Cyber Detection Engineering Lead

Tesat-Spacecom GmbH & Co. KG
München, Germany
21 days ago
Apply on ag.wd3.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Microsoft Windows Software System Penetration Testing Cyber Security Computer Telephony Integration Linux Intrusion Detection and Prevention Python (Programming Language) Data Logging Cyber Threat Analysis Information Technology

Job description

  • Lead Detection Strategy: Define the long-term vision for detection engineering, aligning technical roadmaps with organizational risk profiles while standardizing the development lifecycle.
  • Engine & Rule Lifecycle Management: Architect, develop, maintain, and optimize high-fidelity detection rules for the SOC while expanding framework coverage against MITRE ATT&CK® and Sigma standards.
  • Threat Intelligence Translation: Analyze Cyber Threat Intelligence (CTI) and translate complex TTPs into proactive, resilient detection logic.
  • Automation & Orchestration: Drive “Detection-as-Code” initiatives and engineer automated response playbooks to streamline incident response and minimize manual intervention.
  • Technical Mentorship & Escalation: Act as the primary escalation point for complex technical issues, mentoring junior detection engineers and SOC analysts.
  • Cross-Functional Collaboration: Partner closely with Incident Response and SOC teams to ensure deployment of context-rich detections that enable rapid threat containment.

Requirements

  • Degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
  • Proven track record in developing use cases and detection logic within a Security Operations Center (SOC) environment, including leadership or mentorship experience.
  • Strong proficiency in Python and hands-on experience with automation frameworks to streamline operations.
  • Deep technical expertise in Windows and Linux operating systems, including OS internals, system logging, and telemetry analysis.
  • Practical background in Red Teaming, Penetration Testing, or an offensive mindset to anticipate attacker methodologies.
  • Advanced expertise with the MITRE ATT&CK® framework and Detection-as-Code concepts.
  • Strong communication skills with an empathetic, collaborative approach to leading cross-functional teams and technical initiatives., This job requires an awareness of any potential compliance risks and a commitment to act with integrity, as the foundation for the Company’s success, reputation and sustainable growth.

Benefits & conditions

  • Fair Compensation & Extras: Attractive remuneration and individual additional benefits, such as company pension schemes, mobility offers (e.g., bike leasing), or corporate discounts with partner companies in accordance with our current guidelines.
  • Time for You (and Your Loved Ones): 30 days of annual leave based on our collective agreement (35-hour week); work-life balance through flexible working hours (flextime), mobile working, part-time options, job sharing, and sabbatical opportunities.
  • Growth Made Easy: Excellent professional development opportunities and international, group-wide career perspectives.
  • Feel Good at Work: On-site company doctor; comprehensive health programs (sports courses, preventive care, etc.), canteen and cafeteria, and local childcare facilities at selected locations.
  • Diversity Connects: Work in a diverse environment with more than 140 nationalities, where exchange, mutual support, and inclusion are part of our DNA.

About the company

To support our Digital Security Team, Airbus Defence and Space division is seeking a highly skilled Leader Role for Detection Engineer (d/f/m). This is a critical, high-impact role designed to actively protect our entire organization and our world-class products.

This is a technical, hands-on position that sits at the heart of our defense strategy. You will not simply respond to alerts; you will be the architect of our detection ecosystem-transforming threat intelligence into high-fidelity detection logic and bridging the gap between raw telemetry and actionable security intelligence., Not a 100% match? No worries! Airbus supports your personal growth with customized development solutions., Airbus is committed to achieving workforce diversity and creating an inclusive working environment. We welcome all applications irrespective of social and cultural background, age, gender, disability, sexual orientation or religious belief.

Airbus is, and always has been, committed to equal opportunities for all. As such, we will never ask for any type of monetary exchange in the frame of a recruitment process. Any impersonation of Airbus to do so should be reported to emsom@airbus.com.

At Airbus, we support you to work, connect and collaborate more easily and flexibly. Wherever possible, we foster flexible working arrangements to stimulate innovative thinking.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on ag.wd3.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all