Detection Engineering & Automation Lead

Jobgether· Brussels (Firmensitz, recherchiert)· lever· publié le 06/08/2026
Indispensable :PythonCloudAISecurityLeadRemote

Accountabilities Lead and mentor the Detection Engineering & Automation team, setting priorities, driving delivery, and supporting the professional growth of team members.

Own the full detection engineering lifecycle, from use-case design and implementation to testing, optimization, maintenance, and retirement of detection content.

Develop and maintain SIEM and EDR detection rules, detection-as-code pipelines, security enrichment workflows, and SOAR automation playbooks.

Collaborate with Security Operations, Incident Response, Cyber Defense, and engineering teams to improve detection quality, minimize false positives, and close visibility gaps.

Align detection logic with attacker techniques, critical assets, telemetry sources, and incident response procedures to ensure comprehensive security coverage.

Establish documentation, ownership, validation processes, and testing standards for critical detections while leading automation initiatives that safely accelerate investigations.

Requirements

Bachelor's degree or higher in Computer Science, Information Security, or a related technical discipline is preferred.

At least 5 years of experience in Security Operations, Detection Engineering, Threat Detection, or Security Automation, including 2+ years focused on Detection Engineering.

Previous experience leading or mentoring technical security teams.

Strong hands-on expertise creating and tuning detection content using technologies such as Sigma, YARA, SIEM correlation rules, and detection-as-code methodologies.

Experience developing SOAR automation playbooks and security integrations using Python or similar scripting languages.

Solid understanding of MITRE ATT&CK, EDR, cloud, identity, and network telemetry, along with incident response processes and Detection Engineering performance metrics such as MTTD, MTTR, false-positive rates, and detection coverage.

Professional working proficiency in English and upper-intermediate proficiency in Ukrainian or Russian.

Experience within regulated financial environments, cloud-native security, threat intelligence, threat hunting, AI-assisted detection, or building Detection Engineering functions from an early maturity stage is considered an advantage.

Benefits

20 paid vacation days per year.

10 paid sick leave days annually.

Paid public holidays according to the approved holiday calendar.

Medical allowance.

Fully remote work opportunity.

Professional development and education budget.

Language learning budget.

Wellness budget covering gym memberships, sports equipment, and related expenses.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best!  Why Apply Through Jobgether? 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1