Our mission is to help people integrate technology into everyday life and to enable innovation through technology. We offer software development and infrastructure solutions, with advanced competences in Blockchain, Artificial Intelligence and Machine Learning. All our offices (in Western Europe or nearshore, in CEE) are located within the boundaries of the European Union. We believe working in close cooperation with our clients and employees is the key to success; this means we offer people the best working environment in order to achieve the best results. We love entrepreneurial spirits and encourage people around us to be proactive and make the best decisions not only for business, but for their own personal development. Our nearshore Romanian offices are in Bucharest (Victoriei Square) and Iasi (Palace) and, with over 9000 team members at group level, we make sure we are always close to our customers.
Role Overview:
The Security Engineer - Detection & Response is responsible for building,
maintaining, and continuously improving the technical capabilities that support
Cyber Detection & Response.
The role ensures strong detection coverage, reliable operational pipelines, and
effective engineering support for both security monitoring and incident response.
The role focuses on implementing prioritized detection use cases end to end,
including observability, telemetry pipelines, correlation, enrichment, automation,
and the integrations required to operationalize them for SOC and CSIRT teams.
It also provides hands-on engineering support for response automation and
orchestration, helping improve the speed, quality, and efficiency of investigative
and response workflows.
Key Responsibilities:
1. Detection Engineering
- Design, build, and maintain high-fidelity detections across SIEM, XDR, EDR, identity, network, cloud, and data security telemetry sources.
- Correlate security telemetry with broader datasets to identify advanced threat actor tactics, techniques, and procedures (TTPs).
- Author, optimize, and maintain detection logic, including SQL-based and platform-native detection rules.
- Tune alerts continuously to reduce false positives and improve the signal-to-noise ratio for the 24/7 SOC.
- Replicate and adapt detection use cases across multiple business units, brands, and security tool tenants.
2. Security Automation and Orchestration
- Build, maintain, and troubleshoot Tines workflows and orchestrated playbooks to automate alert triage, enrichment, escalation, containment, and closure.
- Develop and maintain ChatOps and SecBot-driven response automations integrated with collaboration platforms such as Slack.
- Improve and support automation that enhances incident response efficiency, including enrichment workflows, notification pipelines, and dashboard reliability.
- Explore and prototype AI-assisted security workflows, such as automated malware analysis, alert correlation, and investigation support.
3. Telemetry Onboarding and Data Pipeline Engineering
- Engineer and maintain security data pipelines to ensure events are enriched with relevant context such as identity, asset, and geolocation data before reaching incident response teams.
- Onboard new telemetry and log sources into the detection pipeline.
- Validate log quality, perform cleanup where needed, and ensure schema alignment with detection and analytics requirements.
- Expand telemetry coverage across new brands, business units, and environments.
4. Incident Response Engineering Support
- Provide engineering support during security incidents, including automation of containment actions, escalation routing, and forensic data enrichment.
- Build and operate technical workflows that improve incident handling speed, consistency, and accuracy.
5. Platform Reliability and Operational Readiness
- Ensure the availability, effectiveness, quality, and resilience of SOC and CSIRT tooling, pipelines, and detection engineering capabilities.
- Proactively identify, troubleshoot, and urgently resolve issues affecting detections, alerting, integrations, automations, enrichments, dashboards, and Tines applications.
- Maintain the health and continuity of the SOC and CSIRT operational pipeline.
6. Monitoring and Process Improvement
- Continuously improve security monitoring operations, including alert filtering, notification clustering, queue handling, and escalation logic.
- Identify and implement engineering solutions that improve SOC and incident response efficiency, including automation of manual activities and system tuning.
- Improve support for after-hours, holiday, and high-volume monitoring scenarios.
- Design and implement recurring operational and stakeholder reporting.
7. Documentation and Continuous Improvement
- Create and maintain technical documentation, runbooks, and operational procedures related to detection engineering and security operations.
- Contribute to technology evaluations, tooling improvements, and core infrastructure modernization initiatives.
- Present innovation initiatives and technical improvements to relevant security stakeholders.
Requirements
Technical Skills & Experience
- Proven experience in detection engineering, with hands-on work designing and maintaining detections across SIEM, XDR, EDR, identity, network, cloud, and data security telemetry sources
- Strong knowledge of threat actor TTPs and experience correlating security telemetry across multiple data sources to identify advanced threats
- Proficiency writing and optimizing detection logic, including SQL-based queries and platform-native detection rules
- Experience tuning alerts and reducing false positives in a 24/7 SOC environment
- Experience replicating/adapting detection use cases across multiple business units, brands, or tool tenants
Automation & Orchestration
- Hands-on experience with Tines (or similar SOAR platforms) building and troubleshooting workflows/playbooks
- Experience with ChatOps/bot-driven response automation integrated with Slack or similar collaboration tools
- Experience developing automation for alert triage, enrichment, escalation, containment, and case closure
- Familiarity with AI-assisted security workflows (e.g., automated malware analysis, alert correlation, investigation support) is a plus
Data Pipeline & Telemetry Engineering
- Experience engineering and maintaining security data pipelines, including enrichment with identity, asset, and geolocation context
- Experience onboarding new log/telemetry sources into detection pipelines
- Strong understanding of log quality validation, schema alignment, and data cleanup practices
- Experience scaling telemetry coverage across new environments, brands, or business units
Incident Response Support
- Experience providing engineering support during live security incidents
- Ability to build/operate workflows that improve IR speed, consistency, and accuracy, including automated containment and escalation routing
Platform Reliability & Operations
- Experience ensuring uptime, resilience, and reliability of SOC/CSIRT tooling, pipelines, and detection capabilities
- Strong troubleshooting skills; ability to proactively identify and urgently resolve issues in detections, integrations, automations, and dashboards
- Experience maintaining operational continuity of SOC/CSIRT pipelines
Process Improvement & Reporting
- Experience improving monitoring processes: alert filtering, notification clustering, queue management, escalation logic
- Track record of identifying and implementing engineering solutions that increase SOC/IR efficiency
- Experience designing recurring operational/stakeholder reports
- Experience supporting after-hours, holiday, or high-volume monitoring scenarios
Documentation & Collaboration
- Strong technical documentation skills (runbooks, operational procedures)
- Experience contributing to tooling evaluations and infrastructure modernization initiatives
- Ability to present technical improvements/innovation initiatives to security stakeholders
- Strong cross-functional collaboration skills (SOC, CSIRT, engineering teams)
Once on board we offer various programs and benefits:
- 22 annual vacation days, 3 sick days that are not carried to the next year (no medical certificate required)
- A seniority day is added every 3 years in the company
- Floating days - free day for every public holiday that falls on the weekend, with the exception of holidays which always fall during the weekend
- Annual Company Bonus prorated according to the number of worked months in a year
- Private medical insurance
- Access to an online benefit platform, with a monthly allowance of 690 RON, which you can choose to invest in different wellbeing, financial, or retail packages
- Financial support for the birth of your child or unhappy events
- A work culture based on cooperation and development - customized learning paths through external providers as well as special development programs.
- We offer remote work flexibility, driven by smart working principles and aligned with team goals and values
- Wellbeing initiatives to encourage a healthy work life balance through webinars, specialized sessions and internal programs, per our colleagues’ input