Назад
Company hidden
14 дней назад

Detection Engineering Lead

2 700 - 3 900€
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
c1
Страна
Latvia
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Detection Engineering Lead (SIEM/Threat Detection): Designing and continuously improving threat detection capabilities across a global manufacturing environment with an accent on enterprise SIEM platforms, telemetry, logging, and MITRE ATT&CK alignment. Focus on developing and tuning detection content, supporting threat hunting and incident response, and measuring detection coverage, MTTD/MTTR, and false-positive reduction.

Location: Riga, Latvia; hybrid schedule with 3 days on site and 2 days working from home. Working hours are 9:00–17:30, with occasional flexibility for critical cybersecurity initiatives, platform changes, or incident response.

Salary: EUR 2,700–3,900 gross per month, depending on experience and qualifications.

Company

hirify.global is a global specialty chemicals and performance materials company developing materials and solutions for transportation, infrastructure, environmental, and consumer applications.

What you will do

  • Lead the design, development, testing, tuning, and continuous improvement of security detection content across monitoring platforms.
  • Define and maintain telemetry and logging requirements to improve threat visibility.
  • Work with internal teams and external MDR/MSSP providers to improve detection quality and operational effectiveness.
  • Support threat hunting, incident response, and investigations with detection expertise.
  • Develop threat-informed detection strategies aligned with MITRE ATT&CK.
  • Promote version control, testing, peer reviews, automation, and performance reporting for detection engineering.

Requirements

  • At least 5 years of experience in security operations, detection engineering, or threat detection, with strong experience developing detection content.
  • Hands-on expertise with an enterprise SIEM such as Splunk, Microsoft Sentinel, Elastic, Trellix, QRadar, or an equivalent platform.
  • Experience developing and tuning detection content at scale.
  • Strong knowledge of MITRE ATT&CK, log pipelines, and threat detection methodologies.
  • Experience working with or governing a managed detection provider.
  • Fluency in Python, a SIEM query language such as KQL or SPL, and regular expressions; excellent written and spoken English is required.

Nice to have

  • Experience in global industrial, manufacturing, or OT-adjacent environments.
  • Experience with security platform migration or consolidation programs.
  • Experience maturing or scaling a detection engineering capability.
  • GCDA, GCIA, GCDN, Splunk, Sentinel, or OSCP certifications.
  • Familiarity with NIST CSF and MITRE ATT&CK.

Culture & Benefits

  • Permanent employment contract in a collaborative and flexible team environment.
  • Health insurance from the first day of employment.
  • Monthly allowance and annual bonus.
  • Competitive benefits package and vacation.
  • Direct, open feedback and professional support.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →