yoinka

Manager, Threat Detection Engineer

Carlyle Group

Washington, DCMid
Sign in to applyVerified 3h ago
Location
Washington, DC
Work model
On-Site
Level
Mid
Posted
1d ago

About this role

Position

Summary The Threat Detection Engineer is a hands-on technical leader who strengthens how Carlyle identifies, understands and detects cyber threats. Reporting to the AVP, Threat Detection and Intelligence Lead, the Threat Detection Engineer leads assigned detection engineering and threat intelligence processes, turns intelligence into production detections and works with security partners to improve operational outcomes. This role oversees detection content from requirements and design through testing, deployment, tuning and retirement. It also develops intelligence that supports security operations and risk decisions and partners on threat hunting, external-risk response, digital-risk support for executive protection, automation, SOC interaction and platform reliability. The Threat Detection Engineer chooses among AI-assisted methods, deterministic automation and process changes based on the problem, risk and expected value. This is a hands-on technical leadership role that prioritizes assigned services, reviews technical work, coaches contributors and works across teams to carry out Carlyle’s Threat Detection and Intelligence strategy. In-Office Requirement: 4 days per week Primary Responsibilities Detection Engineering and Coverage - 30% Own the detection content lifecycle and use analyst feedback, detection coverage, alert quality, data quality, delivery time and cost to decide what should be tuned, improved or retired. Develop high-fidelity detections across endpoint, identity, email, network, cloud and business-critical application telemetry, identifying visibility and data gaps and ensuring alerts contain the context analysts need to investigate and act. Translate adversary behaviors, threat intelligence, incident learnings and control gaps into testable detection hypotheses and production-ready analytics. Implement approved quality gates for detection content, including data validation, expected-behavior testing, false-positive tolerance, investigation guidance and rollback plans. Use detection-as-code for internally managed content and supported tuning, compensating analytics or provider escalation for vendor-managed content. Coordinate and support targeted threat hunts with incident response and other security partners to validate hypotheses, uncover gaps and convert repeatable findings into durable detections or response logic. Review technical work, establish reusable standards and coach contributors on detection design, testing and investigative usability. Threat Intelligence and External Risk - 30% Manage intelligence requirements based on Carlyle's threat profile, critical assets, executives and business priorities, including portfolio-related risks relevant to Carlyle. Collect, assess and synthesize strategic, operational and tactical intelligence concerning relevant threat actors, campaigns, vulnerabilities, techniques and emerging risks. Produce timely assessments and briefings tailored to security operations, incident response, technology leaders, executives and other stakeholders. Turn intelligence into prioritized detection, hunting, hardening and response requirements. Measure whether the intelligence was timely, useful and acted on, including how quickly it led to a detection or decision. Govern indicator and intelligence-data lifecycles, including sourcing, validation, normalization, enrichment, confidence, aging, pruning and benign-pattern review; maintain trusted information-sharing relationships and evaluate source relevance and reliability. Coordinate monitoring for dark-web activity, lookalike domains, social-media threats, impersonation, exposed information and other digital risks. Provide cyber and digital-risk support to executive protection. Work with Legal, Communications, service providers and relevant business stakeholders on assessments, escalations and takedowns. Automation, Quality and Platform Enablement - 30% Use AI-assisted and analytical tools to accelerate detection-rule

Manager, Threat Detection Engineer at Carlyle Group, Washington, DC | Yoinka