Detection Engineering Lead
Xpertdirect — Estonia · Posted ~2 days ago
🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.
Log in to add to target listDescription
Detection Engineering Lead
Tallinn, Estonia — Hybrid
Cloud Security | Detection Engineering | Threat Intelligence | Cybersecurity
Our client, a growing Cloud Security company based in Tallinn, is looking for a Detection Engineering Lead to own and evolve the detection capabilities protecting enterprise cloud environments.
You'll combine deep security expertise with hands-on engineering, developing detection logic for AWS environments, translating threat intelligence into production security content, and building automated Detection-as-Code workflows.
What You'll Be Working On
• Leading the technical direction of cloud detection engineering across the security platform
• Designing high-quality detection logic for attacks targeting AWS environments
• Developing and maintaining Sigma rules and platform-specific detection content
• Translating emerging threat intelligence and attacker TTPs into actionable production detections
• Building Python tooling to automate detection development, testing, validation, and deployment
• Establishing Detection-as-Code practices using version control, automated testing, and CI/CD
• Improving detection precision while reducing false positives and alert fatigue
• Developing behavioural analytics capable of identifying complex or previously unseen attack patterns
• Working with Threat Researchers and Incident Response teams to turn real-world incidents into new detection capabilities
• Measuring detection coverage against MITRE ATT&CK and identifying gaps across the platform
• Mentoring Detection Engineers and establishing engineering standards across the team
Experience Required
• 6+ years of experience in Detection Engineering, Threat Detection, Security Engineering, Threat Hunting, or related cybersecurity roles
• Strong hands-on experience developing SIEM detection content
• Experience writing Sigma rules or comparable detection logic
• Strong Python scripting or development skills
• Deep understanding of AWS security telemetry and cloud attack techniques
• Strong knowledge of MITRE ATT&CK and adversary tactics, techniques, and procedures
• Experience translating threat intelligence into production detection capabilities
• Ability to provide technical leadership while remaining hands-on with engineering and detection development
Nice to Have
Detection-as-Code experience
Splunk, Microsoft Sentinel, Elastic, or Chronicle
AWS GuardDuty, Security Hub, or CloudTrail
Kubernetes threat detection
SOAR and automated response workflows
Cloud incident response or threat hunting experience
Experience researching emerging cloud attack techniques
GIAC, GCTI, GCIA, GCFA, or comparable security certifications
We have 85,785 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume — in under a minute we'll analyze all 85,785 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume