Security & Detection Engineering Manager
Skills
About This Role
Overview
The Security & Detection Engineering Manager is responsible for owning and leading the detection engineering and security platform strategy across a multi-SIEM, multi-tenant MSSP environment.
This role governs detection architecture, ATT&CK coverage, platform interoperability, multi-tenant isolation, cost engineering, quality assurance and automation governance across a hybrid tooling environment.
1. Detection Strategy & Architecture
- Define and maintain a 12 24 month Detection Engineering Roadmap.
- Own adversary-aligned detection strategy mapped to MITRE ATT&CK.
- Establish detection maturity targets per platform and service tier.
- Maintain a centralised detection content abstraction model (e.g., Sigma/internal DSL).
- Govern detection lifecycle: design validation deployment tuning retirement.
- Prevent detection sprawl and duplication across platforms.
2. MITRE ATT&CK Coverage Governance
- Maintain formal ATT&CK coverage matrix.
- Track and report coverage percentage by tactic and technique.
- Conduct quarterly coverage gap analysis.
- Validate detection coverage through simulation and adversary emulation exercises.
- Produce ATT&CK coverage reporting for executive leadership and audit functions.
3. Multi-Tenant Detection Governance
- Define detection inheritance and baseline models across tenants.
- Govern tenant-level tuning while preserving engineering consistency.
- Enforce strict cross-tenant rule isolation and data scoping controls.
- Maintain metadata-only forwarding controls where required for sovereignty models.
- Prevent cross-tenant configuration contamination.
- Maintain version control and tenant-level detection lineage.
4. Platform Interoperability & Schema Governance
- Own cross-platform detection portability strategy.
- Govern schema alignment across a multi-SIEM environment
- Define translation and normalisation pipelines.
- Ensure detection parity across supported platforms.
- Govern ingestion mapping and telemetry integrity.
5. Cost Engineering & Optimisation
- Own ingestion efficiency model and cost per GB governance.
- Monitor cost per alert generated.
- Optimise:
- Retention tiers (hot/warm/cold)
- Query performance
- Rule execution frequency
- Define and track detection efficiency (signal-to-noise ratio).
- Contribute to platform licensing and cost optimisation decisions.
6. Detection Quality Assurance Framework
- Establish formal Detection QA process including:
- Peer review prior to deployment
- Pre-production validation environment
- False positive regression testing
- Simulation-based testing
- Implement detection health scoring system.
- Track detection decay and stale logic.
- Maintain detection change traceability.
7. Continuous Service Improvement
- Establish structured SOC-to-Engineering feedback loop.
- Conduct regular analyst review sessions.
- Track false positive patterns and alert fatigue metrics.
- Maintain closed-loop improvement tracking.
- Continuously improve detection fidelity and SOC effectiveness.
- Conduct post-incident detection and control gap analysis.
8. Automation & Response Engineering Governance
- Govern SOAR and response automation across platforms.
- Define tiered automation model (manual / assisted / autonomous).
- Establish human-in-the-loop controls for high-risk actions.
- Enforce automation regression testing and version control.
- Monitor automation success and failure rates.
9. Preventative Control Operationalisation & Validation
- Implement Security Architect approved hardening baselines (CIS-aligned).
- Operationalise secure configuration standards across:
- Endpoints
- Identity platforms
- Cloud environments
- Network security controls
- Monitor configuration drift and control degradation.
- Integrate preventative control telemetry into SIEM and detection pipelines.
- Validate control effectiveness using detection and incident data.
- Provide structured feedback to the Security Architect on control performance gaps.
- Support exposure reduction initiatives through engineering execution.
10. Compliance & Audit Evidence Ownership
- Maintain full audit trail for detection changes.
- Provide evidence for ISO 27001, NIST CSF and regional regulatory audits.
- Maintain detection version history.
- Ensure automated response actions are logged and traceable.
- Maintain control compliance dashboards and operational metrics.
- Provide ATT&CK coverage documentation to auditors.
11. Engineering Leadership & Capability Development
- Define detection engineering competency framework.
- Mentor and develop Detection Engineers and SIEM Engineers.
- Establish certification roadmap (Elastic, Microsoft, Google).
- Implement technical performance scorecards.
- Develop succession planning and redundancy controls.
- Maintain backlog governance and engineering delivery cadence.
Platform Expertise (Required)
- Elastic Security (EQL, index lifecycle, ECS governance)
- Microsoft Defender XDR & Sentinel (KQL, ASIM)
Platform Expertise (Desired)
- Google SecOps (UDM schema, detection engineering)
- BindPlane (log routing and telemetry aggregation architecture)
Detection Engineering
- Behaviour-based detection design
- Correlation engineering
- Sigma rule governance
- Detection-as-code practices
- ATT&CK mapping and coverage measurement
Your resume, rewritten
for this exact role.
Sign up free — Base Career tailors your CV to this job description in 60 seconds.
01 / 05
Resume Tailored to This Job

