Detection Engineering & Automation Lead (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Detection Engineering & Automation Lead (Cybersecurity): Leading and developing the Detection Engineering & Automation squad to implement end-to-end detection lifecycles and SOAR playbooks with an accent on detection-as-code and noise reduction. Focus on building SIEM/EDR rules, mapping TTPs to MITRE ATT&CK, and accelerating security investigations through automation.
Location: Europe (Remote)
Company
is a financial services company specializing in brokerage and trading platforms.
What you will do
- Lead and develop the Detection Engineering & Automation squad, managing priorities and mentoring team members.
- Own the full detection lifecycle, from use-case definition and development to testing, tuning, and retirement.
- Build and maintain SIEM/EDR detection rules, detection-as-code workflows, and SOAR automation playbooks.
- Collaborate with SOC, Incident Response, and engineering teams to reduce alert noise and close coverage gaps.
- Map detections to critical assets, attacker TTPs, and incident response runbooks.
- Drive security automation initiatives to accelerate investigations while maintaining system safety.
Requirements
- Location: Must be based in Europe.
- 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation.
- 2+ years of hands-on experience specifically in Detection Engineering.
- 1+ year of experience leading or mentoring a team of engineers.
- Proficiency in writing detection content (Sigma, YARA, SIEM correlation rules) and scripting (Python).
- Strong understanding of MITRE ATT&CK, telemetry sources (EDR, network, cloud, identity), and IR workflows.
- English: Intermediate+ level required.
- Ukrainian/Russian: Upper-intermediate level required.
Nice to have
- Experience in fintech, brokerage, trading platforms, or regulated financial environments.
- Expertise in cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure.
- Experience with AI/LLM-assisted alert summarization or detection tools.
- Threat intelligence and hunting experience using CTI feeds, MISP, or Maltego.
Culture & Benefits
- Remote work opportunities.
- 20 days of paid vacation and 10 days of paid sick leave per year.
- Comprehensive budgets for medical, professional education, language learning, and wellness (gym, sports gear).
- Observation of company-approved public holidays.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →