About Exaforce
Exaforce is a U.S.-based startup at the forefront of cloud security. Founded by security and AI experts from Google, PANW, and F5, Exaforce is well funded and backed by top-tier VCs. Exaforce is on a mission to simplify security and operations in the Cloud. It enables enterprises to force multiply their security teams by giving them unprecedented visibility into their cloud environments, identifying risk, detecting previously unknown threats, while giving them the tools they need to quickly remedy the situation without the manual heavylift.
Position Overview
We are seeking an experienced people leader to manage our global Detection and Response Engineering (DRE) team within our cybersecurity MDR organization. In this role, you will build, lead, and develop a team of Detection and Response Engineers responsible for protecting our customers' cloud environments. You will own the operational rigor, quality, and consistency of detection, threat hunting, and incident response delivered across the team, while acting as an escalation point for critical incidents and a strategic partner to customers, product, and engineering leadership. This role blends hands-on security leadership with day-to-day people management including hiring, coaching, and scaling a high-performing DRE bench as the team and customer base grow.
Key Responsibilities
- Hire, onboard, coach, and manage performance for a team of Detection and Response Engineers across multiple geographies and time zones.
- Own the team's on-call/rotational coverage model, staffing, and capacity planning to ensure 24/7 detection and response coverage.
- Set quality standards and review processes for detection rule tuning, alert triage, correlation logic, and incident investigations across the team.
- Act as the escalation point for high-severity security incidents, driving containment, eradication, and recommending recovery efforts alongside the team.
- Define and track team KPIs/SLAs (e.g., time-to-detect, time-to-respond, false-positive rates) and report on team performance to leadership.
- Partner with Product and Engineering to feed field-identified detection gaps, tooling needs, and platform feedback into the roadmap.
- Own customer-facing escalations and strategic relationships, including executive-level updates on security posture and incident outcomes.
- Build and maintain playbooks, runbooks, and standard operating procedures for the DRE function.
- Drive continuous improvement of detection content, threat hunting methodology, and response automation across the team.
- Collaborate cross-functionally with Software Development, SRE, and Customer Success teams on onboarding and platform integration.
- Support recruiting, career development, and succession planning to grow the team's technical depth over time.
Required Skills
- 5-8+ years in cybersecurity operations, detection engineering, or incident response, including 2+ years in a people management, team lead, or shift-lead capacity.
- Demonstrated experience running or supervising SOC/MDR operations, including on-call and 24/7 coverage models.
- Proven ability to review and improve detection logic, correlation rules, and investigation quality across a team rather than just individually.
- Track record of hiring, coaching, and developing security engineers, including managing performance and career growth.
- Strong incident command experience, leading (not just participating in) containment, eradication, and recovery efforts.
- Excellent written and verbal communication skills, including experience presenting to customers and executive stakeholders.
- Bachelor's degree in Computer Science, Information Security, or a related field.
Preferred Skills
- Experience managing distributed/global teams across multiple time zones.
- Security aspects of key cloud providers (AWS, Azure, GCP) and familiarity with securing code/identity repositories (GitHub, Atlassian).
- Experience building or scaling a detection engineering or MDR function at a startup or high-growth company.
- MITRE ATT&CK framework expertise and experience embedding it into team detection strategy.
- Familiarity with scripting/automation (Python, Bash) to guide technical decisions, even if not hands-on daily.
- Experience with databases and SQL for reviewing detection and investigation logic.
- Cybersecurity leadership or advanced certifications (e.g., CISSP, GCIH, GCFA, CISM) are a plus.
- Experience partnering with Product/Engineering leadership to influence platform roadmap based on field feedback.
What We Offer
- A dynamic and innovative work environment at a leading-edge technology company.
- Opportunities for professional growth and development.
- Competitive salary and benefits package.
- The chance to lead a talented and passionate team dedicated to making a real impact in the cybersecurity industry.
How to Apply
Interested candidates are invited to submit their resume and cover letter outlining their qualifications and experience. Please send your application to careers@exaforce.com with the subject line "Manager, Detection & Response Engineering."
Equal Opportunity Employer
Exaforce is an equal opportunity employer. We are committed to creating a diverse and inclusive workplace where all individuals are treated with respect and dignity. We believe that diversity drives innovation and strengthens our company. We welcome applicants from all backgrounds, and we do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. All employment decisions are based on qualifications, merit, and business needs.


