2023-04-13 14:47:21

Detection Engineering Lead

Cabot Latvia, SIA
2700 - 3900 €/m Gross
Occasional remote work possibility

Job Description

Your Role at Cabot

As the Detection Engineering Lead, you will design, build, and continuously improve Cabot’s threat detection capabilities. Working in a hybrid model with internal teams and an external managed detection partner, you will help ensure security threats are identified quickly and effectively across our global manufacturing environment.

You will lead the development of detection content, improve monitoring capabilities, and help shape the future of cybersecurity operations at Cabot.

This role reports to the Cybersecurity Operations Services Manager.

How You Will Make an Impact

  • Lead the design, development, testing, and improvement of security detection content across Cabot’s monitoring platforms.
  • Continuously improve detection capabilities to increase visibility and reduce security risk.
  • Define and maintain telemetry and logging requirements needed for effective threat detection.
  • Work with internal teams and external security providers to improve detection quality and operational effectiveness.
  • Support threat hunting, incident response, and investigations by providing detection expertise and insights.
  • Develop and maintain threat-informed detection strategies aligned with frameworks such as MITRE ATT&CK.
  • Promote detection engineering best practices, including version control, testing, peer reviews, and automation.
  • Track and report on detection coverage, effectiveness, and key performance metrics.

Requirements

  • 5+ years in security operations, detection engineering, or threat detection, with clear depth in detection content development.
  • Deep hands-on expertise with a major enterprise SIEM (for example Splunk, Microsoft Sentinel, Elastic, Trellix, QRadar, or equivalent).
  • Proven detection-content development and tuning at scale.
  • Strong command of MITRE ATT&CK, log pipelines, and threat detection methodology.
  • Experience working alongside or governing a managed detection provider (MDR / MSSP).
  • Scripting and query fluency (Python, a SIEM query language such as KQL or SPL, and regex).
  • Excellent written and spoken English; this is our working language across a global team.

Nice to have

  • Industry certifications: GCDA, GCIA, GCDN, Splunk or Sentinel certifications, OSCP.
  • Familiarity with security frameworks (NIST CSF, MITRE ATT&CK).

Company offers

  • Health insurance from the first day of employment.
  • Monthly allowance and annual bonus.
  • Hybrid work schedule: 3 days on site and 2 days working from home.