hirq
← All jobs

JustMarkets

Detection Engineering & Automation Lead

Remote, Europe · Remote · Security

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

Incident ResponseSIEMPythonAWSGCPAzureLLMsCybersecurity
We are looking for a Detection Engineering & Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation. This is a unique opportunity to help build and mature the Detection Engineering & Automation function from an early stage, shaping processes, detection strategy, automation, and engineering best practices. Responsibilities - Lead and develop the Detection Engineering & Automation squad, setting priorities, mentoring team members, and driving the delivery of detection and automation initiatives - Own the detection lifecycle end-to-end, including use-case definition, development, testing, tuning, and retirement - Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks - Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to review false positives, reduce alert noise, and address detection coverage gaps - Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks - Ensure critical detections have a clear owner, documentation, and validated testing evidence - Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions Requirements - Higher education in Computer Science, Information Security, or a related technical field is preferred - 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation - 2+ years of hands-on experience in Detection Engineering - 1+ year of experience leading or mentoring a team of engineers - Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and applying detection-as-code practices - Experience with SOAR platforms, automation playbooks, and scripting (Python or similar) to build integrations and automate security workflows - Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity), and incident response workflows - Experience defining and tracking Detection Engineering metrics and KPIs (MTTD, MTTR, false-positive rate, and detection coverage) - English - Intermediate+ - Ukrainian\Russian - Upper-intermediate Will be a plus - Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments - Experience with cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure - Experience with AI/LLM-assisted alert summarization or detection tooling - Threat intelligence and threat hunting experience (CTI feeds, MISP, Maltego, or similar tools) - Previous experience building a Detection Engineering function from an early maturity stage We offer - 20 paid vacation days per year - 10 paid sick leave days per year - Public holidays as per the company’s approved Public holiday list - Medical budget - Opportunity to work remotely - Professional education budget - Language learning budget - Wellness budget (gym membership, sports gear and related expenses)