Manager, Threat Detection and Incident Response

Contentful Contentful · Enterprise · New York, NY · Security

Manager for Threat Detection and Incident Response role at Contentful, focusing on operational and strategic direction, team development, and capability maturity. The role involves hands-on detection and response activities, designing and operating capabilities, leading incident response efforts, and driving continuous improvement. It also includes accelerating AI adoption within security operations.

What you'd actually do

  1. Develop a team, providing coaching, mentorship, goal setting, and performance feedback.
  2. Mature effectiveness and efficiency by improving processes, tooling, and documentation.
  3. Collaborate with security leadership to execute business aligned, risk reduction roadmaps.
  4. Own execution and prioritization across projects and operations, using agile delivery practices.
  5. Shape work scope, sequencing, and success criteria in line with department and company needs.

Skills

Required

  • security operations
  • alert triage
  • incident investigation
  • incident response
  • team management
  • cloud-native security
  • AWS security services
  • Splunk expertise
  • host analysis (Mac, Windows, Linux)
  • threat modeling
  • detection engineering

Nice to have

  • AI adoption
  • DevOps principles
  • agile delivery practices
  • cross-platform investigations
  • hybrid environment investigations

What the JD emphasized

  • 6+ years experience in security operations, including alert triage and investigation
  • 4+ years conducting large scale incident response activities with 2+ years leading
  • 2+ years managing people and security operations teams.
  • Expert usage, data onboarding, and data administration within Splunk
  • Ability to design large-scale threat detection using diverse technologies and data sets