
Detection Engineering Lead
Posted Jul 14

Posted Jul 14
This is a fully remote position, open to applicants in Europe.
• Oversee detection development: ensure comprehensive MITRE coverage while maintaining minimal false-positive and false-negative rates. Collaborate with alert consumers (20+ teams) to minimize noise and maximize signal, enabling prompt action against genuine threats.
• Design and manage detection coverage across both cloud and bare-metal environments.
• Enhance our internal D&R tools and pipelines by onboarding new logs and creating automated response runbooks.
• Incorporate threat intelligence into detection strategies and incident response playbooks, monitoring adversary TTPs relevant to Cloud infrastructure.
• Direct incident response efforts from start to finish: scoping, containment, root cause analysis, post-incident reviews, and ensuring critical action items are resolved to avert future incidents.
• Collaborate with Compliance and Engineering teams to identify actual threats while addressing the requirements of both engineers and regulators.
• Establish and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
• Develop and maintain the Security Incident Response program: encompassing personnel, processes, and tools.
• Create tools, runbooks, and on-call procedures that can scale with the company's growth.
• Minimum of 6 years in security operations, detection engineering, or incident response, with at least 1-2 years in a leadership or mentoring role.
• Extensive hands-on experience with cloud-native environments (Kubernetes, Linux workloads, containerized infrastructure).
• Proficient detection engineering skills: crafting and fine-tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
• Experience in building or managing SOAR workflows and automating responses at scale (preferably with Golang and Temporal).
• Familiarity with threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and their application in detection processes.
• Strong foundational knowledge in incident response: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
• Excellent stakeholder management skills: capable of coordinating with engineers, compliance, legal, and executives during active incident phases. Act as the primary owner and facilitator for complex changes resulting from incident post-mortems.
• Competitive compensation
• Career growth and learning opportunities
• Flexibility and ownership
• Collaborative and innovative culture
• Opportunity to work on impactful AI projects
• International environment and talented teams
Phase2
Job Mobz
RTX
Get handpicked remote jobs straight to your inbox weekly.