Source Job

Portugal 4w PTO

  • Lead and mentor the Detection Engineering & Automation team, driving delivery and professional growth.
  • Own the full detection lifecycle, from use-case design to implementation, optimization, and retirement.
  • Develop SIEM/EDR rules, detection-as-code pipelines, and SOAR automation playbooks to reduce alert fatigue.

Sigma YARA SIEM SOAR Python

15 jobs similar to Detection Engineering & Automation Lead

Jobs ranked by similarity.

$200,000–$250,000/yr
US Unlimited PTO

  • Lead detection engineering innovation by reimagining how unlimited AI capacity transforms SOC workflows.
  • Partner with engineering teams to encode expert detection knowledge into product, designing scoring rubrics for AI-generated content.
  • Stay current on emerging threats and conduct original research to develop novel AI-assisted detection approaches.

Dropzone's mission is to scale cybersecurity beyond human limits by augmenting security engineers with AI specialists. We are an award-winning, venture-backed company disrupting the $200B+ cybersecurity market with a team experienced in cybersecurity, AI/ML, and SaaS.

United States Unlimited PTO

  • Lead the Security Detection & Response team, owning incident response, detection engineering, and automation.
  • Oversee security observability, detection strategy, and AI-assisted workflows to improve speed and reliability.
  • Build and retain a high-performing remote team, collaborating across Engineering, IT, and other departments.

Apollo.io is a leading go-to-market platform for revenue teams, trusted by over 500,000 companies. The company is one of the fastest-growing SaaS firms, raising ~$250 million and valued at $1.6 billion, backed by top-tier investors like Sequoia Capital and Bain Capital Ventures.

$172,279–$249,640/yr
US Canada

  • Build and maintain SIEM for log collection and detection rules across corporate and production environments.
  • Design and deploy canary tokens and early warning mechanisms to detect threats before they reach critical assets.
  • Investigate security incidents end-to-end, including malware analysis, exfiltration assessment, and timeline reconstruction.

Quora operates two platforms: a global knowledge sharing platform with over 300M monthly unique visitors, and Poe, a platform for chatting and building with AI language models. The company is privately held, remote-first, and fosters a culture of transparency, collaboration, and experimentation.

Global 1w paternity

  • Monitor and triage security alerts from SIEM, EDR, and other sources to identify threats.
  • Perform initial investigations to validate alerts, assess severity, and determine root cause.
  • Document findings and communicate with clients and internal teams for effective incident response.

Netrix Global provides holistic IT solutions to help businesses run and scale securely. The company is a top system integrator ranked in the CRN VAR500, with a culture focused on ownership, collaboration, and respect.

Argentina

  • Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
  • Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
  • Develop security automation and workflows to reduce manual toil and improve response speed.

Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.

$75,000–$95,000/yr
Global Unlimited PTO

  • Design, test, and optimize detection workflows including sourcing queries, collection methods, enrichment logic across data sources.
  • Partner with Product and Engineering to communicate customer feedback and emerging threat patterns.
  • Analyze recurring trends across alerts and customer environments to inform scalable platform improvements.

Doppel is building the future of social engineering defense using an AI-native platform to protect against phishing, impersonation, and fraud. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with deep cybersecurity expertise and a culture of clarity and collaboration.

Global

  • Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
  • Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
  • Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.

We are the team behind Chainlink, the industry-standard oracle platform bringing capital markets onchain and powering the majority of DeFi. We have enabled tens of trillions in transaction value and secure the vast majority of DeFi, with a culture of security and innovation.

US

  • Deploy and support Scout products in real customer environments, building and improving deployment automations.
  • Prototype integrations with customer systems and turn repeatable issues into actionable product requirements.
  • Communicate clearly with technical and non-technical customers while researching cybersecurity trends.

Volexity is a cybersecurity company that builds products used in real-world security environments, including incident response and threat intelligence. The company values diversity and is an equal opportunity employer, hiring based on qualifications and merit.

$190,000–$220,000/yr
US Unlimited PTO 12w maternity 12w paternity

  • Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
  • Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
  • Build and extend security-automation tooling with code fluency in Python or TypeScript.

SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.

UK

  • Monitor security events and provide technical analysis on alerts.
  • Lead information security incidents and employee insider investigations.
  • Coordinate building of services and technologies to support security operations.

Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. A recently public company, it fosters a collaborative and growth-minded culture focused on safety, efficiency, and sustainability.

$152,000–$152,000/yr
US

  • Build and maintain Synapse collection pipelines through Storm queries, automation, and data models.
  • Diagnose and resolve complex defects in Synapse tooling and collection systems independently.
  • Support threat hunting and adversary tracking using telemetry and malware analysis techniques.

Dragos is a global leader in OT cybersecurity, combining technology, threat intelligence, and expert services to protect critical infrastructure. The company is a remote-first mission-driven team built on authenticity, transparency, and trust.

  • Lead technical discovery calls and translate customer requirements into high-level solution designs.
  • Draw integration diagrams, validate technical feasibility, and position GuidePoint's differentiated capabilities.
  • Support account executives in pre-sales engagements, ensuring technical alignment before formal scoping.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. Since its inception in 2011, GuidePoint has grown to over 1,200 employees and serves as a trusted advisor to more than 6,200 customers.

$75,600–$97,200/yr
Ireland

  • Triage, investigate, and respond to alerts from the Huntress platform daily.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations.
  • Contribute to detection engineering and collaborate with a passionate team dedicated to protecting companies from cyber-attacks.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, providing enterprise-grade cybersecurity to businesses of all sizes. They secure over 5M endpoints and 14M identities worldwide with a 24/7 human-led SOC and a remote-first culture.

India

  • Investigate and analyze security alerts and incidents across endpoint, network, cloud, and identity environments.
  • Conduct proactive threat hunting, malware analysis, and deobfuscation of suspicious scripts.
  • Collaborate with senior analysts, document findings, and provide remediation recommendations.

The company operates a global Managed Detection and Response environment, protecting organizations from cyber threats. It has a remote-first culture with a collaborative team and opportunities for professional growth.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.