Detection Engineering & Automation Lead
JustMarkets
| Company | JustMarkets |
| Category | Engineering |
| Location | Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Lead |
| Salary | Not stated by the employer |
| Posted | 4 Aug 2026 |
| Last verified | 12 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
We are looking for a Detection Engineering & Automation Lead to improve detection quality and automation so high-risk attacker behavior is identified with less noise and faster investigation.
This is a unique opportunity to help build and mature the Detection Engineering & Automation function from an early stage, shaping processes, detection strategy, automation, and engineering best practices.
Responsibilities
Lead and develop the Detection Engineering & Automation squad, setting priorities, mentoring team members, and driving the delivery of detection and automation initiatives
Own the detection lifecycle end-to-end, including use-case definition, development, testing, tuning, and retirement
Build and maintain SIEM/EDR detection rules, detection-as-code, enrichment workflows, and SOAR automation playbooks
Collaborate with SOC, Cyber Defense leadership, Incident Response, and engineering teams to review false positives, reduce alert noise, and address detection coverage gaps
Map detections to critical assets, attacker TTPs, telemetry sources, and incident response runbooks
Ensure critical detections have a clear owner, documentation, and validated testing evidence
Lead security automation initiatives that accelerate investigations while avoiding unsafe autonomous actions
Requirements
Higher education in Computer Science, Information Security, or a related technical field is preferred
5+ years of experience in SOC, Detection Engineering, Threat Detection, or Security Automation
2+ years of hands-on experience in Detection Engineering
1+ year of experience leading or mentoring a team of engineers
Hands-on experience writing and tuning detection content (Sigma, YARA, SIEM correlation rules) and applying detection-as-code practices
Experience with SOAR platforms, automation playbooks, and scripting (Python or similar) to build integrations and automate security workflows
Strong understanding of attacker TTPs (MITRE ATT&CK), telemetry sources (EDR, network, cloud, identity), and incident response workflows
Experience defining and tracking Detection Engineering metrics and KPIs (MTTD, MTTR, false-positive rate, and detection coverage)
English - Intermediate+
Ukrainian\Russian - Upper-intermediate
Will be a plus
Experience in fintech, brokerage, trading platforms, payments, or other regulated financial environments
Experience with cloud-native detection (CNAPP/CSPM) across AWS, GCP, and Azure
Experience with AI/LLM-assisted alert summarization or detection tooling
Threat intelligence and threat hunting experience (CTI feeds, MISP, Maltego, or similar tools)
Previous experience building a Detection Engineering function from an early maturity stage
We offer
20 paid vacation days per year
10 paid sick leave days per year
Public holidays as per the company’s approved Public holiday list
Medical budget
Opportunity to work remotely
Professional education budget
Language learning budget
Wellness budget (gym membership, sports gear and related expenses)