SOC Lead (Detection Engineering and Automation)
$$$$
Product
We are looking for a SOC Lead (Detection Engineering and Automation) to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation.
This is a unique opportunity to help build and mature the Detection Engineering & Automation function from an early stage, shaping processes, detection strategy, automation, and engineering best practices.
Responsibilities
- Lead and develop the Detection Engineering & Automation squad, setting priorities, mentoring team members, and driving the delivery of detection and automation initiatives
- Own the detection lifecycle end-to-end, including use-case definition, development, testing, tuning, and retirement
- Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks
- Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to review false positives, reduce alert noise, and address detection coverage gaps
- Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks
- Ensure critical detections have a clear owner, documentation, and validated testing evidence
- Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions
Requirements
- Higher education in Computer Science, Information Security, or a related technical field is preferred
- 5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation
- 2+ years of hands-on experience in Detection Engineering
- 1+ year of experience leading or mentoring a team of engineers
- Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and applying detection-as-code practices
- Experience with SOAR platforms, automation playbooks, and scripting (Python or similar) to build integrations and automate security workflows
- Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity), and incident response workflows
- Experience defining and tracking Detection Engineering metrics and KPIs (MTTD, MTTR, false-positive rate, and detection coverage)
- English - Intermediate+
Will be a plus
- Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments
- Experience with cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure
- Experience with AI/LLM-assisted alert summarization or detection tooling
- Threat intelligence and threat hunting experience (CTI feeds, MISP, Maltego, or similar tools)
- Previous experience building a Detection Engineering function from an early maturity stage
We offer
- 20 paid vacation days per year
- 10 paid sick leave days per year
- Public holidays as per the companyβs approved Public holiday list
- Medical budget
- Opportunity to work remotely
- Professional education budget
- Language learning budget
- Wellness budget (gym membership, sports gear and related expenses)
Required skills experience
SOC
5 years
SIEM
5 years
SOAR
5 years
MITRE ATT&CK
3 years
EDR
5 years
Required languages
English
B1 - Intermediate
Ukrainian
B2 - Upper Intermediate
Russian
B2 - Upper Intermediate
Published 4 August
6 views
Β·
0 applications
π
Average salary range of similar jobs in
analytics β
Loading...