Your keywords, structure, and story — rewritten to match this exact role and pass ATS filters.
Free · No card · 60 seconds
02 / 05
Cover Letter for This Role, Done

Job-specific cover letters written in Gulf professional tone — ready in seconds, not hours.
Free · No card · 60 seconds
03 / 05
See How Well You Fit This Role

AI match score with clear reasons — know your fit before investing time in the application.
Free · No card · 60 seconds
04 / 05
Apply in One Click

Autofill any application form on Workday, LinkedIn, Bayt, Greenhouse — with your tailored content.
Free · No card · 60 seconds
05 / 05
Track It. Follow Up at the Right Time.

Visual pipeline for every application with AI-timed follow-up reminders so nothing slips.
Free · No card · 60 seconds
Similar Jobs
Business Development Manager - Cybersecurity & AI
iConnect IT Business Solutions DMCC · Dubai
We are looking for a Business Development Manager to drive growth and expand our client base across the UAE. This role is suited for a proactive, results-driven professional with strong experience in cybersecurity sales
Skills
5 days ago
Apply Now↗Apply Now ↗AI Security & Governance Lead
Faze 3 Consulting · Abu Dhabi
Translate AI governance policies into technical controls, implement security baselines, and ensure compliance with data protection and audit controls.
Skills
1 weeks ago
Apply Now↗Apply Now ↗Cybersecurity & IT Lead
FundingPips · Dubai
Reports To: Head of Platform Engineering & Security Manages: IT Administrator (1 direct report) Experience: 5–8 years in cybersecurity and/or IT management Overview FundingPips is a Dubai-based fintech building infrastru
Skills
1 weeks ago
Apply Now↗Apply Now ↗Security & Protocol Manager-Protective Services Management
Sheikh Shakhbout Medical City - SSMC · Abu Dhabi
JOB DESCRIPTION To provide operational leadership of all security functions within SSMC, including the supervision of Security Control and Security Operations, oversight of both in-house and contracted security personnel
Skills
1 weeks ago
Apply Now↗Apply Now ↗Senior Accountant – Cybersecurity & IT SaaS | US GAAP (Remote)
MAVI · Dubai
US Accounting Ownership. Cybersecurity & Tech Depth. Long-Term Global Partnerships. MAVI partners with high-growth US businesses, embedding experienced accounting professionals directly into their finance operations. In
Skills
2 weeks ago
Apply Now↗Apply Now ↗Senior Data Security & Compliance Specialist
Exquitech Group · Dubai
Location: Lebanon covering MEA Region Employment Type: Full-Time Job Summary: We are seeking a skilled Data Security & Compliance Specialist to lead the implementation of data security, classification, retention, and gov
Skills
2 weeks ago
Apply Now↗Apply Now ↗Coordinator, Information Security & Governance
The National Insurance Company – Daman · Abu Dhabi
Mandate of Information Security & Governance Division Perform administrative and coordination activities to support information security and governance operations. Maintain documentation, records, and tracking logs rel
Skills
2 weeks ago
Apply Now↗Apply Now ↗AI Security & Governance Lead
Faze 3 Consulting · Abu Dhabi
AI Security & Governance Lead Be the technical authority that makes enterprise AI safe, auditable, and trusted. A leading Abu Dhabi-based holding group is building a first-of-its-kind AI Governance function, and we're hi
Skills
2 weeks ago
Apply Now↗Apply Now ↗AI Security & Governance Lead
Faze 3 Consulting · Abu Dhabi
AI Security & Governance Lead — Abu Dhabi, UAE Be the technical authority that makes enterprise AI safe, auditable, and trusted. A leading Abu Dhabi-based holding group is building a first-of-its-kind AI Governance funct
Skills
2 weeks ago
Apply Now↗Apply Now ↗2.2K+
Cover Letters & Follow-ups
1.8K+
Resumes Tailored
190.5K+
Jobs Tracked
Trusted by professionals at
Stop applying blindly.
Start getting hired.
Base Career automates the hardest parts of job searching — apply smarter, not harder.
AI Resume in 60s
Your resume rewritten for this exact role using the job description as the brief.
ATS-Optimized
Get past automated screening filters with the right keywords matched to each job.
Application Tracker
Track every job, follow-up, and interview in one visual kanban board.
Free plan · No credit card required