Beyond Finance
Detection & Response Engineering Manager
Chicago, IL (Hybrid) · Senior · Full-time
Stay score
odds of building a lasting career here
Sponsors, but it's cap-subject — you still face the weighted lottery (~61% per draw at Level IV). Good if you win; have a cap-exempt backup on your list.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card filing pattern in this occupation
Files H-1B transfers
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- You'll stay hands-on, coaching and growing the team while working in the detections, pipelines, and investigations yourself.
- Security operations: monitoring, triage, and incident response across our SaaS applications, user workstations, and AWS, including signals from insider risk.
- Logging pipeline: ingest, normalize, enrich, and route security telemetry through APIs and connectors.
Responsibilities
- You'll own detection and response for our environment: monitoring, triage, and incident response across our SaaS applications, user workstations, and AWS.
- You're inheriting an established function with room to mature, and a mandate to build: as we bring automation and AI into security operations, you'll take new capabilities from idea to production.
Requirements
- 7+ years in security operations, detection, or incident response.
- You can take a broad roadmap and prioritize independently, breaking the big picture into concrete, sequenced work for you and the team.
- Experience mentoring or leading engineers or analysts
- formal management tenure is not required.
- You write your own scripts and build detection logic as code.
- A track record of taking projects from prototype to production, including the architecture and the hands-on build.
- Depth in SIEM and SOAR
- we use Datadog Cloud SIEM, ingesting logs from across our platforms, including AWS.
- You can identify which KPIs apply where and set acceptable thresholds for each, across measures such as detection coverage, false-positive rate, MTTR, and automation rate.
Nice to have
- Certifications such as CISSP, the GIAC detection/IR family, or OSCP.
- Experience applying AI or LLMs to security work.
- Awareness of AI-specific risks such as prompt injection and agent trust boundaries.
- Hands-on threat hunting experience.
- Fintech or other regulated-industry experience, and familiarity with PCI DSS, SOC 2, or GLBA.
- Experience securing cloud-native and containerized environments.
- 401(k) matching program
- Merit advancement opportunities
Compensation
- $150,000 - $180,000 USD
Benefits
- Detection engineering: own the detection lifecycle, write, tune, and retire detections, map coverage to MITRE ATT&CK, and reduce false positives.
- While you make a difference for others, we'll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us.
- Considerable employer contributions for health, dental, and vision programs
- Generous PTO, paid holidays, and paid parental leave
Company info
- At Beyond Finance, we've made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future.
This listing is sourced directly from Beyond Finance's careers page and normalized into a canonical job model.