
Manager, Threat Research - TTP Detection
- Canada
- Permanent
- Full-time
- Lead and manage a global team of approximately 8 behavior-based detection engineers
- Own the roadmap for suspicious behavior classification, focused on Windows endpoints with planned expansion into macOS
- Prioritize TTP (Tactics, Techniques, and Procedures) detection initiatives using customer telemetry, sandbox data, and internal threat feeds
- Guide the team in mapping Indicators of Compromise (IOCs) to the MITRE ATT&CK framework and improving coverage across attack surfaces
- Engage in detailed technical discussions and troubleshoot detection logic and rule behavior with the team
- Contribute technical depth to help review and refine behavior detection logic and guide engineers through low-level detection challenges
- Plan, assign, and track team workstreams to meet detection KPIs and ensure continuous improvement
- Mentor and support engineers in malware analysis, rule tuning, and threat detection methodologies
- Collaborate cross-functionally with threat intelligence, product, and engineering stakeholders
- Must have at least 5 years of experience specifically in detection engineering or behavior-based threat research with a focus on Windows threats
- Must have at least 2 years of team leadership or people management experience in a cybersecurity or technical domain
- Must have strong expertise in Windows operating systems, internals, and forensic tools
- Experience mapping behaviors to the MITRE ATT&CK framework
- Knowledge of malware kill chains and hands-on-keyboard attack techniques
- Experience with programming or scripting languages such as Python or Lua
- Bachelor's degree in Computer Science, Computer Security, or related field
- Experience with big data platforms such as ElasticSearch, Kibana, or Redshift
- Familiarity with threat hunting, behavior-based classification, and telemetry analysis
- Excellent written and verbal communication skills with a focus on technical coaching