Simplify Logo
SentinelOne

SentinelOne

AI-powered endpoint and cloud protection platform

Manager, Detection Engineering - Rapid Response Team

Full-Time
$164k - $226k/yr
Mid, Senior
Remote in USA
Remote
No H1B Sponsorship

About the job

Requirements
  • Proven experience leading or mentoring a detection engineering, threat detection, or security operations center-adjacent team.
  • Current hands-on detection engineering expertise, including writing, reviewing, and tuning detection rules, understanding the end-to-end detection lifecycle, and working with false-negative and false-positive feedback loops.
  • Strong hands-on experience with GitHub and detection-as-code pipelines, including pull requests, code review, and merge-to-release workflows.
  • Hands-on experience developing detections across more than one engine, including endpoint behavioral, signature-based engines such as YARA, and cloud or security information and event management-based engines across multiple data sources, or the ability to ramp quickly across engines.
  • Experience developing detections at a product or vendor company where coverage spans many customers and industries rather than a single organization.
  • Strong understanding of adversary behavior, MITRE ATT&CK, ransomware, and in-the-wild campaigns.
  • Experience working in fast-moving, service-level-objective-driven environments with competing priorities and responding to emerging threats outside a traditional schedule.
  • Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.
Responsibilities
  • Personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard for the team.
  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.
  • Own the Rapid Response Team's operational cadence, including threat triage and prioritization, service-level-objective adherence, incident coordination, and workload balancing across concurrent threats.
  • Protect the team's focus and capacity by shielding engineers from unscoped demand while ensuring high-priority work is completed within target turnaround times.
  • Grow cross-functional partnerships that extend the team's reach and represent the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.
  • Own and evolve the team's roadmap, process documentation, service charter, and metrics.
  • Champion detection automation and tooling, aligning the automation roadmap with the team's needs.
  • Drive proactive and transparent communication of the team's work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.
  • Lead the Rapid Response Team responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps.
Desired Qualifications
  • A strong technical lead ready to step fully into management may be considered in lieu of direct people-management experience.
  • Familiarity with intake and triage workflows and detection automation tooling.
  • Excellent communication and stakeholder management skills, including representing a technical team to senior leadership and partner teams.

About the company

SentinelOne provides autonomous cybersecurity solutions for endpoints, cloud, and identity environments. Its AI-powered platform unifies prevention, detection, response, remediation, and forensics, enabling real-time protection against malware, ransomware, and advanced persistent threats (APTs). The product monitors multiple vectors for suspicious behavior and uses automated, integrated response to rapidly eliminate threats without manual intervention. The company differentiates itself through a single, unified platform that combines multiple security functions and a 24/7 team offering threat hunting, incident response, and incident management. Its goal is to keep enterprise customers safe from evolving cyber threats by staying at the leading edge of security technology and delivering comprehensive protection across devices, cloud resources, and identities.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Mountain View, California

Founded

2013

Get referred to SentinelOne

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 27, 2026 revenue rose 21% to $292 million, beating estimates.
  • ARR reached $1.22 billion in Q2 2026, up 22% year over year.
  • September 3, 2026 AWS and OpenAI integrations expand Wayfinder distribution and relevance.

What critics are saying

  • May 2026 layoffs cut 8% of staff, signaling pressure to fund AI investments.
  • CrowdStrike and Palo Alto Networks attack SentinelOne's endpoint niche with broader platforms.
  • FY2027 EPS guidance was lowered in August 2026 despite stronger revenue, showing fragile profitability.

What makes SentinelOne unique

  • September 2026 Wayfinder uses OpenAI GPT-5.6-Cyber for validated malware analysis.
  • Singularity unifies endpoint, cloud, identity, and XDR into one autonomous security stack.
  • SentinelOne serves 1,715 customers spending over $100,000 annually, proving enterprise traction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA

Unlimited PTO

Industry leading gender-neutral parental leave

Paid Company Holidays

Paid Sick Time

Employee stock purchase program

Disability & life insurance

Employee assistance program

Gym membership reimbursement

Cell phone reimbursement

Numerous company-sponsored events

Growth & Insights and Company News

Headcount

6 month growth

-10%

1 year growth

-10%

2 year growth

-8%
Yahoo Finance
Sep 10th, 2026
SentinelOne CEO sells 38,759 shares worth $767K for mandatory tax withholding on vested stock

