> Markdown version of [/jobs/ext/5489-staff-security-engineer-security-data-detection-and-automation](https://www.wearedevelopers.com/jobs/ext/5489-staff-security-engineer-security-data-detection-and-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Security Engineer - Security Data, Detection and Automation - **Company:** Nscale - **Location:** Amer, Spain - **Salary:** €180,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing, Cyber Security, Continuous Integration, Information Engineering, Domain Name System (DNS), Identity and Access Management, Intrusion Detection and Prevention, Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, Mitre Att&ck, Cybercrime, Data Pipelines, Security Orchestration, Automation & Response - **Published:** May 18, 2026 - **Apply:** https://es.indeed.com/viewjob?jk=2e3f60ce18acfb36 ## About the Role Do you have experience in SoC?, * 8+ years in detection engineering, security data engineering, SIEM engineering, security automation, incident response engineering, or similar roles. * Strong hands-on experience with SIEM, security analytics, log management, or detection platforms. * Strong ability in coding, scripting, querying, or detection-content development. * Experience building detection logic from host, identity, cloud, SaaS, network, DNS, proxy, EDR, vulnerability, or application telemetry. * Experience with detection testing, threat hunting, incident response, alert tuning, and runbook development. * Ability to design scalable data pipelines, enrichment flows, or automations. * Strong understanding of attacker TTPs, MITRE ATT&CK, identity attacks, cloud attacks, endpoint telemetry, and insider-threat indicators. * Experience with SOAR, case management, detection-as-code, GitOps, CI/CD, or automated detection testing is preferred. * Experience measuring MDR, SOC, or managed detection provider performance is preferred. * Experience using AI or agentic workflows to improve triage, enrichment, investigation, or detection validation with guardrails is preferred. ## Description We are hiring a Senior Staff Engineer - Security Data, Detection and Automation to build the telemetry, detection, response automation, case-quality metrics, and reporting foundation for an increasingly Nscale-owned SOC capability. This role sits at the intersection of security engineering, data engineering, detection engineering, and security operations. You will work across endpoint, identity, SaaS, cloud, network, vulnerability, and production access domains, partnering closely with security leadership as well as adjacent teams shaping identity and vulnerability management requirements. Your impact will be strategic and measurable. The focus is not to create more alerts, but to turn raw telemetry into reliable, explainable, high-signal security outcomes that strengthen internal ownership of detection logic, containment decisions, runbooks, executive metrics, case quality, and automation., * Design security telemetry architecture across endpoint security, security analytics, identity platforms, SaaS systems, cloud platforms, vulnerability tools, endpoint inventory, and production access systems. * Build a telemetry source map covering ownership, data quality, retention, coverage, priority use cases, and known gaps. * Establish data quality, parser quality, ingestion health, field normalization, and source ownership standards. * Create daily source-health reporting and scoring for SIEM or security analytics data quality. Detection Engineering and Threat Coverage * Own the detection engineering lifecycle from hypothesis and data source selection through logic, testing, tuning, ownership, runbook, expiry, and metrics. * Define high-value detection use cases across identity, endpoint, SaaS, cloud, and production access. * Develop detections with documented test logic, runbooks, data dependencies, and case-quality criteria. * Apply TTP-led threat modeling across corporate, cloud, production, identity, SaaS, endpoint, insider, and AI-agent risk scenarios. * Validate detection coverage through attack simulation or other coverage-testing approaches. Automation and Operational Improvement * Build SOAR and automation workflows that enrich alerts, suppress low-value noise, route cases, and improve analyst decision-making. * Design scalable data pipelines, enrichment flows, and automations that improve operational quality. * Implement detection-as-code or version-controlled detection content where practical. * Use automation to improve the consistency, explainability, and actionability of security outcomes. SOC Performance and Reporting * Measure MDR/SOC performance using case-quality metrics such as false positive rate, time to triage, time to containment, evidence completeness, and escalation quality. * Create a MDR/SOC case-quality review loop for internal and external stakeholders. * Produce security dashboards and executive reporting that connect security operations to measurable risk reduction. * Improve alert explainability so analysts and leaders can understand why detections fired and what actions matter most. Cross-Functional Partnership * Partner with security leadership to strengthen internal ownership of detection logic, containment decisions, runbooks, executive metrics, and automation. * Collaborate with Identity and Vulnerability Management hires to define production-access, privileged-access, and exposure-driven detection requirements. * Connect engineering and operational stakeholders around shared standards for telemetry quality, response workflows, and detection effectiveness., The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)