Fresh remote jobs, sorted by category — join Jobicy on Telegram  › Fresh remote jobs on Telegram  ›
All remote jobs
Open role
Remote opportunity atApollo.io

Engineering Manager, Security Detection & Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
33Listing views
2Application actions
30 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

Apollo.io is seeking a hands-on Engineering Manager to lead its remote Security Detection & Response team. The role combines people leadership with technical ownership of detection engineering, SIEM content, security observability, incident response, and Python-based automation. The manager will build a high-velocity team that delivers Panther detections, MITRE ATT&CK-aligned use cases, investigation playbooks, and response automations. Success depends on balancing rapid iteration with detection quality, measurable coverage, and clear cross-functional communication of security risk. The position requires deep cloud and SaaS security expertise, strong incident leadership, and comfort making decisions amid startup ambiguity.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior technical leadership role with responsibility for both a security engineering team and high-severity detection and response outcomes. It requires expertise across detection engineering, cloud/SaaS telemetry, incident response, automation, and executive-level risk communication in a fast-moving startup environment.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$253,600
US market range$210k–$300k
AI insightThe disclosed annual total cash compensation range is $225,400 to $281,800 USD, producing a midpoint of $253,600. This is competitive for a US-based Engineering Manager leading security detection and response; an estimated broader US market range for comparable senior security engineering management roles is approximately $210,000 to $300,000 annually, excluding the value of equity and benefits.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you prioritize detection engineering work when the team has more potential threats to cover than capacity allows?

I would prioritize based on business-critical assets, likely attacker paths, current telemetry quality, known coverage gaps, and the expected impact of each detection. I would use measurable criteria such as exploitability, blast radius, detection confidence, and implementation effort, then revisit priorities regularly as incidents and threat intelligence change.

Describe how you would improve a noisy detection rule without creating a coverage gap.

I would first analyze alert samples to identify recurring benign patterns, then validate the intended adversary behavior against relevant telemetry and attack simulations. I would tune through scoped exclusions, contextual enrichment, thresholds, or correlation logic, deploy safely in monitor mode where appropriate, and track both false-positive reduction and retained true-positive coverage.

What metrics would you use to evaluate a Detection & Response team?

I would track detection coverage for prioritized threats, detection latency, alert precision, time to triage, time to contain, telemetry onboarding completeness, rule deployment lead time, and tuning outcomes. These metrics should be paired with incident learnings and business-risk context rather than used as isolated productivity measures.

How do you lead a high-severity security incident while maintaining effective stakeholder communication?

I establish a clear incident commander, define technical workstreams, maintain an evidence-based timeline, and set a predictable update cadence. Technical responders receive focused tasks and decision authority, while executives and affected partners receive concise updates covering impact, containment status, risk, and next steps without unnecessary technical detail.

How would you use AI in security triage and response while managing its limitations?

I would apply AI to bounded tasks such as alert enrichment, evidence summarization, investigation guidance, and drafting response actions, while retaining human review for consequential decisions. I would measure accuracy, monitor for hallucinations or data-handling risks, use structured inputs and guardrails, and validate outputs against trusted telemetry and documented playbooks.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. Apollo.io provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, Apollo.io turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members.

Role Overview

Apollo is looking for a startup-minded Engineering Manager to lead our Security Detection & Response team. You’ll build and scale a team that ships detection systems, automations, and investigation tools at startup velocity—moving from concept to production in weeks, not months. This is a hands-on leadership role for someone who can coach engineers, make fast decisions with incomplete information, and stay close to the technical details while balancing speed with rigor.

This role operates in a fully remote environment and requires excellent asynchronous communication, comfort with ambiguity, and the ability to ship fast and learn from what sticks.

Key Responsibilities

Team Leadership & Engineering Culture

  • Build, lead, and retain a high-performing remote Security Detection & Response team with clear expectations, strong onboarding, documentation, and knowledge-sharing practices.
  • Coach engineers to grow in technical depth, operational ownership, and leadership capability while prioritizing shipping velocity and iteration over perfection.
  • Define team culture around experimentation: ship detection rules quickly, measure effectiveness, iterate based on signal.
  • Partner closely with Engineering, Infrastructure, IT, Fraud, Legal, People, Support, and Product—translating security risk into business decisions and communicating impact clearly to both technical and non-technical stakeholders.

