Detection Engineering Lead
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Riga, Latvia; hybrid schedule with 3 days on site and 2 days working from home. Working hours are 9:00–17:30, with occasional flexibility for critical cybersecurity initiatives, platform changes, or incident response.
Salary: EUR 2,700–3,900 gross per month, depending on experience and qualifications.
Company
is a global specialty chemicals and performance materials company developing materials and solutions for transportation, infrastructure, environmental, and consumer applications.
What you will do
- Lead the design, development, testing, tuning, and continuous improvement of security detection content across monitoring platforms.
- Define and maintain telemetry and logging requirements to improve threat visibility.
- Work with internal teams and external MDR/MSSP providers to improve detection quality and operational effectiveness.
- Support threat hunting, incident response, and investigations with detection expertise.
- Develop threat-informed detection strategies aligned with MITRE ATT&CK.
- Promote version control, testing, peer reviews, automation, and performance reporting for detection engineering.
Requirements
- At least 5 years of experience in security operations, detection engineering, or threat detection, with strong experience developing detection content.
- Hands-on expertise with an enterprise SIEM such as Splunk, Microsoft Sentinel, Elastic, Trellix, QRadar, or an equivalent platform.
- Experience developing and tuning detection content at scale.
- Strong knowledge of MITRE ATT&CK, log pipelines, and threat detection methodologies.
- Experience working with or governing a managed detection provider.
- Fluency in Python, a SIEM query language such as KQL or SPL, and regular expressions; excellent written and spoken English is required.
Nice to have
- Experience in global industrial, manufacturing, or OT-adjacent environments.
- Experience with security platform migration or consolidation programs.
- Experience maturing or scaling a detection engineering capability.
- GCDA, GCIA, GCDN, Splunk, Sentinel, or OSCP certifications.
- Familiarity with NIST CSF and MITRE ATT&CK.
Culture & Benefits
- Permanent employment contract in a collaborative and flexible team environment.
- Health insurance from the first day of employment.
- Monthly allowance and annual bonus.
- Competitive benefits package and vacation.
- Direct, open feedback and professional support.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →