Detection & Response Platform Lead

Team Blue
Barcelona, Spain
10 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Apple Mac Systems Software as a Service Cyber Security Linux DevOps Intrusion Detection and Prevention Windows Servers Software Vulnerability Management SentinelOne Expertise

Job description

Experteer Overview As Detection u**amp; Response Platform Lead, you drive the endpoint security strategy and scale detection capabilities across team.blue’s infrastructure.You own detection and response platforms, optimize configurations, and partner with DevOps, Vulnerability Management, and SaaS teams to cut alert noise and strengthen preventive controls.You’ll engineer scalable detection, automate workflows, and lead threat-informed improvements across a distributed security organization.This role shapes the future of team.blue’s Security Operations with impact across multiple brands and markets.Compensaciones / Beneficios * Own strategic direction and optimization of detection u** response platforms across team.blue infrastructure * Maintain and improve services by reviewing incidents and collaborating with vendors * Monitor alert trends and tune detection policies to improve true positive rates and reduce alert fatigue * Conduct threat hunting to identify gaps in detection coverage and validate efficacy * Develop custom detection rules using threat intelligence, hunting findings, and incident learnings * Collaborate with Operations, Infrastructure, and Vulnerability Management to enforce protection standards * Provide threat context to upstream teams to reduce alert volume and improve preventive controls * Document detection logic, playbooks, runbooks, and configuration standards * Share detection content and learnings within team.blue * Stay current on endpoint threat landscape, techniques, and detection methods * Implement blameless postmortems after incidents to drive continuous improvement Responsabilidades * 5+ years in technical security roles (security operations, detection engineering, incident response, or security-focused system administration) * Endpoint security expertise across Windows Server, Linux, and macOS * Experience developing detection rules, alerts, and response workflows * Hands-on EDR/XDR experience (SentinelOne experience valued) * Threat analysis skills to interpret attacker TTPs and translate to detections * Collaborative, cross-functional experience with IT, DevOps, and business teams * Strong English communication skills Requisitos principales * remote-first flexibility * hybrid or office-based work * work-life balance * minimal travel * join a distributed security team * inclusive culture

Requirements

drive continuous improvement Responsabilidades * 5+ years in technical security roles (security operations, detection engineering, incident response, or security-focused system administration) * Endpoint security expertise across Windows Server, Linux, and macOS * Experience developing detection rules, alerts, and response workflows * Hands-on EDR/XDR experience (SentinelOne experience valued) * Threat analysis skills to interpret attacker TTPs and translate to detections * Collaborative, cross-functional experience with IT, DevOps, and business teams * Strong English communication skills Requisitos principales * remote-first flexibility * hybrid or office-based work * work-life balance * minimal travel * join a distributed security team * inclusive culture

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

6:03 min

Engaging software developers deeply in secure engineering practices

Tanya Janca · World Congress 2021

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

Videos

See all

Related articles

See all