Skip to content
Back to all jobs

Detection Engineering and Automation Lead

Share:XWhatsApp
Remote- full time- Posted August 4, 2026- via djinni.co

You will be redirected to djinni.co to apply.

We are looking for a Detection Engineering & Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation.

 

This is a unique opportunity to help build and mature the Detection Engineering & Automation function from an early stage, shaping processes, detection strategy, automation, and engineering best practices.

 

Responsibilities

  • Lead and develop the Detection Engineering & Automation squad, setting priorities, mentoring team members, and driving the delivery of detection and automation initiatives
  • Own the detection lifecycle end-to-end, including use-case definition, development, testing, tuning, and retirement
  • Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks
  • Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to review false positives, reduce alert noise, and address detection coverage gaps
  • Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks
  • Ensure critical detections have a clear owner, documentation, and validated testing evidence
  • Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions

 

Requirements

  • Higher education in Computer Science, Information Security, or a related technical field is preferred
  • 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation
  • 2+ years of hands-on experience in Detection Engineering
  • 1+ year of experience leading or mentoring a team of engineers
  • Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and applying detection-as-code practices
  • Experience with SOAR platforms, automation playbooks, and scripting (Python or similar) to build integrations and automate security workflows
  • Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity), and incident response workflows
  • Experience defining and tracking Detection Engineering metrics and KPIs (MTTD, MTTR, false-positive rate, and detection coverage)
  • English - Intermediate+

 

Will be a plus

  • Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments
  • Experience with cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure
  • Experience with AI/LLM-assisted alert summarization or detection tooling
  • Threat intelligence and threat hunting experience (CTI feeds, MISP, Maltego, or similar tools)
  • Previous experience building a Detection Engineering function from an early maturity stage

 

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company’s approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

More general jobs

Sponsored

Working abroad? Stay connected with a Saily eSIM

Get affordable mobile data the moment you land. No physical SIM, no roaming bills.

Use code MONIQU2427 at checkout

Get a Saily eSIM →

Affiliate link: we may earn a commission at no extra cost to you.

Get booked. Keep 85% of every booking.

Be discovered by clients looking for talent in your city.

  • Self-serveList your profile on a flat subscription. Clients send you an inquiry through the platform.
  • ManagedPrefer a hands-on option? Elite managed bookings are arranged with us by agreement, a separate paid lane.