{bc}

Security & Detection Engineering Manager

Blackford TechnologiesAbu Dhabi, UAE2 months agoSenior
Senior

Skills

Project ManagementTeam LeadershipTechnical Expertise

About This Role

Overview

The Security & Detection Engineering Manager is responsible for owning and leading the detection engineering and security platform strategy across a multi-SIEM, multi-tenant MSSP environment.

This role governs detection architecture, ATT&CK coverage, platform interoperability, multi-tenant isolation, cost engineering, quality assurance and automation governance across a hybrid tooling environment.

1. Detection Strategy & Architecture

  • Define and maintain a 12 24 month Detection Engineering Roadmap.
  • Own adversary-aligned detection strategy mapped to MITRE ATT&CK.
  • Establish detection maturity targets per platform and service tier.
  • Maintain a centralised detection content abstraction model (e.g., Sigma/internal DSL).
  • Govern detection lifecycle: design validation deployment tuning retirement.
  • Prevent detection sprawl and duplication across platforms.

2. MITRE ATT&CK Coverage Governance

  • Maintain formal ATT&CK coverage matrix.
  • Track and report coverage percentage by tactic and technique.
  • Conduct quarterly coverage gap analysis.
  • Validate detection coverage through simulation and adversary emulation exercises.
  • Produce ATT&CK coverage reporting for executive leadership and audit functions.

3. Multi-Tenant Detection Governance

  • Define detection inheritance and baseline models across tenants.
  • Govern tenant-level tuning while preserving engineering consistency.
  • Enforce strict cross-tenant rule isolation and data scoping controls.
  • Maintain metadata-only forwarding controls where required for sovereignty models.
  • Prevent cross-tenant configuration contamination.
  • Maintain version control and tenant-level detection lineage.

4. Platform Interoperability & Schema Governance

  • Own cross-platform detection portability strategy.
  • Govern schema alignment across a multi-SIEM environment
  • Define translation and normalisation pipelines.
  • Ensure detection parity across supported platforms.
  • Govern ingestion mapping and telemetry integrity.

5. Cost Engineering & Optimisation

  • Own ingestion efficiency model and cost per GB governance.
  • Monitor cost per alert generated.
  • Optimise:
  • Retention tiers (hot/warm/cold)
  • Query performance
  • Rule execution frequency
  • Define and track detection efficiency (signal-to-noise ratio).
  • Contribute to platform licensing and cost optimisation decisions.

6. Detection Quality Assurance Framework

  • Establish formal Detection QA process including:
  • Peer review prior to deployment
  • Pre-production validation environment
  • False positive regression testing
  • Simulation-based testing
  • Implement detection health scoring system.
  • Track detection decay and stale logic.
  • Maintain detection change traceability.

7. Continuous Service Improvement

  • Establish structured SOC-to-Engineering feedback loop.
  • Conduct regular analyst review sessions.
  • Track false positive patterns and alert fatigue metrics.
  • Maintain closed-loop improvement tracking.
  • Continuously improve detection fidelity and SOC effectiveness.
  • Conduct post-incident detection and control gap analysis.

8. Automation & Response Engineering Governance

  • Govern SOAR and response automation across platforms.
  • Define tiered automation model (manual / assisted / autonomous).
  • Establish human-in-the-loop controls for high-risk actions.
  • Enforce automation regression testing and version control.
  • Monitor automation success and failure rates.

9. Preventative Control Operationalisation & Validation

  • Implement Security Architect approved hardening baselines (CIS-aligned).
  • Operationalise secure configuration standards across:
  • Endpoints
  • Identity platforms
  • Cloud environments
  • Network security controls
  • Monitor configuration drift and control degradation.
  • Integrate preventative control telemetry into SIEM and detection pipelines.
  • Validate control effectiveness using detection and incident data.
  • Provide structured feedback to the Security Architect on control performance gaps.
  • Support exposure reduction initiatives through engineering execution.

10. Compliance & Audit Evidence Ownership

  • Maintain full audit trail for detection changes.
  • Provide evidence for ISO 27001, NIST CSF and regional regulatory audits.
  • Maintain detection version history.
  • Ensure automated response actions are logged and traceable.
  • Maintain control compliance dashboards and operational metrics.
  • Provide ATT&CK coverage documentation to auditors.

11. Engineering Leadership & Capability Development

  • Define detection engineering competency framework.
  • Mentor and develop Detection Engineers and SIEM Engineers.
  • Establish certification roadmap (Elastic, Microsoft, Google).
  • Implement technical performance scorecards.
  • Develop succession planning and redundancy controls.
  • Maintain backlog governance and engineering delivery cadence.

Platform Expertise (Required)

  • Elastic Security (EQL, index lifecycle, ECS governance)
  • Microsoft Defender XDR & Sentinel (KQL, ASIM)

Platform Expertise (Desired)

  • Google SecOps (UDM schema, detection engineering)
  • BindPlane (log routing and telemetry aggregation architecture)

Detection Engineering

  • Behaviour-based detection design
  • Correlation engineering
  • Sigma rule governance
  • Detection-as-code practices
  • ATT&CK mapping and coverage measurement

Your resume, rewritten for this exact role.

Sign up free — Base Career tailors your CV to this job description in 60 seconds.

