Detection & Response Platform Lead

team.blue Global
Remote

About The Position

team.blue is looking for a Detection & Response Platform Lead to drive their endpoint security strategy and evolve their detection capabilities at scale. This role offers the opportunity to shape the future of team.blue’s Security Operations by owning the detection and response platforms, building scalable detection solutions, automating workflows, and collaborating across DevOps, Operations, and SaaS portfolio companies to reduce threats upstream. The position can be based anywhere within the EU as fully remote or hybrid working from one of their many offices.

Requirements

  • 5+ years in technical security roles – security operations, detection engineering, incident response, or system administration with security focus
  • Endpoint security expertise – Good understanding of operating systems such as Windows (Server), Linux, and macOS
  • Detection engineering capabilities – Experience developing detection rules, alerts, and response workflows
  • Hands-on EDR/XDR experience – Practical experience with EDR platforms (SentinelOne experience valued)
  • Threat analysis skills – Ability to analyze attack patterns, understand attacker TTPs, and translate to detections
  • Collaborative approach – Experience working across organizational boundaries with IT, DevOps, and business teams
  • Good English – Both verbal and written communication skills

Nice To Haves

  • Automation mindset – Scripting skills (PowerShell, Python) and enthusiasm for automating repetitive tasks
  • Security certifications
  • SOC/MDR service experience – Working with external SOC or MDR providers
  • MITRE ATT&CK knowledge – Practical experience mapping detections to the MITRE ATT&CK framework
  • Cloud security knowledge – Understanding of cloud environments (Azure, AWS, GCP) and their security models
  • Multi-tenant experience – Working in SaaS or MSP environments supporting multiple organizations

Responsibilities

  • Own the strategic direction, configuration, and optimization of detection & response platforms across team.blue infrastructure
  • Maintain and continuously improve the services, reviewing incidents and collaborating with the vendor to enhance service quality
  • Monitor alert trends and tune detection policies to optimize true positive rates while reducing alert fatigue
  • Conduct threat hunting to identify gaps in detection coverage and validate detection efficacy
  • Build custom detection rules based on threat intelligence, hunting findings, and incident learnings
  • Partner with Operations and Infrastructure teams to ensure consistent endpoint protection standards
  • Work with vulnerability management to prioritize patching based on active threats and detection findings
  • Provide threat context to upstream teams to improve preventive controls and reduce alert volume
  • Implement blameless postmortems after incidents to drive continuous improvement
  • Sharing detection content and learnings within team.blue
  • Document detection logic, playbooks, runbooks, and configuration standards
  • Stay current on endpoint threat landscape, attack techniques, and detection methodologies

Benefits

  • Remote-first flexibility – Work fully remote within the EU, hybrid, or from one of our offices
  • Occasional team events or company gatherings
  • Healthy boundaries to prevent burnout and maintain sustainable performance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service