SentinelOne CEO Tomer Weingarten sold 38,759 shares of Class A Common Stock on 8 September 2026, valued at approximately $767,000. The transaction was non-discretionary, mandated by the company's equity incentive plan to cover tax withholding obligations from vesting restricted stock units. Following the sale, Weingarten retains 1,801,827 shares valued at $35.01 million. The sale followed a 5% one-year return for the stock but was not a reaction to market conditions. SentinelOne develops the Singularity XDR Platform, an AI-powered cybersecurity solution. The company operates a subscription-based SaaS model serving enterprises globally. With a market capitalisation of $6.7 billion, SentinelOne reported trailing twelve-month revenue of $1.1 billion and employs approximately 2,900 people.

Yahoo Finance
Sep 10th, 2026
SentinelOne CFO sells 21,664 shares worth $421K as stock posts 5% one-year gain

SentinelOne's chief financial officer Sonalee Elizabeth Parekh sold 21,664 shares of Class A Common Stock on 8 September 2026, according to an SEC Form 4 filing. The transaction was valued at approximately $421,100. The sale was executed automatically under a Rule 10b5-1 trading plan adopted on 9 June 2026. Such plans allow corporate insiders to schedule share sales in advance whilst operating within SEC guidelines. Parekh retains a significant stake of 942,617 shares, representing 0.28% of the company and valued at approximately $18.3 million. At the time of the transaction, SentinelOne shares had delivered a one-year total return of 5%. The cybersecurity firm reported trailing twelve-month revenue of $1.1 billion.

Yahoo Finance
Sep 8th, 2026
SentinelOne stock surges 16% in August on AI expansion and Q2 earnings beat

SentinelOne's stock rose almost 16% in August, driven by positive business updates and better-than-expected quarterly earnings. The cybersecurity company announced an expansion of its Wayfinder Frontier AI Services and a new partnership with Amazon Web Services to integrate AI runtime security into Amazon Bedrock. Second-quarter revenue grew 21% to $291 million, whilst adjusted net income more than doubled to $28.5 million. However, the company reduced its full-year adjusted earnings per share guidance for fiscal 2027, though it raised its revenue forecast. The mixed results initially reversed some of August's gains. SentinelOne specialises in AI-powered cybersecurity solutions designed to protect against advanced digital threats.

Yahoo Finance
Sep 5th, 2026
OpenAI commits $1B to cyber defence, backs Cloudflare and SentinelOne AI security services

OpenAI launched Daybreak for Frontline Defenders on 3 September, committing $1 billion in subsidized access, training, and partnerships. The Daybreak Defense Network now includes over 35 enterprise products and services. Cloudflare is offering invitation-only access to an AI vulnerability-discovery and remediation service built with GPT-5.6 Cyber. SentinelOne is adding Daybreak models to its Wayfinder services. Both companies take different approaches to the same programme. Cloudflare's model starts at the network and developer edge, combining source-code analysis with traffic and security context. SentinelOne approaches from endpoint and security operations, placing AI inside workflows for security teams. Eighty-seven hedge funds held Cloudflare at 30 June, versus 84 at 31 March. Forty-one held SentinelOne in Q2, up from 37 in Q1.

Yahoo Finance
Sep 4th, 2026
SentinelOne integrates GPT-5.6-Cyber for malware analysis after benchmarking

SentinelOne has expanded its Wayfinder Frontier AI Services to run on OpenAI Daybreak models, starting with GPT-5.6-Cyber. The endpoint and cloud security vendor introduced two new capabilities: one scans customer code repositories for OWASP-class flaws, implants, exposed secrets and supply-chain risks, with findings mapped to MITRE ATT&CK; the other evaluates telemetry against detection rules to identify posture gaps, including risky use of VPNs, proxies and remote-management tools. SentinelLABS benchmarking found GPT-5.6-Cyber performed best in class on reverse engineering and analysis of military-grade malware. The company's offensive-security analysts validate every verdict before delivery to customers. "Attackers are increasingly using AI to find and exploit weaknesses," said Chief Customer Officer Steve Stone.