Remotery

Detection Engineering Lead

Posted Jul 14

This is a fully remote position, open to applicants in Europe.

📋 Description

• Oversee detection development: ensure comprehensive MITRE coverage while maintaining minimal false-positive and false-negative rates. Collaborate with alert consumers (20+ teams) to minimize noise and maximize signal, enabling prompt action against genuine threats.

• Design and manage detection coverage across both cloud and bare-metal environments.

• Enhance our internal D&R tools and pipelines by onboarding new logs and creating automated response runbooks.

• Incorporate threat intelligence into detection strategies and incident response playbooks, monitoring adversary TTPs relevant to Cloud infrastructure.

• Direct incident response efforts from start to finish: scoping, containment, root cause analysis, post-incident reviews, and ensuring critical action items are resolved to avert future incidents.

• Collaborate with Compliance and Engineering teams to identify actual threats while addressing the requirements of both engineers and regulators.

• Establish and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.

• Develop and maintain the Security Incident Response program: encompassing personnel, processes, and tools.

• Create tools, runbooks, and on-call procedures that can scale with the company's growth.


⛳️ Requirements

• Minimum of 6 years in security operations, detection engineering, or incident response, with at least 1-2 years in a leadership or mentoring role.

• Extensive hands-on experience with cloud-native environments (Kubernetes, Linux workloads, containerized infrastructure).

• Proficient detection engineering skills: crafting and fine-tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.

• Experience in building or managing SOAR workflows and automating responses at scale (preferably with Golang and Temporal).

• Familiarity with threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and their application in detection processes.

• Strong foundational knowledge in incident response: memory forensics, log analysis, network traffic analysis, and post-incident reporting.

• Excellent stakeholder management skills: capable of coordinating with engineers, compliance, legal, and executives during active incident phases. Act as the primary owner and facilitator for complex changes resulting from incident post-mortems.


🏝️ Benefits

• Competitive compensation

• Career growth and learning opportunities

• Flexibility and ownership

• Collaborative and innovative culture

• Opportunity to work on impactful AI projects

• International environment and talented teams

People also viewed

Phase2Jul 26

Software Architect

US flagUnited States OnlyFull-timeFull-stack Engineer$123k – $144k/year
ApplyView job
RimuteeJul 26

Arquitecto de Software

CR flagCosta Rica OnlyFull-timeFull-stack Engineer
ApplyView job
Job MobzJul 26

Software Developer

RO flagRomania OnlyFull-timeFull-stack Engineer$40k – $50k/year
ApplyView job
RTXJul 26

Full Stack Principal Application Developer

US flagArizona OnlyFull-timeFull-stack Engineer$86.8k – $165.2k/year
ApplyView job
Rocket MortgageJul 26

Software Engineer II – Acquisition and Funnel

US flagMichigan OnlyFull-timeFull-stack Engineer$97k – $207k/year
ApplyView job
AutomoxJul 26

Software Engineer

US flagColorado, +2 more statesFull-timeFull-stack Engineer$125k – $150k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers