The Security & Detection Engineering Manageris responsible for owning and leading the detection engineering and security platform strategy across a multi-SIEM, multi-tenant MSSP environment.
This role governs detection architecture, ATT&CK coverage, platform interoperability, multi-tenant isolation, cost engineering, quality assurance and automation governance across a hybrid tooling environment.
1.Detection Strategy & Architecture - Define and maintain a 12–24 month Detection Engineering Roadmap.
- Own adversary-aligned detection strategy mapped to MITRE ATT&CK.
- Establish detection maturity targets per platform and service tier.
- Maintain a centralised detection content abstraction model (e.g., Sigma/internal DSL).
- Govern detection lifecycle: design → validation → deployment → tuning → retirement.
- Prevent detection sprawl and duplication across platforms.
2.MITRE ATT&CK Coverage Governance