> Markdown version of [/jobs/ext/2074921-detection-response-platform-lead](https://www.wearedevelopers.com/jobs/ext/2074921-detection-response-platform-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Detection & Response Platform Lead - **Company:** team - **Location:** Gent, Belgium (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Cyber Security, Linux, DevOps, Domain Name System (DNS), Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Software Vulnerability Management, Scripting, Google Cloud, Cloud Platform System, Mitre Att&ck, SentinelOne Expertise - **Published:** August 16, 2026 - **Apply:** https://www.careerjet.be/jobad/be5fb0124aa335e5ad79180d8071679470 ## About the Role 5+ years in technical security roles - security operations, detection engineering, incident response, or system administration with security focus Endpoint security expertise - Good understanding of operating systems such as Windows (Server), Linux, and macOS Detection engineering capabilities - Experience developing detection rules, alerts, and response workflows Hands-on EDR/XDR experience - Practical experience with EDR platforms (SentinelOne experience valued) Threat analysis skills - Ability to analyze attack patterns, understand attacker TTPs, and translate to detections Collaborative approach - Experience working across organizational boundaries with IT, DevOps, and business teams Good English - Both verbal and written communication skills Nice to Have Automation mindset - Scripting skills (PowerShell, Python) and enthusiasm for automating repetitive tasks Security certifications SOC/MDR service experience - Working with external SOC or MDR providers MITRE ATT&CK knowledge - Practical experience mapping detections to the MITRE ATT&CK framework Cloud security knowledge - Understanding of cloud environments (Azure, AWS, GCP) and their security models Multi-tenant experience - Working in SaaS or MSP environments supporting multiple organizations ## Description is an ecosystem of 60+ successful brands working together across 22 European countries to provide its 3.5 million SMB customers with everything they need to succeed online by offering best-in-class expertise and services. 's brands are a mix of traditional hosting businesses that offer services from domain names, email, shared hosting, e-commerce, and server hosting solutions and, as specialist SaaS providers, adjacent products such as compliance, marketing tools, and team collaboration products. This broad product offering makes it a one-stop partner for online businesses and entrepreneurs across Europe. The role We are looking for a Detection & Response Platform Lead to drive our endpoint security strategy and evolve our detection capabilities at scale. This is an opportunity to shape the future of 's Security Operations. You will own our detection and response platforms as the foundation, while building scalable detection solutions, automating workflows, and collaborating across DevOps, Operations, and SaaS portfolio companies to reduce threats upstream. Your objectives are: Strategically manage our endpoint detection platforms - Own detection & response platforms configurations, optimization, and vendor relationships to maximize detection efficacy across infrastructure Engineer scalable detection solutions - Automate alert triage and enrichment, and continuously improve detection coverage Drive cross-functional influence - Partner with DevOps, vulnerability management, and SaaS companies to reduce alert volume by strengthening preventive controls and threat modeling upstream The position can be based anywhere within the EU as fully remote or hybrid working from one of our many offices. Your Responsibilities Platform Ownership & Strategy Own the strategic direction, configuration, and optimization of detection & response platforms across infrastructure Maintain and continuously improve the services, reviewing incidents and collaborating with the vendor to enhance service quality Monitor alert trends and tune detection policies to optimize true positive rates while reducing alert fatigue Detection Engineering & Automation Conduct threat hunting to identify gaps in detection coverage and validate detection efficacy Build custom detection rules based on threat intelligence, hunting findings, and incident learnings Cross-Functional Collaboration & Influence Partner with Operations and Infrastructure teams to ensure consistent endpoint protection standards Work with vulnerability management to prioritize patching based on active threats and detection findings Provide threat context to upstream teams to improve preventive controls and reduce alert volume Continuous Improvement & Knowledge Sharing Implement blameless postmortems after incidents to drive continuous improvement Sharing detection content and learnings within Document detection logic, playbooks, runbooks, and configuration standards Stay current on endpoint threat landscape, attack techniques, and detection methodologies Your Skillset ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)