Detection and Response Manager
Con Edison
The Detection and Response Manager will build, lead, and continuously mature the Detection and Response Team, serving as Tier 3 support for Con Edisons IT and OT Cybersecurity Operations Center (CSOC). This role is responsible for advanced threat detection, incident escalation, and enterprise wide incident response. Reporting to the Director of Cybersecurity Operations, the manager will establish a new team that functions as the primary escalation path for the CSOC, advances detection engineering maturity, and conducts proactive threat hunting across the enterprise. The role also influences front line CSOC effectiveness by delivering validated detections, well defined playbooks, and targeted training to ensure consistent and confident execution. This position partners closely with Security Engineering, the CSOC, Offensive Security, Corporate Security, and the ETS team to strengthen and evolve how threats are identified and responded to across the organization. As Con Edison continues to invest in technologies such as cloud platforms, containers, AI, and OT environments, the scope of this role includes maturing detection and response capabilities across both existing and emerging technologies. This includes enhancing incident response processes and expanding SIEM and SOAR use cases to support business growth and resilience. The Detection and Response Manager ensures the development of repeatable procedures, validation of detections through realistic scenarios, effective training of stakeholder teams, and seamless transitions of new capabilities to the CSOC. The ultimate objective is to strengthen Tier 1 and Tier 2 operations, enabling faster response times, higher confidence, and improved security outcomes. Required Education/Experience * Bachelor's Degree and 8 years of relevant work experience or * Master's Degree and 6 years of relevant work experience. Preferred Education/Experience * Master's Degree Majors preferred in IT, computer science, business administration, engineering or decision sciences including mathematics, analytics, quantitative methods. and 6 years of relevant work experience. Relevant Work Experience * Leadership experience in cybersecurity operations, detection engineering, or incident response, including building and maturing teams, required. * Hands-on experience designing, tuning, and validating detections across diverse data sources, with a track record of reducing false positives, required. * Deep hands-on experience with SIEM and SOAR platforms, including building correlation logic, case workflows, and automation playbooks, required. * Demonstrated experience leading hypothesis-driven threat hunts and converting findings into durable detections, required. * Experience operating in or alongside cloud security (AWS, GCP, Azure, or OCI) required. * Exposure to OT environments and a willingness to develop OT depth, including OT risk, telemetry, and operational constraints, required. * Experience developing and operationalizing playbooks, procedures, and training material, required. * Experience validating detections through tabletop exercises, purple team testing, and controlled scenarios, required. * Track record of improving operational metrics (MTTD, MTTR, false positive reduction), required. * Direct experience in OT or critical infrastructure environments preferred. * Experience partnering with offensive security or threat intelligence teams to translate findings into detections and response improvements preferred. * Experience evaluating and deploying AI-driven security tooling in a production environment preferred. * Strong working knowledge of MITRE ATT&CK, used to map detections, hunts, and coverage gaps, preferred. * Strong stakeholder management across security, engineering, and business teams, preferred. Skills and Abilities * Effective leadership skills * Demonstrated problem solving skills * Demonstrated written communication skills Licenses and Certifications * Driver's License Required * Project Management Professional (PMP) Training and/or certification in Project Management is a plus. Preferred * Other: Cybersecurity certifications such as CISSP, CISM, GCFA, GCIA, or GCFE Preferred Physical Demands * Sit or stand to answer a phone for the duration of the workday * Sit or stand to use a keyboard, mouse, and computer for the duration of the workday * Ability to read small print and symbols Additional Physical Demands * The selected candidate will be assigned a System Emergency Assignment (i.e., an emergency response role) and will be expected to work non-business hours during emergencies, which may include nights, weekends, and holidays. * Must be able and willing to travel within Company service territory, as needed. Core Responsibilities * Build and lead the Detection and Response Team. * Operate as the escalation path for high complexity alerts, suspected incidents and root cause investigations, supporting both IT and OT CSOC workflows. * Improve the end-to-end response lifecycle, including alert triage, investigation, containment, remediation coordination, lessons learned and documentation. * Partner with Security Engineering to develop and mature detection use cases, including tuning detections for low false positives and high signal quality. * Lead continuous threat hunting by regularly scanning telemetry and investigation outputs to find stealthy attacker behavior and emerging patterns across IT and OT. * Lead campaign-based threat hunting by defining hypotheses, objectives and success criteria with stakeholders, then running time bound hunts aligned to risk, new threats and specific business systems. * Identify opportunities across the business where cybersecurity requirements were not implemented, were not consistently enforced, or were misaligned to risk and work with stakeholders to close those gaps. * Collaborate with Offensive Security and threat intelligence stakeholders to incorporate new findings into detections, detections engineering and response improvements. * Own the end to end lifecycle and continuous improvement of SIEM and SOAR use cases, spanning alert enrichment, case management, automated response actions, and orchestration. * Develop and improve incident response processes, including playbook development, scenario testing, tabletop exercises and after-action reviews. * Guide capability transitions to the CSOC by ensuring detections and response procedures are documented, trained, tested and ready for steady state operations. * Establish measurable performance targets and an operating rhythm, including metrics such as mean time to detect, mean time to respond, investigation throughput, false positive rates and impact from tuning or automation. * Evaluate, pilot, and operationalize AI-driven detection and response tools and technology (e.g., anomaly detection, alert summarization/enrichment, and automated triage) to reduce false positives and accelerate MTTD/MTTR.
- ...Leadership experience in cybersecurity operations, detection engineering, or incident response, including building and maturing teams, required.... ...and coverage gaps, preferred. Strong stakeholder management across security, engineering, and business teams, preferred...SuggestedWork experience placementNight shift
$320k - $405k
...together to build beneficial AI systems. About the Role The Detection & Response (D&R) team plays a critical role in protecting our systems,... ...threats. We’re looking for an experienced Technical Program Manager to own and evolve incident management within D&R. This is a...SuggestedWork at officeImmediate startVisa sponsorshipFlexible hoursShift work$240k - $300k
...Director of Engineering, Endpoint Detection and Response (EDR) Remote US Reports to: Vice President, Engineering Location: Remote US Compensation... ...—not just the 1%—with enterprise-grade, fully owned, and managed cybersecurity products at the price of an affordable SaaS...SuggestedFull timeRemote workWorldwideHome office- ...Sysdig is seeking a Product Manager in the United States to lead execution for runtime threat detection across various environments. The ideal candidate will have... ...management focused on building security products. Responsibilities include managing roadmaps and collaborating...Suggested
$150k - $180k
...investment firm that offers alternative asset management as well as capital markets and insurance... ...excellence while remaining agile in response to the evolving needs of our businesses.... ...cyber incidents within the Threat Detection & Response (TD&R) function in our New York...SuggestedWork at officeLocal area$145k - $195k
Service Delivery Manager, Managed Detection and Response, United States S-RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges....Immediate startFlexible hoursShift work$168k - $195k
...services and ensures the necessary IT risk management and security measures are in place and... ...for cyber defense and incident response. This is a high-impact leadership role that... ...world attack scenarios. Advanced Detection & Hunting Strategy Threat Hunting Architecture...Work at officeLocal areaImmediate startRemote workShift work- ...A forward-looking tech company is seeking an experienced Security Engineer specialized in detection and response. The role involves designing and implementing security measures to protect sensitive information and ensure compliance with regulations. Candidates should...
$347k
...Security organization exists to enable safe, responsible innovation at scale. As our systems,... ...'s environments by building advanced detection systems, driving real-time response capabilities... .... Lead, mentor, and directly manage several small teams of senior engineers...$10k
...Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on... ...Security Operations Center (SOC) Experience with query-based log management solutions (ELK, Datadog, Panther, etc) Strong deductive...Full timeWork experience placementWork at officeHome officeRelocation packageFlexible hours2 days per week$173k - $226.8k
...seeking a Security Operations Engineering Manager to lead our Security Operations team. In... ...build out our security operations and response capabilities. You thrive in a team environment... ...of security incidents. Partner with Detection Engineering team to mature detection,...Temporary workLocal areaWorldwide$347k
OpenAI is seeking a Global Detection and Response Lead to scale our cybersecurity operations across our global infrastructure. This leadership... ...response and detection engineering. You will mentor teams, manage incident preparedness, and enhance monitoring capabilities....- Con Edison is seeking a Detection and Response Manager based in New York to lead the Detection and Response Team within the Cybersecurity Operations Center. This pivotal role is responsible for advanced threat detection and incident response, overseeing a new team that...
$314.8k - $359.3k
...Technical (Cyber Hunt, Logging and Threat Detection) Cybersecurity is essential to... ...passionate about cybersecurity and risk management. You see security as an innovation enabler... ...ll serve as the Senior Director who is responsible for threat detection, cyber logging,...Full timePart timeLocal area$7,500 per month
...communities, transform public spaces, and spark cultural conversations. About This Role TaskForce is seeking a Rapid Response & Guerrilla Marketing Manager to help execute fast-moving, high-impact field activations that respond to cultural and political moments in real...Full timeContract workLocal areaShift work- ...over 3 years of experience in security engineering or similar roles, strong communication skills, and a customer-first approach. Responsibilities include developing strategies tailored to customer needs, leading technical guidance through sales cycles, and ensuring...Remote workFlexible hours
- ...Project Manager (Incident Response) Who You Are You are the person who makes chaos look manageable. When a cyberattack hits and five workstreams are spinning at once, you’re the one holding the center, tracking every moving part, keeping every stakeholder informed, and...Contract workWork at office
$170k - $210k
...drive their global operations strategy. This role involves leading a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance. Candidates should have extensive cybersecurity experience, particularly in SOC environments,...- ...Emergency Response Roster - Humanitarian Advocacy & External Engagement Director Join to apply for the Emergency Response Roster - Humanitarian... ...disaster strikes. Job Purpose In line with the WVI Disaster Management Standards for global emergencies this position fills an...Full timeWork at officeLocal areaImmediate startRemote workShift work
$196.6k - $260k
...operations organization (United States and India) responsible for ITIL-aligned Incident, Problem, and Change Management, as well as the technical functions that keep... ..., Security, and Customer Success to proactively detect and remediate issues using DataDog observability...H1bNight shift- ...Technical Implementation & Operations Manager Vector Airport Systems is an established... ...accurate and timely delivery of data. Key Responsibilities Plan, oversee and assist in the... ...performance Efficient installations Fast issue detection and resolution Strong team processes...Remote work
$204k - $255k
...more authentic way. The Community You Will Join: The Threat Detection and Response team (TDR) at Airbnb is focused on automating security... ...threats and malicious activity. We are seeking an Engineering Manager to lead our Investigations & Incident Response team within...Work experience placementCasual workLive inWork at officeRemote work- PBS Facility Service is looking for a Manager of Laborers, Handyman, and Emergency Response Operations in New York. In this role, you will oversee a team, coordinate maintenance and repair work, and provide guidance to staff to ensure compliance with industry standards....
$180k - $248k
...Senior Technical Product Marketing Manager Remote - USA | Brand & Product Come join the... ...and CI/CD pipelines Cloud security and detection engineering AI infrastructure and governance... ...Azure, GCP) Threat detection, incident response, or security operations AI architecture,...Full timeTemporary workH1bRemote workHome officeFlexible hours$290k - $365k
About The Role We are looking for an Incident Response Manager to serve as the operational backbone of how Anthropic handles incidents. When... ...to-market teams to continuously improve how the organization detects, responds to, and learns from incidents Qualifications Have...Work at officeVisa sponsorshipFlexible hours- ...Technical Product Manager for AI Security Products Remote (within the US) About the Role... ...insidious adversarial AI attacks can be to detect and defend against. Determined to prove... ...Start‑up. What You’ll Do You will be responsible for translating customer needs, technical...Remote workHome officeFlexible hours
- ...Security Operations to join its expanding team in New York. This role is pivotal in managing day-to-day security operations and involves coordinating with our managed detection and response provider. The ideal candidate should have over 5 years of experience in security...
$7,500 per month
TaskForce is seeking a Rapid Response & Guerrilla Marketing Manager in New York, NY, to oversee fast-moving field activations that respond to cultural moments. This tactical role involves managing multiple projects, vendor sourcing, and coordinating capture teams. Candidates...Full timeContract work- Join to apply for the Account Manager, Immune Response, Hospital Sales (Kentucky, Indiana) role at QIAGEN 1 week ago Be among the first 25 applicants Join to apply for the Account Manager, Immune Response, Hospital Sales (Kentucky, Indiana) role at QIAGEN Get AI-powered...Full time
$128k - $176k
...World's Identity Company Okta is the leader in Identity management and The World's Identity Company . Our mission is to... ...Access Management (PAM): Privileged Access. Identity Threat Detection & Response (ITDR): Identity Security Posture Management and Identity...For contractorsWork experience placementWork at officeLocal areaWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection and Response Manager. Be the first to apply!
- government affairs manager New York, NY
- offer manager New York, NY
- vending manager New York, NY
- engineer manager New York, NY
- natural science manager New York, NY
- equipment manager New York, NY
- city manager New York, NY
- scanning manager New York, NY
- middleware manager New York, NY
- disability manager New York, NY


