Lead Detection Engineer
תיאור המשרה
we are looking for a Lead Detection Engineer .This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.Youre welcome to work in our offices in Tel Aviv, IsraelYour responsibilities will include: Detection coverage strategy across endpoint, identity, cloud, and infrastructure - how it's measured, prioritized, and continuously improved.
Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic. Architecture connecting detections to enrichment, triage, and automated response workflows. Technical standards for how detections are designed, tested, documented, deployed, and retired.
Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops. Design and build high-fidelity behavioral detections across SIEM and EDR platforms. Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
Validate detections through threat simulations and continuous detection testing. Partner with SOC analysts to close the feedback loop between detections and real investigations. Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
Make architectural decisions that scale as the team and organization grow.Requirements: We expect you to have: Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role - with demonstrated depth, not just breadth.
Experience owning or leading detection engineering work as a senior technical contributor Strong understanding of attacker tradecraft and adversary behavior. Hands-on experience with at least one enterprise SIEM and EDR platform - Splunk, Microsoft Sentinel, CrowdStrike, or equivalent. Cloud security depth across Azure, AWS, or GCP.
Strong query development skills in SPL, KQL, Sigma, or similar. Strong scripting skills (python, powershell etc)Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
Experience using MITRE ATT&CK to design, validate, and measure detection coverage Ability to make and defend technical decisions and establish standards others adopt.This position is open to all candidates.
מתעניינים במשרה הזו?