# Senior Manager, Detection & Response (Security Engineering)
**Company:** [Confluent](https://scaleengineer.com/companies/confluent)
Senior Manager leading Confluent's Detection & Response organization within Infrastructure Security, responsible for defining strategic vision, technical roadmap, and operational execution for detecting, investigating, and responding to security threats across multi-cloud environments. Lead a distributed, high-performing engineering team across North America and India, building real-time security automation using Kafka, Kubernetes, and AI-assisted workflows with 12+ years of experience and proven team leadership capabilities.
**Role:** Manager
**Seniority:** Manager
**Locations:** Remote, United States
**Remote:** yes
**Salary:** 241700–319000 USD
[Apply](https://jobs.ashbyhq.com/confluent/46f3f467-8728-47b4-8fad-06e18ffbe552)
Canonical: https://scaleengineer.com/jobs/confluent/senior-manager-detection-response-security-engineering
---
## Responsibilities

- Strategic Vision & Roadmap Execution: Own the strategic vision and roadmap execution for Confluent's Detection & Response program across multi-cloud infrastructure environments (AWS, GCP, Azure). Define technical direction and ensure alignment with organizational security objectives and incident response maturity goals.
- Team Leadership & Development: Build, scale, and mentor a distributed, global team of high-performing security engineers across North America and India. Foster professional development, drive hiring initiatives, and create an engineering-centric security culture that emphasizes automation and continuous improvement.
- Detection Engineering & Incident Response Operations: Drive the evolution of detection engineering and incident response capabilities by leveraging modern software practices with emphasis on large-scale automation. Oversee security incident response operations, serve as escalation point and Incident Commander during high-severity security events, and lead comprehensive post-incident reviews.
- Operational Metrics & Program Maturity: Establish and improve operational metrics to continuously evaluate and enhance program maturity. Track detection coverage, mean time to detect (MTTD), mean time to respond (MTTR), and other KPIs. Implement data-driven approaches to minimize operational toil and improve responder efficiency.
- Cross-Functional Collaboration: Partner closely with Engineering, Legal, and Compliance teams to integrate detection telemetry and proactive response mechanisms across the company. Translate complex security risks into clear strategic priorities for engineering leadership and drive alignment across organizational stakeholders.
- Security Automation & Platform Development: Champion development of real-time, high-throughput security automation systems utilizing Confluent's Kafka platform as central transport. Leverage scalable Kubernetes pipelines, custom ETL jobs, and AI-assisted triage workflows to reduce alert fatigue and improve threat detection accuracy.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science, Cybersecurity, or Engineering","description":"Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related technical field, or equivalent hands-on experience. Foundation in computer science principles and formal training in security domains strongly preferred."}
- {"name":"Advanced Degree (Preferred)","description":"Master's degree in Computer Science, Cybersecurity, or related discipline is preferred and demonstrates commitment to continuous learning in rapidly evolving security domains. Advanced certifications in security engineering or incident response also valued."}

### technical

- {"name":"Detection Engineering & Threat Intelligence","description":"Deep technical expertise in detection engineering, incident response workflows, and threat intelligence practices. Proven ability to design and implement detection strategies, build alert hierarchies, and develop threat models across enterprise environments."}
- {"name":"Scalable Data Pipelines & Stream Processing","description":"Hands-on experience building or operating scalable data and event pipelines, modern telemetry stacks, or stream-processing architectures. Proficiency with Apache Kafka, event-driven architectures, and real-time data processing frameworks essential for modern security operations."}
- {"name":"Multi-Cloud Security Infrastructure","description":"Technical knowledge across AWS, GCP, and Azure cloud environments. Understanding of cloud-native security posture, identity management, network security, and cloud-specific threat vectors across heterogeneous infrastructure."}
- {"name":"Security Automation & Orchestration","description":"Experience designing and implementing security automation platforms, including SOAR (Security Orchestration, Automation and Response) concepts, custom ETL workflows, and AI-assisted triage systems. Familiarity with Infrastructure as Code and containerized environments (Kubernetes)."}
- {"name":"Incident Response & Crisis Management","description":"Demonstrated ability to lead complex, high-severity security incidents with composure, clarity, and cross-functional leadership. Experience with incident classification, response playbooks, post-incident review processes (blameless postmortems), and continuous improvement methodologies."}

### experience

- {"name":"Overall Software Engineering & Security Experience","description":"12+ years of experience in software development, security engineering, or security operations. Deep background in building resilient systems, understanding application security principles, and translating engineering practices into security contexts."}
- {"name":"Engineering & Security Management","description":"5+ years in direct engineering or security management roles with proven track record of building, coaching, and scaling engineering teams across multiple time zones and distributed locations. Experience mentoring technical engineers and fostering high-performance team cultures."}
- {"name":"Enterprise Security Operations","description":"Significant experience operating security programs at scale within enterprise organizations. Background in managing security operations centers (SOCs), detection platforms, or incident response capabilities serving large, complex infrastructure environments."}
- {"name":"Stakeholder & Executive Communication","description":"Proven ability to communicate with diverse stakeholders including engineering leadership, Legal, Compliance, and executive management. Experience translating complex security risks into actionable strategic priorities and influencing organizational decision-making."}

## Skills

### required

- {"name":"Engineering Leadership","description":"Proven ability to lead, mentor, and scale distributed engineering teams across geographies. Experience building high-performance cultures, conducting performance reviews, succession planning, and fostering technical excellence among team members."}
- {"name":"Detection Engineering","description":"Expert-level knowledge of building detection rules, alert tuning, YARA rules, SIGMA rules, or other detection methodologies. Understanding of attack patterns, adversary techniques (MITRE ATT&CK), and threat modeling frameworks."}
- {"name":"Incident Response & SOAR Operations","description":"Hands-on experience managing security incidents, developing response playbooks, and operating Security Orchestration, Automation and Response (SOAR) platforms. Competency with incident classification, severity assessment, and escalation procedures."}
- {"name":"Real-Time Data Processing","description":"Technical proficiency with Apache Kafka, stream-processing architectures, event-driven systems, and high-throughput data pipelines. Understanding of distributed systems concepts, horizontal scaling, and latency optimization in data-intensive environments."}
- {"name":"Cloud Security Architecture","description":"Deep understanding of security posture across multi-cloud environments (AWS, GCP, Azure). Knowledge of cloud-native security services, identity and access management, cloud logging, and threat detection within cloud infrastructure."}
- {"name":"Strategic Planning & Roadmap Development","description":"Demonstrated ability to define multi-year technical strategies, develop roadmaps, prioritize initiatives based on business impact, and drive execution across organizational boundaries. Experience with strategic frameworks like OKRs or similar planning methodologies."}
- {"name":"Cross-Functional Stakeholder Management","description":"Excellent communication skills with ability to translate complex security concepts for diverse audiences including engineers, executives, Legal, and Compliance teams. Proven track record of building consensus and influencing without direct authority."}

### preferred

- {"name":"Apache Kafka Expertise","description":"Working knowledge of Confluent's Apache Kafka platform and stream processing capabilities. Understanding of Kafka's role in modern data architectures and potential applications in security telemetry collection and event processing."}
- {"name":"Kubernetes & Container Security","description":"Experience securing containerized environments, Kubernetes orchestration, and Infrastructure as Code practices. Knowledge of container networking, pod security policies, and runtime security monitoring for cloud-native applications."}
- {"name":"AI/ML in Security Operations","description":"Familiarity with machine learning applications in security including anomaly detection, behavioral analytics, and AI-assisted alert triage. Understanding of how ML can reduce false positives and improve detection accuracy at scale."}
- {"name":"SIEM & Log Management","description":"Experience with Security Information and Event Management (SIEM) platforms, centralized logging, log aggregation tools, and parsing structured/unstructured security telemetry. Knowledge of ELK, Splunk, or similar platforms beneficial."}
- {"name":"Threat Intelligence Platforms","description":"Experience integrating external threat intelligence feeds, managing threat intelligence platforms (TIPs), and operationalizing threat data for detection rule development and incident investigation."}
- {"name":"Security Certifications","description":"Industry certifications such as CISSP, CISM, CEH (Certified Ethical Hacker), GCIA (GIAC Certified Incident Handler), or GSEC (GIAC Security Essentials) demonstrate formal security expertise and commitment to professional development."}

