Staff Security Engineer - Detection & Response (w/m/d)

JTL-Software GmbH

United States

Remote

USD 135,000 - 203,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Meal allowance
Home office setup
Wellpass
JobRad
Pension plan
Capital-forming payments
Team events

Job summary

JTL-Software GmbH is expanding its security team with a Staff-level role responsible for owning the SIEM, developing detection content, and leading incident response. You will influence tooling, architecture, and standards while working closely with external partners.

This is a senior, IC role reporting to the Director Cybersecurity & IT. Key tasks include onboarding data sources, tuning detections, incident response leadership, and rolling out hardening baselines across endpoints and cloud.

Qualifications

  • Built or substantially rebuilt a detection capability.
  • Written and tuned production SIEM detections and fluent in its query language.
  • Investigated security incidents from start to finish.
  • Designed and rolled out a hardening baseline.
  • Scripting for automation with PowerShell or Python.
  • Set technical standards followed by others without formal authority.
  • Fluent English, written and spoken.

Responsibilities

  • Own the SIEM platform from implementation partner to production-ready state.
  • Develop detection content and ensure coverage against relevant techniques.
  • Lead end-to-end incident investigations and proactive threat hunting.
  • Design and roll out security baselines across endpoints, servers, identity, and cloud.
  • Manage external security partners and decide on tooling and cost implications.

Skills

Detection capability build
Detection content tuning
Incident response
Hardening baseline
Automation scripting
Influence without authority
Fluent English

Tools

PowerShell
Python

Job description

Your mission

JTL-Software builds the e-commerce software our customers run their businesses on. As the platform and the business grow, we are expanding our security team.
This is a newly created Staff-level position with end-to-end ownership of that area. You will own our SIEM and the detection content that runs on it, lead security investigations from first alert to resolution, and set the hardening standard across endpoints, identity, servers and cloud. You will also own the engineering relationship with the external partners who support us.
We are looking for someone who has built a detection capability. Our environment is predominantly Microsoft and Azure, and you will have genuine influence over the tooling, the architecture and the standards we adopt instead of maintaining decisions that were made before you arrived.
This is a senior individual contributor role. You set the detection and hardening standard for the security team, you work without a technical lead above you, and you report directly to the Director Cybersecurity & IT.

Build and own the SIEM
  • Take ownership of the platform from the implementation partner, to a depth that allows you to defend or revise its design decisions
  • Own data source onboarding, parsing, normalisation and coverage
  • Make and justify explicit decisions on log coverage, retention and ingest cost
  • Develop the platform as the estate grows, rather than leaving it as delivered
Detection engineering
  • Write, tune and maintain the detection content, beyond the vendor's default rule set
  • Map coverage against the techniques relevant to our estate and close the gaps that matter
  • Treat detections as code: version control, review, testing, and a defined process for false positives
  • Convert offensive security findings into detections
Incident response
  • Investigate and lead the technical side of security incidents end to end
  • Threat hunting against our own telemetry, proactively rather than in response to a report
  • Own the technical half of the incident response process and refine it after each event
Hardening
  • Design and roll out security baselines across endpoints, servers, identity and cloud
  • Work with IT and engineering to get them applied, including where that requires making the case
  • Measure configuration drift and close it
Partners and tooling
  • Own the engineering relationship with our external security partners: scope, escalation and expectations
  • Make build-versus-buy decisions on detection and response tooling, including the cost implications
Your profile
  • You have built or substantially rebuilt a detection capability, rather than only operating one designed by someone else
  • You have written and tuned detection content in a production SIEM yourself, and are fluent in its query language
  • You have personally investigated real security incidents from start to finish
  • You have designed and rolled out a hardening baseline
  • You script to a level where automation is your default: PowerShell, Python or equivalent
  • You have set a technical standard that others followed, without formal authority over them
  • Fluent English, written and spoken
Why us?
  • Remote-first within Germany, with the option to work remotely from eligible countries for up to 180 days per year
  • Meal allowance of up to €115 net per month
  • Ergonomic workspace allowance for your home office setup
  • Regular team events, company-wide gatherings, and summer and Christmas parties to stay connected as a remote-first company
  • EGYM Wellpass and JobRad subsidy
  • Financial benefits including capital-forming payments (Vermögenswirksame Leistungen) and a company pension scheme
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Detection & Response Security Engineer (SIEM)
Staff Detection & Response Security Engineer (SIEM)

JTL-Software GmbH • United States

Remote
USD 135,000 - 203,000
Meal allowance
Home office setup
Wellpass
+4
Product Security Engineer
Product Security Engineer

Talon.One • Berlin (NH)

Hybrid
USD 101,000 - 147,000
Learning budget
Language courses
30 days annual leave
+6
Cyber Defense Engineer
Cyber Defense Engineer

BeyondTrust, Inc. • United States

Remote
USD 87,000 - 134,000
Bupa healthcare
Parental leave
Employee Assistance Programme
+5
Network & Security Engineer - 2nd Level Incident Response
Network & Security Engineer - 2nd Level Incident Response

Anqa IT-Security GmbH • United States

Hybrid
USD 60,000 - 80,000
Flexible Arbeitszeiten
Homeoffice-Möglichkeiten
Betriebliche Altersvorsorge
+1
Security Operations Center Specialist (m/f/x)
Security Operations Center Specialist (m/f/x)

Liebherr-IT Services GmbH • Delaware

Hybrid
USD 68,000 - 102,000
Attraktives Gehalt & Sozialleistungen
Flexibles hybrides Arbeiten
Gestaltungsfreiraum
+8
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
(Senior) IT Support Engineer
(Senior) IT Support Engineer

Orcrist Technologies GmbH • United States

Remote
USD 69,000 - 104,000
Remote-first
Home-office budget
30 days vacation
+5
Gruppen Informationssicherheitsbeauftragter (m/f/d)
Gruppen Informationssicherheitsbeauftragter (m/f/d)

orcristtechnologies • United States

Remote
USD 180,000 - 240,000
Remote-first across Europe
Home-office budget
30 days vacation
+2
GERMAN SPEAKING SECURITY ENGINEER
GERMAN SPEAKING SECURITY ENGINEER

LITIT • United States

Hybrid
USD 64,000 - 95,000
Remote work opportunities
Office in Vilnius
Flexible time off
+4
Cloud Engineer – AWS, IoT & AI in Agile Global Team
Cloud Engineer – AWS, IoT & AI in Agile Global Team

QUNDIS GmbH • Kentucky

Hybrid
USD 80,000 - 100,000
Performance-based compensation
Professional development opportunities
Team events