← Zurück zur Liste
Stelle · Senior

Detection Engineering and Automation Lead

Sonstige • Senior • Remote • Vollzeit Europäische Union EU/EMEA

JustMarkets is looking for a Detection Engineering and Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation.

Responsibilities

  • Lead and develop the Detection Engineering and Automation squad, set priorities, mentor team members
  • Own the detection lifecycle end-to-end: use-case definition, development, testing, tuning, retirement
  • Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks
  • Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to reduce false positives and address coverage gaps
  • Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks
  • Ensure critical detections have a clear owner, documentation, and validated testing evidence
  • Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions

Requirements

  • Higher education in Computer Science, Information Security, or related technical field preferred
  • 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation
  • 2+ years of hands-on experience in Detection Engineering
  • 1+ year of experience leading or mentoring a team of engineers
  • Hands-on experience writing and tuning detection content: Sigma, YARA, SIEM correlation rules, detection-as-code practices
  • Experience with SOAR platforms, automation playbooks, and scripting in Python or similar to build integrations
  • Strong understanding of attacker TTPs, MITRE ATT&CK, telemetry sources, EDR, network, cloud, identity, and incident response workflows
  • Experience defining and tracking Detection Engineering metrics and KPIs: MTTD, MTTR, false-positive rate, coverage
  • English: Intermediate+
  • Ukrainian/Russian: Upper-intermediate

Nice to have

  • Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments
  • Experience with cloud-native detection, CNAPP/CSPM, across AWS, GCP, and Azure
  • Experience with AI/LLM-assisted alert summarization or detection tooling
  • Threat intelligence and threat hunting experience, CTI feeds, MISP, Maltego, or similar tools
  • Previous experience building a Detection Engineering function from an early maturity stage

Soft skills

Team leadership and mentoringRisk-aware decision making

What we offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company's approved list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget: gym membership, sports gear, etc.
Languages: English: Intermediate+, Ukrainian/Russian: Upper-intermediate
Education: Higher education in Computer Science, Information Security, or related technical field preferred

Ähnliche Stellen