Must Have Technical/Functional Skills
Required Skills & Experience
• 7+ years in program or project management, with at least 3+ years embedded within or directly supporting cybersecurity, SOC, or detection engineering functions.
Detection Engineering Lifecycle:
• Strong understanding of the detection engineering lifecycle, including use case development, SIEM rule authoring, alert tuning, and detection validation.
• Familiarity with detection-as-code practices and platforms (e.g., Splunk, Microsoft Sentinel, Chronicle, Elastic SIEM).
• Working knowledge of MITRE ATT&CK framework and its application to detection coverage mapping and gap analysis.
AI & Emerging Threat Domains:
• Experience supporting or managing security programs that address AI/ML system monitoring, GenAI risk, or emerging technology threat vectors.
• Familiarity with AI-specific threat models and the unique detection challenges posed by LLMs, AI pipelines, and model serving infrastructure.
Program Management:
• Proven ability to manage complex, multi-workstream programs across cross-functional teams in matrixed organizations.
• Strong command of program management methodologies (Agile, SAFe, Waterfall, or hybrid) and tooling (e.g., Jira, Confluence, ServiceNow, Smartsheet).
• Demonstrated experience managing senior stakeholder relationships and communicating program status at executive level.
Cross-Functional Collaboration:
• Track record of successfully coordinating across diverse teams including security engineering, data/platform engineering, threat intelligence, and business stakeholders.
• Strong facilitation skills for workshops, planning sessions, and working group governance.
Soft Skills:
• Exceptional written and verbal communication skills with the ability to translate complex technical concepts for non-technical audiences.
• Strong organizational skills with a detail-oriented approach to risk, dependency, and issue management.
• Ability to operate effectively in ambiguous, fast-moving environments with competing priorities.
• Certifications (Preferred but not required): PMP, PgMP, SAFe Agilist, CISSP (Associate), or equivalent cybersecurity or program management credentials.
Education
A Bachelor's degree in Computer Science, Information Security, Business, or a related field is required, or equivalent professional experience.
Skillsets Required:
BFT CyberTech: BRD process management. Strong program mgmt skills for detecting engineering lifecycle management for SOC use cases
Roles & Responsibilities
Program & Product Management
This role requires a senior Program Manager with deep experience leading detection engineering lifecycle management for Security Operations Center (SOC) environments, with a specific focus on enabling and scaling d etection use cases for monitoring AI systems. The consultant will serve as the connective tissue across cross-functional teams spanning detection engineers, threat intelligence analysts, data engineers, platform teams, and business stakeholders driving
structured program delivery from detection conception through to production deployment and continuous improvement.
Key Responsibilities
Detection Engineering Program Management:
• Own and manage the end-to-end detection engineering lifecycle from use case ideation, requirements gathering, and prioritization through to development, validation, deployment, and tuning.
• Maintain and manage a structured detection use case backlog, ensuring alignment with SOC operational priorities and emerging threat landscapes.
• Define and enforce program governance standards, including intake processes, milestone tracking, and delivery cadences across detection engineering workstreams.
• Produce and communicate program status reports, risk registers, and delivery roadmaps for senior stakeholders and leadership.
AI System Monitoring Use Cases:
• Drive the identification, scoping, and delivery of detection use cases specifically targeting AI system behaviors, including model abuse, prompt injection, data exfiltration via AI interfaces, and anomalous AI pipeline activity.
• Collaborate with AI/ML engineering, data science, and security teams to translate AI-specific threat models into actionable detection requirements.
• Track the maturity and coverage of AI-focused detections, ensuring continuous improvement against evolving AI threat vectors.
Cross-Functional Stakeholder Management:
• Act as the primary program interface between detection engineering teams, SOC operations, threat intelligence, data platform, cloud engineering, and business stakeholders.
• Facilitate and lead cross-functional planning sessions, working groups, and steering committees to align priorities and resolve blockers.
• Manage dependencies, risks, and interdependencies across multiple concurrent detection engineering workstreams and teams.
• Build and maintain strong stakeholder relationships to ensure program transparency, buy-in, and accountability.
Process & Operational Excellence:
• Design and implement scalable program management frameworks, workflows, and tooling to support detection engineering at enterprise scale.
• Drive adoption of structured detection engineering methodologies (e.g., detection-as-code, use case tiering, coverage mapping to MITRE ATT&CK).
• Establish and track KPIs and OKRs for detection engineering program health, delivery velocity, and SOC impact.
• Continuously identify and implement process improvements to reduce cycle time and improve detection quality.
Documentation & Reporting:
• Maintain comprehensive program documentation including use case catalogues, decision logs, RACI matrices, and delivery plans.
• Develop executive-level reporting and narrative updates to communicate program progress, risks, and strategic value.
• Working knowledge of MITRE ATT&CK framework and its application to detection coverage mapping and gap analysis.
Salary Range: $90,000 to $115,000 per year