Cyber Detection & Response Engineering Lead Expert
Daily tasks
- Solution Architecture & Design: Design and execute pragmatic solutions across security monitoring, detection engineering, incident response, automation, and security operations (SOC/CSIRT).
- AI-Enabled Capabilities: Apply AI-driven technologies to enhance detection accuracy, investigation speed, response workflows, and operations — ensuring robust validation and human oversight.
- Technology Leadership: Guide SIEM, SOAR, EDR, XDR, log management, integration, migration, and detection content operations.
- Client Advisory & Transformation: Translate complex business requirements and security risks into target operating models, architectural designs, and strategic improvement roadmaps.
- Stakeholder Engagement: Facilitate workshops, present strategic recommendations, and align technical teams with executive business stakeholders.
- Team Leadership & Mentorship: Lead, coach, and review the work of consultants, nurturing their technical capabilities and career growth.
- Business Development: Drive proposal development, RFP responses, effort estimation, solution shaping, and client presentations.
- Practice Building: Develop reusable CDR frameworks, accelerators, service offerings, and delivery methodologies to scale the practice.
Requirements
Professional Experience: Strong background in cybersecurity detection and response, SOC operations, incident response, or dedicated cybersecurity consulting. CDR Expertise: Proven hands-on delivery experience across multiple CDR domains (SIEM, detection engineering, security automation, IR, governance, or target operating model design). Project Leadership: Demonstrated track record of leading cybersecurity engagements, complex workstreams, or multidisciplinary project teams. AI Integration Awareness: In-depth understanding of AI applications within CDR, including potential opportunities, limitations, security risks, validation needs, and human-in-the-loop requirements. Presales & Bidding: Experience contributing to proposals, RFP responses, effort estimation, and business development initiatives. Communication & Soft Skills: Fluent English (written and verbal) combined with outstanding presentation, leadership, and problem-solving skills. Nice to Have Experience with SOAR platforms, security workflow automation, or complex API/tool integrations. Working knowledge of query and scripting languages (e.g., KQL, SQL, Python). Hands-on experience leveraging embedded AI capabilities in modern SIEM, SOAR, EDR, or XDR platforms. Familiarity with industry frameworks such as MITRE ATT&CK, NIST CSF, and standard incident response lifecycles. Cloud security monitoring experience across Microsoft Azure, AWS, or GCP. Industry-recognized security certifications (e.g., CISSP, CISM, GCIH, or platform-specific certifications). Management consulting background. Proficiency in an additional European language (German, French, or Spanish).
Must have: Cybersecurity, Security, AI
Nice to have: API, Scripting language, SQL, EDR, NIST, Microsoft Azure, AWS, CISSP, CISM