Detection Engineering Lead

Xpertdirect — Estonia · Posted ~2 days ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Detection Engineering Lead Tallinn, Estonia — Hybrid Cloud Security | Detection Engineering | Threat Intelligence | Cybersecurity Our client, a growing Cloud Security company based in Tallinn, is looking for a Detection Engineering Lead to own and evolve the detection capabilities protecting enterprise cloud environments. You'll combine deep security expertise with hands-on engineering, developing detection logic for AWS environments, translating threat intelligence into production security content, and building automated Detection-as-Code workflows. What You'll Be Working On • Leading the technical direction of cloud detection engineering across the security platform • Designing high-quality detection logic for attacks targeting AWS environments • Developing and maintaining Sigma rules and platform-specific detection content • Translating emerging threat intelligence and attacker TTPs into actionable production detections • Building Python tooling to automate detection development, testing, validation, and deployment • Establishing Detection-as-Code practices using version control, automated testing, and CI/CD • Improving detection precision while reducing false positives and alert fatigue • Developing behavioural analytics capable of identifying complex or previously unseen attack patterns • Working with Threat Researchers and Incident Response teams to turn real-world incidents into new detection capabilities • Measuring detection coverage against MITRE ATT&CK and identifying gaps across the platform • Mentoring Detection Engineers and establishing engineering standards across the team Experience Required • 6+ years of experience in Detection Engineering, Threat Detection, Security Engineering, Threat Hunting, or related cybersecurity roles • Strong hands-on experience developing SIEM detection content • Experience writing Sigma rules or comparable detection logic • Strong Python scripting or development skills • Deep understanding of AWS security telemetry and cloud attack techniques • Strong knowledge of MITRE ATT&CK and adversary tactics, techniques, and procedures • Experience translating threat intelligence into production detection capabilities • Ability to provide technical leadership while remaining hands-on with engineering and detection development Nice to Have Detection-as-Code experience Splunk, Microsoft Sentinel, Elastic, or Chronicle AWS GuardDuty, Security Hub, or CloudTrail Kubernetes threat detection SOAR and automated response workflows Cloud incident response or threat hunting experience Experience researching emerging cloud attack techniques GIAC, GCTI, GCIA, GCFA, or comparable security certifications