## Tech stack

### tools

- {"name":"SIEM Platforms (Splunk, ELK, IBM QRadar)","description":"Security Information and Event Management tools for centralized security log collection, correlation, alerting, and security event analysis across enterprise infrastructure."}
- {"name":"SOAR Platforms (Palo Alto Cortex XSOAR, Splunk SOAR)","description":"Security Orchestration, Automation and Response platforms for automating incident response workflows, playbook execution, and coordinating response actions across security tools."}
- {"name":"Cloud Platforms (AWS, GCP, Azure)","description":"Major cloud providers with native security services, monitoring tools, and identity management systems. Proficiency with cloud security services and threat detection capabilities across multi-cloud environments."}
- {"name":"Threat Intelligence Platforms","description":"Tools for aggregating, managing, and operationalizing threat intelligence data. Platforms like Anomali, Sixgill, or ThreatConnect for enriching detection rules and investigations."}
- {"name":"Incident Management Tools (Jira, PagerDuty, Opsgenie)","description":"Platforms for tracking security incidents, on-call management, alert routing, and incident lifecycle management. Essential for coordinating detection and response operations."}
- {"name":"Git & Version Control","description":"Source code management systems for version controlling detection rules, automation scripts, infrastructure as code, and collaborative security engineering practices."}

### others

- {"name":"MITRE ATT&CK Framework","description":"Adversary tactics, techniques, and procedures (TTPs) framework used for threat modeling, detection design, attack pattern analysis, and security research in detection engineering."}
- {"name":"Blameless Postmortem Processes","description":"Incident review methodology focused on continuous improvement, root cause analysis, and organizational learning without assigning blame. Critical for building mature incident response culture."}
- {"name":"OKR (Objectives & Key Results)","description":"Strategic planning framework for setting ambitious security goals, measuring progress, and aligning team efforts with organizational objectives in detection and response programs."}
- {"name":"Infrastructure as Code (Terraform, CloudFormation)","description":"Tools for managing cloud infrastructure programmatically, enabling reproducible security deployments, environment parity, and automated infrastructure provisioning."}

### databases

- {"name":"Elasticsearch","description":"Distributed search and analytics engine commonly used for centralized logging, security data storage, SIEM implementations, and real-time security event analysis."}
- {"name":"PostgreSQL","description":"Relational database for storing structured security data, incident metadata, detection rules, and threat intelligence information supporting detection operations."}
- {"name":"ClickHouse","description":"Columnar database optimized for OLAP (Online Analytical Processing) queries on large volumes of security event data, enabling efficient threat hunting and security analytics."}

### languages

- {"name":"Python","description":"Primary scripting language for security automation, detection rule development, incident response tooling, and custom ETL job creation. Essential for building efficient security engineering solutions at scale."}
- {"name":"Go","description":"Used for developing high-performance security tools, data processing applications, and service development. Valuable for building scalable, concurrent systems in real-time detection and response infrastructure."}
- {"name":"SQL","description":"Critical for querying security data lakes, SIEM platforms, and log repositories. Essential for threat hunting, incident investigation, and security telemetry analysis across large datasets."}
- {"name":"Bash/Shell Scripting","description":"Fundamental for security operations automation, deployment scripts, infrastructure orchestration, and incident response tooling in Unix/Linux environments."}

### frameworks

- {"name":"Apache Kafka","description":"Confluent's core data-streaming platform used as central transport for security telemetry collection, processing, and event distribution across detection and response infrastructure."}
- {"name":"Kubernetes","description":"Container orchestration platform for deploying, scaling, and managing detection pipelines, incident response tooling, and security services in containerized environments."}
- {"name":"ETL Frameworks","description":"Custom ETL (Extract, Transform, Load) job development for security data pipeline creation, telemetry normalization, and real-time threat data processing across multiple sources."}

## Benefits

### benefits

- {"name":"Competitive Health Insurance","description":"Comprehensive medical, dental, and vision coverage with options for employees and their families. Confluent provides competitive rates and coverage options designed for tech industry professionals."}
- {"name":"401(k) Retirement Plan","description":"Company-sponsored retirement savings plan with employer matching contributions to support long-term financial planning and retirement security."}
- {"name":"Professional Development & Learning","description":"Budget for conferences, training programs, security certifications (CISSP, CISM, CEH, GCIA), and continuous learning opportunities. Support for staying current with rapidly evolving security landscapes."}
- {"name":"Remote Work Flexibility","description":"Distributed team environment with flexibility in work arrangements. Location independence supporting work-life balance across North America, India, and other regions."}
- {"name":"Equity Participation","description":"Stock options or RSU (Restricted Stock Unit) grants providing ownership stake in Confluent. Direct participation in company success as part of compensation package."}
- {"name":"Time Off & Paid Leave","description":"Generous vacation, sick leave, and personal days. Unlimited or flexible PTO policies typical in high-growth tech companies with emphasis on employee wellbeing."}
- {"name":"Leadership Development","description":"Executive coaching, management training, and leadership development programs designed to support growth trajectory for experienced security engineering leaders."}
- {"name":"Inclusive & Diverse Culture","description":"Commitment to belonging as baseline value, supporting diverse perspectives, backgrounds, and identities. Equal opportunity workplace fostering psychological safety and inclusion."}

## Compensation

- **max:** 0
- **min:** 0
- **currency:** 
- **stockOptions:** false

## Interview process

### steps

## Full description
We’re not just building better tech. We’re rewriting how data moves and what the world can do with it. With Confluent, data doesn’t sit still. Our platform puts information in motion, streaming in near real-time so companies can react faster, build smarter, and deliver experiences as dynamic as the world around them.

It takes a certain kind of person to join this team. Those who ask hard questions, give honest feedback, and show up for each other. No egos, no solo acts. Just smart, curious humans pushing toward something bigger, together.

One Confluent. One Team. One Data Streaming Platform.

##   
**About the Role:**

We are seeking an experienced engineering leader to head our Detection & Response organization within Infrastructure Security. In this role, you will define the strategic vision, technical roadmap, and operational execution for how Confluent detects, investigates, and responds to security threats across our multi-cloud environments (AWS, GCP, Azure).

You will lead and grow a distributed team of high-performing engineers across North America and India. Our team applies modern engineering principles to security—leveraging scalable Kubernetes pipelines, custom ETL jobs, AI-assisted triage workflows, and Confluent’s own data-streaming platform (Kafka) as our central transport. If you are passionate about building real-time, high-throughput security automation and fostering an engineering-first incident response culture, this role is for you.

## **What You Will Do:**

* Own the strategic vision and roadmap execution for Confluent's Detection & Response program across our multi-cloud infrastructure.
* Build, scale, and mentor a distributed, global team across North America and India.
* Drive the evolution of detection engineering and incident response capabilities by utilizing modern software practices with an emphasis on large scale automation.
* Oversee security incident response operations, serving as an escalation point/Incident Commander during high-severity security events and driving post-incident reviews.
* Establish or improve operational metrics to continuously evaluate and improve program maturity.
* Partner closely with Engineering, and stakeholders across Legal and Compliance teams, to integrate detection telemetry and proactive response across the company.
* Champion an engineering-centric security culture focused on automation, noise reduction, and continuous improvement to minimize operational toil for responders.

## **What You Will Bring:**

* 12+ years of experience in software development, security engineering, or security operations, with 5+ years in direct engineering or security management.
* Proven track record of building, coaching, and scaling engineering teams across multiple time zones.
* Deep technical domain expertise across detection engineering, incident response, and threat intelligence. Experience building or operating scalable data/event pipelines, modern telemetry stacks, or stream-processing architectures.
* Demonstrated ability to lead complex, high-severity security incidents with composure, clarity, and cross-functional leadership.
* Excellent communication and stakeholder management skills, with a proven ability to translate complex security risks into clear strategic priorities for engineering leadership.
* Bachelor’s or Master's degree in Computer Science, Cybersecurity, Engineering, or equivalent experience.

## 

## **Ready to build what's next? Let’s get in motion.**

### 

# **Come As You Are**

Belonging isn’t a perk here. It’s the baseline. We work across time zones and backgrounds, knowing the best ideas come from different perspectives. And we make space for everyone to lead, grow, and challenge what’s possible.

We’re proud to be an equal opportunity workplace. Employment decisions are based on job-related criteria, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by law.

# **Privacy Statement**

Confluent is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organization. By proceeding with this application, you understand that Confluent will share your personal information with other IBM affiliates involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross-border data transfer, are available [here](http://ibm.com/careers/us-en/privacy-policy/).