Shipping Detection Systems & Content at Startup Velocity

  • Define and evolve the Security Detection & Response strategy: what to build, when, and why. Prioritize ruthlessly; not every threat gets a detection.
  • Lead the team in shipping detection rules, MITRE ATT&CK-aligned use cases, investigation playbooks, and response automations with measurement and validation loops—but ship first, perfect later.
  • Oversee Panther detections and AI-assisted workflows for triage, enrichment, and response. Continuously measure coverage, precision, latency, and tuning effectiveness through safe rollout and attack simulation.
  • Drive Python-based tooling, Git-based workflows, and CI/CD practices to enable the team to ship detection content in days, not quarters.
  • Stay close to the technical work: code reviews, architecture decisions, and hands-on problem-solving alongside the team.

Security Observability & Incident Response as Outcome

  • Own end-to-end security observability: telemetry onboarding, signal quality, threat intelligence inputs, and alert tuning. Good detections prevent incidents.
  • Lead complex and high-severity incidents with clear decision-making and effective communication. Translate incident learnings into detection and response priorities for the next sprint.
  • Stay technically engaged in investigations across cloud infrastructure, SaaS platforms, corporate systems, and user behavior. Use incidents as teaching moments for the team and validation for detection strategy.
  • Work with Engineering and Infrastructure on telemetry pipelines and operational readiness. Ensure the team has the data they need to ship fast.

Metrics & Impact

  • Define and own strategy-aligned metrics: detection latency, coverage gaps, false positive rates, team velocity. Use data to inform priorities and stakeholder decisions.
  • Communicate security impact in business terms: what risks are you preventing, and what’s the cost of being wrong?

Required Skills & Experience

  • 5+ years in Security Detection & Response, Security Engineering, or Incident Response—hands-on experience building and shipping detection systems, not just managing incidents.
  • 2+ years of people management, including hiring, coaching, and performance management, ideally in a remote-first environment.
  • Strong technical foundation: modern SIEM platforms, detection engineering, log analysis, threat intelligence workflows. Panther experience highly valued.
  • Python proficiency for automation, analysis, and internal tooling. You need to remain technically credible with your engineers and review code.
  • Comfort with startup velocity: able to make sound decisions with incomplete information, ship fast, iterate based on feedback, and know when “good enough” is good enough.
  • Git workflows, CI/CD practices, and experience building security content and automation pipelines as code.
  • Cloud-native and SaaS expertise: GCP preferred. Familiarity with Apollo’s toolsets (Google Workspace, Okta, GitHub, Slack, Atlassian, Cloudflare, CrowdStrike, Kandji, Panther, Snowflake) strongly valued.
  • Excellent communication: You’ll translate technical security work into business impact for executives and explain engineering trade-offs to non-technical stakeholders.

Preferred Qualifications

  • Experience leading Detection Engineering or Security Engineering teams in a high-growth cloud or SaaS startup environment (not just enterprises or government).
  • AI-assisted security workflows: You’ve used AI for triage, investigation, or response in production and know the limitations.
  • MITRE ATT&CK, threat intelligence workflows, and vulnerability management SLAs—but with a bias toward automation and shipping, not just compliance.
  • Relevant certifications such as CISSP, GCIA, GCIH, GCED, or cloud security certifications.
  • Track record of shipping fast: you’ve led teams that iterate weekly and measure success by velocity + signal.

The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings (“OTE”) range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process.

Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits.

Pay Transparency Range

$225,400—$281,800 USD

We are AI Native

Apollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team. If you’re energized by finding smarter, faster ways to get things done using AI and automation, you’ll thrive here.

Why You’ll Love Working at Apollo

At Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency, and learn voraciously to stay ahead.

We invest deeply in your growth, ensuring you have the resources, support, and autonomy to own your role and make a real impact. Collaboration is at our core—we’re all for one, meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action, giving you the freedom to experiment, take smart risks, and drive big wins.

If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you.

Learn more here!

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu