<div class="content-intro"><p><a class="notion-link-token notion-focusable-token notion-enable-hover" href="http://apollo.io/" data-token-index="0"><span class="link-annotation-7a57a4e3-9668-4c92-9fb1-a9318bf3a91b--723603012">Apollo.io</span></a> is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world's largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. <a class="notion-link-token notion-focusable-token notion-enable-hover" href="http://apollo.io/" data-token-index="2"><span class="link-annotation-7a57a4e3-9668-4c92-9fb1-a9318bf3a91b--723603012">Apollo.io</span></a> provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, <a class="notion-link-token notion-focusable-token notion-enable-hover" href="http://apollo.io/" data-token-index="4"><span class="link-annotation-7a57a4e3-9668-4c92-9fb1-a9318bf3a91b--723603012">Apollo.io</span></a> turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members.</p></div><h2><strong>Role Overview</strong></h2> <p>Apollo is looking for a startup-minded Engineering Manager to lead our Security Detection & Response team. You'll build and scale a team that ships detection systems, automations, and investigation tools at startup velocity—moving from concept to production in weeks, not months. This is a hands-on leadership role for someone who can coach engineers, make fast decisions with incomplete information, and stay close to the technical details while balancing speed with rigor.</p> <p>This role operates in a fully remote environment and requires excellent asynchronous communication, comfort with ambiguity, and the ability to ship fast and learn from what sticks.</p> <h2><strong>Key Responsibilities</strong></h2> <h3><strong>Team Leadership & Engineering Culture</strong></h3> <ul> <li>Build, lead, and retain a high-performing remote Security Detection & Response team with clear expectations, strong onboarding, documentation, and knowledge-sharing practices.</li> <li>Coach engineers to grow in technical depth, operational ownership, and leadership capability while prioritizing shipping velocity and iteration over perfection.</li> <li>Define team culture around experimentation: ship detection rules quickly, measure effectiveness, iterate based on signal.</li> <li>Partner closely with Engineering, Infrastructure, IT, Fraud, Legal, People, Support, and Product—translating security risk into business decisions and communicating impact clearly to both technical and non-technical stakeholders.</li> </ul> <h3><strong>Shipping Detection Systems & Content at Startup Velocity</strong></h3> <ul> <li>Define and evolve the Security Detection & Response strategy: what to build, when, and why. Prioritize ruthlessly; not every threat gets a detection.</li> <li>Lead the team in shipping detection rules, MITRE ATT&CK-aligned use cases, investigation playbooks, and response automations with measurement and validation loops—but ship first, perfect later.</li> <li>Oversee Panther detections and AI-assisted workflows for triage, enrichment, and response. Continuously measure coverage, precision, latency, and tuning effectiveness through safe rollout and attack simulation.</li> <li>Drive Python-based tooling, Git-based workflows, and CI/CD practices to enable the team to ship detection content in days, not quarters.</li> <li>Stay close to the technical work: code reviews, architecture decisions, and hands-on problem-solving alongside the team.</li> </ul> <h3><strong>Security Observability & Incident Response as Outcome</strong></h3> <ul> <li>Own end-to-end security observability: telemetry onboarding, signal quality, threat intelligence inputs, and alert tuning. Good detections prevent incidents.</li> <li>Lead complex and high-severity incidents with clear decision-making and effective communication. Translate incident learnings into detection and response priorities for the next sprint.</li> <li>Stay technically engaged in investigations across cloud infrastructure, SaaS platforms, corporate systems, and user behavior. Use incidents as teaching moments for the team and validation for detection strategy.</li> <li>Work with Engineering and Infrastructure on telemetry pipelines and operational readiness. Ensure the team has the data they need to ship fast.</li> </ul> <h3><strong>Metrics & Impact</strong></h3> <ul> <li>Define and own strategy-aligned metrics: detection latency, coverage gaps, false positive rates, team velocity. Use data to inform priorities and stakeholder decisions.</li> <li>Communicate security impact in business terms: what risks are you preventing, and what's the cost of being wrong?</li> </ul> <h2><strong>Required Skills & Experience</strong></h2> <ul> <li>5+ years in Security Detection & Response, Security Engineering, or Incident Response—hands-on experience building and shipping detection systems, not just managing incidents.</li> <li>2+ years of people management, including hiring, coaching, and performance management, ideally in a remote-first environment.</li> <li>Strong technical foundation: modern SIEM platforms, detection engineering, log analysis, threat intelligence workflows. Panther experience highly valued.</li> <li>Python proficiency for automation, analysis, and internal tooling. You need to remain techni