01 / 05

Resume Tailored to This Job

Resume Tailored to This Job

Your keywords, structure, and story — rewritten to match this exact role and pass ATS filters.

Get My Free Resume

Free · No card · 60 seconds

02 / 05

Cover Letter for This Role, Done

Cover Letter for This Role, Done

Job-specific cover letters written in Gulf professional tone — ready in seconds, not hours.

Get My Cover Letter

Free · No card · 60 seconds

03 / 05

See How Well You Fit This Role

See How Well You Fit This Role

AI match score with clear reasons — know your fit before investing time in the application.

Check My Fit Score

Free · No card · 60 seconds

04 / 05

Apply in One Click

Apply in One Click

Autofill any application form on Workday, LinkedIn, Bayt, Greenhouse — with your tailored content.

Start Applying Faster

Free · No card · 60 seconds

05 / 05

Track It. Follow Up at the Right Time.

Track It. Follow Up at the Right Time.

Visual pipeline for every application with AI-timed follow-up reminders so nothing slips.

Track My Applications

Free · No card · 60 seconds

Similar Jobs

Business Development Manager - Cybersecurity & AI

iConnect IT Business Solutions DMCC · Dubai

Mid-Seniorfulltime

We are looking for a Business Development Manager to drive growth and expand our client base across the UAE. This role is suited for a proactive, results-driven professional with strong experience in cybersecurity sales

Skills

Market ResearchSales StrategyLead Generation

AI Security & Governance Lead

Faze 3 Consulting · Abu Dhabi

Senior

Translate AI governance policies into technical controls, implement security baselines, and ensure compliance with data protection and audit controls.

Skills

AI SecurityAI GovernanceAI Compliance Lead

Cybersecurity & IT Lead

FundingPips · Dubai

Mid-Seniorfulltime

Reports To: Head of Platform Engineering & Security Manages: IT Administrator (1 direct report) Experience: 5–8 years in cybersecurity and/or IT management Overview FundingPips is a Dubai-based fintech building infrastru

Skills

cybersecurityinformation securitynetwork security

Security & Protocol Manager-Protective Services Management

Sheikh Shakhbout Medical City - SSMC · Abu Dhabi

Mid-Seniorfulltime

JOB DESCRIPTION To provide operational leadership of all security functions within SSMC, including the supervision of Security Control and Security Operations, oversight of both in-house and contracted security personnel

Skills

IT StrategyTeam LeadershipBudget Management

Senior Accountant – Cybersecurity & IT SaaS | US GAAP (Remote)

MAVI · Dubai

Mid-Seniorfulltime

US Accounting Ownership. Cybersecurity & Tech Depth. Long-Term Global Partnerships. MAVI partners with high-growth US businesses, embedding experienced accounting professionals directly into their finance operations. In

Skills

Financial ReportingIFRSGAAP

Senior Data Security & Compliance Specialist

Exquitech Group · Dubai

Mid-Seniorfulltime

Location: Lebanon covering MEA Region Employment Type: Full-Time Job Summary: We are seeking a skilled Data Security & Compliance Specialist to lead the implementation of data security, classification, retention, and gov

Skills

ExcelRisk Management

Coordinator, Information Security & Governance

The National Insurance Company – Daman · Abu Dhabi

Entryfulltime

Mandate of Information Security & Governance Division Perform administrative and coordination activities to support information security and governance operations. Maintain documentation, records, and tracking logs rel

Skills

Scala

AI Security & Governance Lead

Faze 3 Consulting · Abu Dhabi

AED 20,000/monthSeniorfulltime

AI Security & Governance Lead Be the technical authority that makes enterprise AI safe, auditable, and trusted. A leading Abu Dhabi-based holding group is building a first-of-its-kind AI Governance function, and we're hi

Skills

AzureCybersecurity

AI Security & Governance Lead

Faze 3 Consulting · Abu Dhabi

Mid-Seniorfulltime

AI Security & Governance Lead — Abu Dhabi, UAE Be the technical authority that makes enterprise AI safe, auditable, and trusted. A leading Abu Dhabi-based holding group is building a first-of-its-kind AI Governance funct

Skills

AzureCybersecurity

2.2K+

Cover Letters & Follow-ups

1.8K+

Resumes Tailored

190.5K+

Jobs Tracked

Trusted by professionals at

PwC//
Emaar//
KPMG//
Noon//
Amazon AWS//
Talabat//
Deloitte//
Emirates//
Careem//
Aramex//
McKinsey//
Property Finder//
Majid Al Futtaim//
Chalhoub Group//
PwC//
Emaar//
KPMG//
Noon//
Amazon AWS//
Talabat//
Deloitte//
Emirates//
Careem//
Aramex//
McKinsey//
Property Finder//
Majid Al Futtaim//
Chalhoub Group//
AI Job Platform

Stop applying blindly. Start getting hired.

Base Career automates the hardest parts of job searching — apply smarter, not harder.

AI Resume in 60s

Your resume rewritten for this exact role using the job description as the brief.

ATS-Optimized

Get past automated screening filters with the right keywords matched to each job.

Application Tracker

Track every job, follow-up, and interview in one visual kanban board.

Free plan · No credit card required