Назад
Company hidden
20 часов назад

Detection Engineering & Automation Lead (Fintech)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
lead
Английский
b1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Detection Engineering & Automation Lead (Cybersecurity): Leading and developing the Detection Engineering & Automation squad to implement end-to-end detection lifecycles and SOAR playbooks with an accent on detection-as-code and noise reduction. Focus on building SIEM/EDR rules, mapping TTPs to MITRE ATT&CK, and accelerating security investigations through automation.

Location: Europe (Remote)

Company

hirify.global is a financial services company specializing in brokerage and trading platforms.

What you will do

  • Lead and develop the Detection Engineering & Automation squad, managing priorities and mentoring team members.
  • Own the full detection lifecycle, from use-case definition and development to testing, tuning, and retirement.
  • Build and maintain SIEM/EDR detection rules, detection-as-code workflows, and SOAR automation playbooks.
  • Collaborate with SOC, Incident Response, and engineering teams to reduce alert noise and close coverage gaps.
  • Map detections to critical assets, attacker TTPs, and incident response runbooks.
  • Drive security automation initiatives to accelerate investigations while maintaining system safety.

Requirements

  • Location: Must be based in Europe.
  • 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation.
  • 2+ years of hands-on experience specifically in Detection Engineering.
  • 1+ year of experience leading or mentoring a team of engineers.
  • Proficiency in writing detection content (Sigma, YARA, SIEM correlation rules) and scripting (Python).
  • Strong understanding of MITRE ATT&CK, telemetry sources (EDR, network, cloud, identity), and IR workflows.
  • English: Intermediate+ level required.
  • Ukrainian/Russian: Upper-intermediate level required.

Nice to have

  • Experience in fintech, brokerage, trading platforms, or regulated financial environments.
  • Expertise in cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure.
  • Experience with AI/LLM-assisted alert summarization or detection tools.
  • Threat intelligence and hunting experience using CTI feeds, MISP, or Maltego.

Culture & Benefits

  • Remote work opportunities.
  • 20 days of paid vacation and 10 days of paid sick leave per year.
  • Comprehensive budgets for medical, professional education, language learning, and wellness (gym, sports gear).
  • Observation of company-approved public holidays.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →