Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

JustMarkets via Greenhouse

Detection Engineering & Automation Lead

lead Europe
still open verified 2d ago posted 42d ago checked just now
Apply at job-boards.eu.greenhouse.io

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 42d ago

The date the source published, not the day we noticed it (2026-08-04). Last seen at its source just now.

Is it remote?

Remote, Europe

That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.

Who may apply?

Europe

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay €103.4k–129.4k/yr

Middle 50% of 18 listings that do state pay — Engineering · Lead · Europe · EUR/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSAzureGCPIncident ManagementKnowledge BaseMentoringPythonSIEM

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

We are looking for a Detection Engineering & Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation.

This is a unique opportunity to help build and mature the Detection Engineering & Automation function from an early stage, shaping processes, detection strategy, automation, and engineering best practices.

Responsibilities

  • Lead and develop the Detection Engineering & Automation squad, setting priorities, mentoring team members, and driving the delivery of detection and automation initiatives
  • Own the detection lifecycle end-to-end, including use-case definition, development, testing, tuning, and retirement
  • Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks
  • Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to review false positives, reduce alert noise, and address detection coverage gaps
  • Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks
  • Ensure critical detections have a clear owner, documentation, and validated testing evidence
  • Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions

Requirements

  • Higher education in Computer Science, Information Security, or a related technical field is preferred
  • 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation
  • 2+ years of hands-on experience in Detection Engineering
  • 1+ year of experience leading or mentoring a team of engineers
  • Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and applying detection-as-code practices
  • Experience with SOAR platforms, automation playbooks, and scripting (Python or similar) to build integrations and automate security workflows
  • Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity), and incident response workflows
  • Experience defining and tracking Detection Engineering metrics and KPIs (MTTD, MTTR, false-positive rate, and detection coverage)
  • English - Intermediate+
  • Ukrainian\Russian - Upper-intermediate

Will be a plus

  • Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments
  • Experience with cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure
  • Experience with AI/LLM-assisted alert summarization or detection tooling
  • Threat intelligence and threat hunting experience (CTI feeds, MISP, Maltego, or similar tools)
  • Previous experience building a Detection Engineering function from an early maturity stage

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company’s approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Role mission

Improve detection quality and automation so high-risk attacker behavior is found with less noise and faster investigation.

Requirements hard skills

1. 5+ years of experience in SOC, Detection Engineering, Threat Detection or Security Automation, including 2+ years focused specifically on detection engineering.
2. 1+ year of experience leading or mentoring a team of engineers.
3. Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and detection-as-code practices.
4. Practical experience with SOAR/automation platforms and building playbooks that reduce manual triage time.
5. Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity) and incident response workflows.
6. Experience defining and tracking detection engineering metrics/KPIs (MTTD/MTTR, false-positive rate, coverage).
7. Scripting/automation skills (Python or similar) to build integrations and automation workflows.

Requirements soft skills

1. Strong sense of ownership and ability to prioritize a high-risk detection backlog independently.
2. Strong cross-team collaboration with SOC, Cyber Defense, IR and engineering teams.
3. Clear written documentation of detections, runbooks and tuning rationale.
4. Coaching and people-management skills to grow technical squad.
5. Ability to make risk-based decisions within defined decision rights and escalate appropriately.

Responsibilities

1. Own the detection lifecycle end-to-end: use-case definition, development, testing, tuning and retirement.
2. Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows and automation playbooks (SOAR).
3. Map detections to critical assets, attacker TTPs, telemetry sources and incident response runbooks.
4. Review false positives, alert noise and detection coverage gaps together with SOC and Cyber Defense leadership.
5. Ensure critical detections have a clear owner, documentation, and validated testing evidence.
6. Lead security automation initiatives that speed up investigation while avoiding unsafe autonomous actions.

Will be a plus

1. Experience in fintech, brokerage, trading platforms, payments or other regulated financial environments.
2. Experience with cloud-native detection (CNAPP/CSPM) across AWS/GCP/Azure.
3. Experience with AI/LLM-assisted alert summarization or detection tooling.
4. Threat intelligence / hunting experience (CTI feeds, MISP, Maltego or similar tools).
5. Prior experience building a detection engineering function from an early maturity stage.

Apply at job-boards.eu.greenhouse.io