Senior Lead Cyber Detection Engineer
Nutné:PythonAWSAzureGoogle CloudCloudDevOpsCI/CDAIFinTechSecuritySeniorLeadJunior
Key Responsibilities
Detection Engineering & Security Monitoring
- Design, develop, and tune high-fidelity detection use cases across SIEM, EDR, NDR, and cloud security platforms.
- Build detection logic mapped to MITRE ATT&CK, focusing on reducing dwell time and false positives.
- Drive Detection-as-Code practices, leveraging automation, version control, and CI/CD pipelines.
- Continuously improve use-case coverage based on threat intelligence, incidents, and red/purple team outcomes.
- Evaluate and onboard new security telemetry sources to enhance visibility.
Threat Hunting
- Lead proactive, hypothesis-driven threat hunting campaigns across endpoints, network, cloud, and identity systems.
- Investigate anomalous behaviors and identify stealthy adversary activities that bypass automated detections.
- Develop reusable hunting playbooks and analytics.
- Collaborate with Incident Response to transition hunts into confirmed incidents and detection improvements.
Threat Intelligence
- Operationalize threat intelligence (strategic, tactical, and operational) into actionable detection use cases.
- Track and profile threat actors targeting financial services / payment ecosystems.
- Integrate intelligence feeds into detection pipelines and SOC workflows.
- Produce intelligence-driven insights and advisories for stakeholders.
Leadership & Technical Oversight
- Serve as a technical lead and mentor for SOC analysts and junior detection engineers.
- Set standards for detection quality, triage effectiveness, and threat coverage.
- Partner with Red Team/Purple Team to validate detection capabilities.
- Act as an escalation point for complex investigations and advanced threat scenarios.
Automation & Engineering
- Develop scripts and tooling (Python, PowerShell, etc.) to automate detection, enrichment, and response workflows.
- Integrate with SOAR platforms to improve SOC efficiency.
- Drive telemetry normalization and data quality improvements.
Stakeholder Engagement
- Work closely with IT, Cloud, DevOps, Fraud, and Risk teams to improve enterprise visibility.
- Provide clear technical reporting and metrics to leadership.
- Support regulatory and audit requirements relevant to security monitoring.
Required Qualifications & Experience
10–15+ years of cybersecurity experience, with at least:
- 5+ years in detection engineering / threat hunting / SOC engineering
- 3+ years in a lead or senior technical role
Strong experience with:
- SIEM platforms
- EDR/XDR solutions
- Threat hunting methodologies and tooling
- Agentic AI, LLM
Deep understanding of:
- MITRE ATT&CK framework
- Adversary tactics, techniques, and procedures (TTPs)
Experience with:
- Cloud security monitoring (AWS, Azure, GCP)
- Identity threat detection (e.g., Azure AD, IAM abuse)
- Detection & Alerting Use Case Management
Strong scripting/programming skills:
- Python, PowerShell, or equivalent
Experience in financial services, fintech, or payment environments is highly preferred
Familiarity with:
- Detection engineering lifecycle
- Data analytics and log pipelines
- SOAR and automation frameworks
Preferred Certifications
- GIAC (GCFA, GCDA, GCTI, GPEN)
- CISSP, CISM
- Microsoft SC-200 / Azure security certifications
- Elastic(or equivalent SIEM certifications)
Key Competencies
- Deep technical expertise with hands-on capability
- Analytical and investigative mindset
- Strong leadership and mentoring skills
- Ability to translate intelligence into actionable detection
- Strong communication and stakeholder management
- Continuous improvement and engineering mindset
What Success Looks Like
- Measurable reduction in MTTD and false positives
- Increased detection coverage aligned to MITRE ATT&CK
- Proactive identification of previously unknown threats
- Mature, scalable Detection Engineering program
- Strong collaboration across SOC, IR, and Red Team functions