Stefanini
Posted 4w ago

Security Engineer - Detection & Response

Stefanini
Bucharest, Bucharest, Romania
HybridFull Time
Responsibilities
  • building detections
  • automating responses
  • engineering pipelines
Requirements
  • 3–5 years in security
  • Detection
  • SOC engineering, or security operations
  • Advanced detection
  • Telemetry pipeline
  • SIEM/XDR/EDR, Tines, SOAR
  • Incident response, and automation experience
  • Excellent English required
Technical tools mentioned
Microsoft SentinelMicrosoft Defender XDRSplunkQRadarCrowdStrikeTinesSlackSQLSIEMXDREDRSOAR

Job description

Job Description





The Security Engineer - Detection & Response is responsible for building, maintaining, and continuously improving the technical capabilities that support Cyber Detection & Response.

The role ensures strong detection coverage, reliable operational pipelines, and effective engineering support for both security monitoring and incident response.

The role focuses on implementing prioritized detection use cases end to end, including observability, telemetry pipelines, correlation, enrichment, automation, and the integrations required to operationalize them for SOC and CSIRT teams.

It also provides hands-on engineering support for response automation and orchestration, helping improve the speed, quality, and efficiency of investigative and response workflows.

Key Responsibilities:

Detection Engineering

  • Design, build, and maintain high-fidelity detections across SIEM, XDR, EDR, identity, network, cloud, and data security telemetry sources.
  • Correlate security telemetry with broader datasets to identify advanced threat actor tactics, techniques, and procedures (TTPs).
  • Author, optimize, and maintain detection logic, including SQL-based and platform-native detection rules.
  • Tune alerts continuously to reduce false positives and improve the signal-to-noise ratio for the 24/7 SOC.
  • Replicate and adapt detection use cases across multiple business units, brands, and security tool tenants.

Security Automation and Orchestration

  • Build, maintain, and troubleshoot Tines workflows and orchestrated playbooks to automate alert triage, enrichment, escalation, containment, and closure.
  • Develop and maintain ChatOps and SecBot-driven response automations integrated with collaboration platforms such as Slack.
  • Improve and support automation that enhances incident response efficiency, including enrichment workflows, notification pipelines, and dashboard reliability.
  • Explore and prototype AI-assisted security workflows, such as automated malware analysis, alert correlation, and investigation support.

 

Telemetry Onboarding and Data Pipeline Engineering

  • Engineer and maintain security data pipelines to ensure events are enriched with relevant context such as identity, asset, and geolocation data before reaching incident response teams.
  • Onboard new telemetry and log sources into the detection pipeline.
  • Validate log quality, perform cleanup where needed, and ensure schema alignment with detection and analytics requirements.
  • Expand telemetry coverage across new brands, business units, and environments.

 

Incident Response Engineering Support

  • Provide engineering support during security incidents, including automation of containment actions, escalation routing, and forensic data enrichment.
  • Build and operate technical workflows that improve incident handling speed, consistency, and accuracy.

 

Platform Reliability and Operational Readiness

  • Ensure the availability, effectiveness, quality, and resilience of SOC and CSIRT tooling, pipelines, and detection engineering capabilities.
  • Proactively identify, troubleshoot, and urgently resolve issues affecting detections, alerting, integrations, automations, enrichments, dashboards, and Tines applications.
  • Maintain the health and continuity of the SOC and CSIRT operational pipeline.

 

Monitoring and Process Improvement

  • Continuously improve security monitoring operations, including alert filtering, notification clustering, queue handling, and escalation logic.
  • Identify and implement engineering solutions that improve SOC and incident response efficiency, including automation of manual activities and system tuning.
  • Improve support for after-hours, holiday, and high-volume monitoring scenarios.
  • Design and implement recurring operational and stakeholder reporting.

 

Documentation and Continuous Improvement

  • Create and maintain technical documentation, runbooks, and operational procedures related to detection engineering and security operations.
  • Contribute to technology evaluations, tooling improvements, and core infrastructure modernization initiatives.
  • Present innovation initiatives and technical improvements to relevant security stakeholders.



Job Requirements



Education:

  • Preferred: Bachelor's degree in computer science, Information Technology, Engineering, Business Administration or a related field.

Language proficiency:

  • Excellent English communication skills, both verbal and written, for professional communication and documentation.

Experience:

  • Minimum 3–5 years of hands-on experience in Security Engineering, Detection Engineering, SOC Engineering, or Security Operations, with a strong focus on detection development, security monitoring, and incident response.
  • Advanced experience designing, implementing, and optimizing security detections, alerting strategies, and telemetry pipelines across enterprise environments, including cloud, network, endpoint, identity, and SIEM platforms.
  • Advanced experience developing and maintaining security automation and orchestration workflows, including SOAR playbooks (preferably Tines) to improve incident response, alert triage, enrichment, and operational efficiency.
  • Advanced experience collaborating with SOC, Incident Response, and Engineering teams to support security investigations, continuously improve detection capabilities, and implement operational best practices through documentation, reporting, and process optimization.

Mandatory Technical skills:

  • Advanced experience with SIEM/XDR/EDR technologies (e.g., Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike) and developing detection rules.
  • Advanced experience with Tines (or similar workflow automation platforms) to build, maintain, and troubleshoot security automation workflows and orchestrated playbooks.
  • Ability to understand security telemetry, log ingestion, normalization, and data pipeline engineering, including onboarding new log sources, schema mapping, and data enrichment.
  • Strong knowledge of cybersecurity frameworks and incident response practices, including, threat detection methodologies, automation, and security monitoring across cloud and hybrid environments.

Soft skills:

  • Excellent interpersonal and communication skills to share knowledge and to communicate effectively with different stakeholders (IT and business partners).
  • Highly disciplined and motivated: a self-starter who can both work independently or as a member of a team.
  • Ability to demonstrate a Can-Do, delivery-focused and solution-oriented approach (rather than problem-oriented).
  • Flexible, practical, and positive mindset.
  • Ability to quickly adapt to changing situations.
  • Ability to constantly demonstrate ownership and proactiveness in seeking to improve and optimize in anything related to their and their team's work.

Work conditions:

  • Working hours: normal business hours.
  • Offers on-call support during the nights, weekends and public holidays.
  • Working setup: hybrid.

Diversity & Inclusion

Here at the Stefanini Group, we value plurality and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, and nationality. We understand and encourage the importance of being you!

About Stefanini

Global provider of digital transformation and IT solutions.

Similar jobs

Security Engineer roles near Bucharest, Bucharest
1w
Save
Mark Applied
Hide
Senior Security Engineer
Bucharest, Bucharest, Romania
lei18k-lei22k/mo HybridFull Time
ORTEC
ORTEC: Provides data-driven supply chain optimization software and advisory services.
Hands-on security professional with a solid security foundation, technical problem-solving skills, and experience or interest in Azure, Microsoft 365, Entra ID, endpoint security, vulnerabilities, incident response, or monitoring.
Microsoft Azure, Microsoft 365, Entra ID, XDR, PKI
1w
Save
Mark Applied
Hide
Senior Security Engineer
Bucharest, Bucharest, Romania
lei18k-lei22k/mo HybridFull Time
ORTEC
ORTEC: A global technology providing software solutions and analytics for diverse industries.
Hands-on security professional with a strong technical foundation and experience or interest in Azure, Microsoft 365, Entra ID, endpoint security, vulnerability management, incident response, or security monitoring.
Microsoft Azure, Microsoft 365, Entra ID, XDR
1w
Save
Mark Applied
Hide
Incident Response Analyst II (Hybrid, Bucharest)
Bucharest, Bucharest, Romania
HybridFull Time
CrowdStrike
CrowdStrikeNASDAQ: CRWD: Provides cloud-native endpoint protection and cybersecurity services.
Incident response experience in a SOC, CSIRT, or incident response team; software development with Python or Go; automation, APIs, integrations, cloud platforms, Linux, networking, authentication, and enterprise security knowledge.
Python, Go, AWS, Azure, Google Cloud, Linux, GitLab CI, GitHub Actions, Jenkins, Docker, Kubernetes, Terraform, SIEM, EDR, SOAR, MITRE ATT&CK
3w
Save
Mark Applied
Hide
Senior Security Engineer, Enterprise Security
Chicago or New York City or Austin or Berlin or Bucharest or Dubai or Jakarta or London or Paris or San Francisco or São Paulo or Singapore or Seoul or Sydney or Tokyo
$129k-$180k/yr HybridFull Time
Braze
BrazeNASDAQ: BRZE: Platform for personalized customer engagement and cross-channel messaging.
5+ YOE5+ years security engineering experience, 3+ years in corporate security, hands-on endpoint, network, IAM, SSO, MDM, CrowdStrike EDR, SIEM, forensics, and SaaS security experience.
Crowdstrike EDR, SIEM, IAM, SSO, MDM
4w
Save
Mark Applied
Hide
Security Engineer - Detection & Response
Bucharest, Bucharest, Romania
HybridFull Time
Stefanini
Stefanini: Global provider of IT consulting and digital business solutions.
3+ YOERequires 3–5 years of security engineering or SOC experience, advanced detection and automation skills, SIEM/XDR/EDR expertise, Tines experience, telemetry pipeline knowledge, and excellent English communication.
SIEM, XDR, EDR, Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike, Tines, SQL, Slack
4w
Save
Mark Applied
Hide
Security Engineer - Node.js Proactive Defense (worldwide remote, work anywhere)
Bucharest or Europe
RemoteFull Time
CloudLinux
CloudLinux: Provides security, stability, and live patching for Linux servers.
Experienced engineer with Node.js and JavaScript expertise, strong web application security knowledge, detection-at-scale experience, and ability to act as PM/architect/lead for a new runtime-protection product.
Node.js, JavaScript
3mo
Save
Mark Applied
Hide
Grid Technologies
Bucharest, Bucharest, Romania
HybridFull Time
Siemens Energy
Siemens EnergyXetra: ENR: Designs and manufactures energy technology and power generation equipment.
Degree or equivalent experience in engineering/IT, professional OT/industrial automation experience, knowledge of Windows Server/Active Directory/WSUS, hands-on PLC and automation experience, familiarity with IEC 62443 or similar.
Windows Server, Active Directory, WSUS, Siemens Step7, TIA Portal, Beckhoff TwinCAT, PLCs
1w
Save
Mark Applied
Hide
Network Security Engineer - Telco Virtual Firewalls
Bucharest, Bucharest, Romania
OnsiteFull Time
Infosys
InfosysNYSE: INFY: Provides IT consulting, software development, and business outsourcing services.
5+ YOERequires 5–12 years in network security, Palo Alto virtual firewalls, Telco cloud/NFV, networking, HA design, troubleshooting, and ITIL-aligned operations; certifications such as PCNSE, CCNP, or CCIE preferred.
Palo Alto, VM-Series, CN-Series, Panorama, OpenStack, Kubernetes, BGP, IPSec, SSL VPN, Python, Ansible, REST APIs, TCP/IP, NAT, ITIL, SDN, NFV, ETSI, 5G, LTE