> Markdown version of [/jobs/ext/1472921-lead-threat-detection-engineer](https://www.wearedevelopers.com/jobs/ext/1472921-lead-threat-detection-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Threat Detection Engineer - **Company:** McKesson - **Location:** Irving, TX, United States - **Experience:** Expert - **Salary:** $139,000.0 - $231,600.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Cyber Security, Computer Programming, Information Engineering, Intrusion Detection and Prevention, Python (Programming Language), Enterprise Messaging Systems, Red Team (Cyber Security), Security Information and Event Management, Cyber Threat Analysis, Information Technology, Cybercrime, Splunk - **Published:** July 28, 2026 - **Apply:** https://mckesson.wd3.myworkdayjobs.com/en-US/External_Careers/job/USA-TX-Irving/Lead-Threat-Detection-Engineer_JR0121243-1 ## About the Role * Prioritize detection use-case and scope and create a logical rule * Ability to prioritize decisions to either write a rule and/or tune a tool/policy * Practical experience with threat Actor tracking, tactics, tools, and techniques and working closely with Intel, SOC, and Red Teams (Purple Teams) * Ability to measure detection coverage across common frameworks (e.g. NIST CSF, MITRE, KC) and simplify rules and configurations to optimize alerts * Ability to automate tasks via scripting, automating inputs and outputs of APIs, and programming skills such as python to enable detection engineering tasks * Exceptional interpersonal, organizational, and communication skills and ability to internalize and exemplify Mckesson core values. * Splunk SPL knowledge and SIEM experience or additional SIEM background, * 10+ years of professional experience in two or more domains, including: detection engineering, data engineering, incident response, threat hunting, threat intelligence. * Bachelor's degree in computer science, Information Security, Security Engineering, Statistics, or Data Science * Chronicle Experience, Splunk Certifications (1,2), Automation certifications (Security with Python SEC573), Sigma Rules ## Description McKesson's Lead Threat Detection Engineer will be a member of our global cyber threat intelligence, incident response, analytics, and engineering team responsible for advancing our detection capabilities and tools. This team is responsible for building detection content, enabling integration, automation, enrichment, and performance of alerts. This role enables speed, quality, and coverage of threats for security operations and reduces risk to McKesson business operations., * Mature from a manual detection practice to a modern, automated, and standardized Detection-as-Code practice and infrastructure. * Develop use-cases based on intelligence, red team results, and incident data * Develop IOC workflows and a feedback loop for the Threat Intel Platform (TIP) * Write detection and correlation rules to identify threats across our stack * Assist in onboarding logs and identifying gaps in logs or alert results * Develop a deep understanding of data models, macros, indexes, sources, and field alias and the technology foundation our detection stack is built * Understand data schema/API standards, automation, and messaging systems * Bring a metrics-driven mindset to our rules, signals (IOCs), and alerts ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)