Must Have Technical/Functional Skills
Required Skills & Experience
- 7+ years in program or project management, with at least 3+ years embedded within or directly supporting cybersecurity, SOC, or detection engineering functions.
Detection Engineering Lifecycle:
- Strong understanding of the detection engineering lifecycle, including use case development, SIEM rule authoring, alert tuning, and detection validation.
- Familiarity with detection-as-code practices and platforms (e.g., Splunk, Microsoft Sentinel, Chronicle, Elastic SIEM).
- Working knowledge of MITRE ATT&CK framework and its application to detection coverage mapping and gap analysis.
AI & Emerging Threat Domains:
- Experience supporting or managing security programs that address AI/ML system monitoring, GenAI risk, or emerging technology threat vectors.
- Familiarity with AI-specific threat models and the unique detection challenges posed by LLMs, AI pipelines, and model serving infrastructure.
Program Management:
- Proven ability to manage complex, multi-workstream programs across cross-functional teams in matrixed organizations.
- Strong command of program management methodologies (Agile, SAFe, Waterfall, or hybrid) and tooling (e.g., Jira, Confluence, ServiceNow, Smartsheet).
- Demonstrated experience managing senior stakeholder relationships and communicating program status at executive level.
Cross-Functional Collaboration:
- Track record of successfully coordinating across diverse teams including security engineering, data/platform engineering, threat intelligence, and business stakeholders.
- Strong facilitation skills for workshops, planning sessions, and working group governance.
Soft Skills:
- Exceptional written and verbal communication skills with the ability to translate complex technical concepts for non-technical audiences.
- Strong organizational skills with a detail-oriented approach to risk, dependency, and issue management.
- Ability to operate effectively in ambiguous, fast-moving environments with competing priorities.
- Certifications (Preferred but not required): PMP, PgMP, SAFe Agilist, CISSP (Associate), or equivalent cybersecurity or program management credentials.
Education
A Bachelor's degree in Computer Science, Information Security, Business, or a related field is required, or equivalent professional experience.
Skillsets Required:
BFT CyberTech: BRD process management. Strong program mgmt skills for detecting engineering lifecycle management for SOC use cases
Roles & Responsibilities
Program & Product Management
This role requires a senior Program Manager with deep experience leading detection engineering lifecycle management for Security Operations Center (SOC) environments, with a specific focus on enabling and scaling d etection use cases for monitoring AI systems. The consultant will serve as the connective tissue across cross-functional teams - spanning detection engineers, threat intelligence analysts, data engineers, platform teams, and business stakeholders - driving
structured program delivery from detection conception through to production deployment and continuous improvement.
Key Responsibilities
Detection Engineering Program Management:
- Own and manage the end-to-end detection engineering lifecycle - from use case ideation, requirements gathering, and prioritization through to development, validation, deployment, and tuning.
- Maintain and manage a structured detection use case backlog, ensuring alignment with SOC operational priorities and emerging threat landscapes.
- Define and enforce program governance standards, including intake processes, milestone tracking, and delivery cadences across detection engineering workstreams.
- Produce and communicate program status reports, risk registers, and delivery roadmaps for senior stakeholders and leadership.
AI System Monitoring Use Cases:
- Drive the identification, scoping, and delivery of detection use cases specifically targeting AI system behaviors, including model abuse, prompt injection, data exfiltration via AI interfaces, and anomalous AI pipeline activity.
- Collaborate with AI/ML engineering, data science, and security teams to translate AI-specific threat models into actionable detection requirements.
- Track the maturity and coverage of AI-focused detections, ensuring continuous improvement against evolving AI threat vectors.
Cross-Functional Stakeholder Management:
- Act as the primary program interface between detection engineering teams, SOC operations, threat intelligence, data platform, cloud engineering, and business stakeholders.
- Facilitate and lead cross-functional planning sessions, working groups, and steering committees to align priorities and resolve blockers.
- Manage dependencies, risks, and interdependencies across multiple concurrent detection engineering workstreams and teams.
- Build and maintain strong stakeholder relationships to ensure program transparency, buy-in, and accountability.
Process & Operational Excellence:
- Design and implement scalable program management frameworks, workflows, and tooling to support detection engineering at enterprise scale.
- Drive adoption of structured detection engineering methodologies (e.g., detection-as-code, use case tiering, coverage mapping to MITRE ATT&CK).
- Establish and track KPIs and OKRs for detection engineering program health, delivery velocity, and SOC impact.
- Continuously identify and implement process improvements to reduce cycle time and improve detection quality.
Documentation & Reporting:
- Maintain comprehensive program documentation including use case catalogues, decision logs, RACI matrices, and delivery plans.
- Develop executive-level reporting and narrative updates to communicate program progress, risks, and strategic value.
- Working knowledge of MITRE ATT&CK framework and its application to detection coverage mapping and gap analysis.
Salary Range: $90,000 to $115,000 per year