostering technical excellence among team members.

  • Detection Engineering

    Expert-level knowledge of building detection rules, alert tuning, YARA rules, SIGMA rules, or other detection methodologies. Understanding of attack patterns, adversary techniques (MITRE ATT&CK), and threat modeling frameworks.

  • Incident Response & SOAR Operations

    Hands-on experience managing security incidents, developing response playbooks, and operating Security Orchestration, Automation and Response (SOAR) platforms. Competency with incident classification, severity assessment, and escalation procedures.

  • Real-Time Data Processing

    Technical proficiency with Apache Kafka, stream-processing architectures, event-driven systems, and high-throughput data pipelines. Understanding of distributed systems concepts, horizontal scaling, and latency optimization in data-intensive environments.

  • Cloud Security Architecture

    Deep understanding of security posture across multi-cloud environments (AWS, GCP, Azure). Knowledge of cloud-native security services, identity and access management, cloud logging, and threat detection within cloud infrastructure.

  • Strategic Planning & Roadmap Development

    Demonstrated ability to define multi-year technical strategies, develop roadmaps, prioritize initiatives based on business impact, and drive execution across organizational boundaries. Experience with strategic frameworks like OKRs or similar planning methodologies.

  • Cross-Functional Stakeholder Management

    Excellent communication skills with ability to translate complex security concepts for diverse audiences including engineers, executives, Legal, and Compliance teams. Proven track record of building consensus and influencing without direct authority.

Preferred

  • Apache Kafka Expertise

    Nice to have

    Working knowledge of Confluent's Apache Kafka platform and stream processing capabilities. Understanding of Kafka's role in modern data architectures and potential applications in security telemetry collection and event processing.

  • Kubernetes & Container Security

    Nice to have

    Experience securing containerized environments, Kubernetes orchestration, and Infrastructure as Code practices. Knowledge of container networking, pod security policies, and runtime security monitoring for cloud-native applications.

  • AI/ML in Security Operations

    Nice to have

    Familiarity with machine learning applications in security including anomaly detection, behavioral analytics, and AI-assisted alert triage. Understanding of how ML can reduce false positives and improve detection accuracy at scale.

  • SIEM & Log Management

    Nice to have

    Experience with Security Information and Event Management (SIEM) platforms, centralized logging, log aggregation tools, and parsing structured/unstructured security telemetry. Knowledge of ELK, Splunk, or similar platforms beneficial.

  • Threat Intelligence Platforms

    Nice to have

    Experience integrating external threat intelligence feeds, managing threat intelligence platforms (TIPs), and operationalizing threat data for detection rule development and incident investigation.

  • Security Certifications

    Nice to have

    Industry certifications such as CISSP, CISM, CEH (Certified Ethical Hacker), GCIA (GIAC Certified Incident Handler), or GSEC (GIAC Security Essentials) demonstrate formal security expertise and commitment to professional development.

Tech stack

Languages

PythonGoSQLBash/Shell Scripting

Frameworks

Apache KafkaKubernetesETL Frameworks

Databases

ElasticsearchPostgreSQLClickHouse

Tools

SIEM Platforms (Splunk, ELK, IBM QRadar)SOAR Platforms (Palo Alto Cortex XSOAR, Splunk SOAR)Cloud Platforms (AWS, GCP, Azure)Threat Intelligence PlatformsIncident Management Tools (Jira, PagerDuty, Opsgenie)Git & Version Control

Other

MITRE ATT&CK FrameworkBlameless Postmortem ProcessesOKR (Objectives & Key Results)Infrastructure as Code (Terraform, CloudFormation)

Compensation

Pay and benefits.

Base·USD 241,700 – 319,000

Benefits

  • Competitive Health Insurance

    Comprehensive medical, dental, and vision coverage with options for employees and their families. Confluent provides competitive rates and coverage options designed for tech industry professionals.

  • 401(k) Retirement Plan

    Company-sponsored retirement savings plan with employer matching contributions to support long-term financial planning and retirement security.

  • Professional Development & Learning

    Budget for conferences, training programs, security certifications (CISSP, CISM, CEH, GCIA), and continuous learning opportunities. Support for staying current with rapidly evolving security landscapes.

  • Remote Work Flexibility

    Distributed team environment with flexibility in work arrangements. Location independence supporting work-life balance across North America, India, and other regions.

  • Equity Participation

    Stock options or RSU (Restricted Stock Unit) grants providing ownership stake in Confluent. Direct participation in company success as part of compensation package.

  • Time Off & Paid Leave

    Generous vacation, sick leave, and personal days. Unlimited or flexible PTO policies typical in high-growth tech companies with emphasis on employee wellbeing.

  • Leadership Development

    Executive coaching, management training, and leadership development programs designed to support growth trajectory for experienced security engineering leaders.

  • Inclusive & Diverse Culture

    Commitment to belonging as baseline value, supporting diverse perspectives, backgrounds, and identities. Equal opportunity workplace fostering psychological safety and inclusion.

Full posting

Original listing.

We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.

It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.

One Confluent. One Team. One Data Streaming Platform.


About the Role:

We are seeking an experienced engineering leader to head our Detection & Response organization within Infrastructure Security. In this role, you will define the strategic vision, technical roadmap, and operational execution for how Confluent detects, investigates, and responds to security threats across our multi-cloud environments (AWS, GCP, Azure).

You will lead and grow a distributed team of high-performing engineers across North America and India. Our team applies modern engineering principles to security—leveraging scalable Kubernetes pipelines, custom ETL jobs, AI-assisted triage workflows, and Confluent’s own data-streaming platform (Kafka) as our central transport. If you are passionate about building real-time, high-throughput security automation and fostering an engineering-first incident response culture, this role is for you.

What You Will Do:

  • Own the strategic vision and roadmap execution for Confluent's Detection & Response program across our multi-cloud infrastructure.

  • Build, scale, and mentor a distributed, global team across North America and India.

  • Drive the evolution of detection engineering and incident response capabilities by utilizing modern software practices with an emphasis on large scale automation.

  • Oversee security incident response operations, serving as an escalation point/Incident Commander during high-severity security events and driving post-incident reviews.

  • Establish or improve operational metrics to continuously evaluate and improve program maturity.

  • Partner closely with Engineering, and stakeholders across Legal and Compliance teams, to integrate detection telemetry and proactive response across the company.

  • Champion an engineering-centric security culture focused on automation, noise reduction, and continuous improvement to minimize operational toil for responders.

What You Will Bring:

  • 12+ years of experience in software development, security engineering, or security operations, with 5+ years in direct engineering or security management.

  • Proven track record of building, coaching, and scaling engineering teams across multiple time zones.

  • Deep technical domain expertise across detection engineering, incident response, and threat intelligence. Experience building or operating scalable data/event pipelines, modern telemetry stacks, or stream-processing architectures.

  • Demonstrated ability to lead complex, high-severity security incidents with composure, clarity, and cross-functional leadership.

  • Excellent communication and stakeholder management skills, with a proven ability to translate complex security risks into clear strategic priorities for engineering leadership.

  • Bachelor’s or Master's degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.

     

Ready to build what's next? Let’s get in motion.

Come As You Are

Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

Privacy Statement

Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available here.

Redirects to Confluent's application page.

Other roles

More at Confluent.

View all 23 roles