×
Register Here to Apply for Jobs or Post Jobs. X

Detection & Response Platform Lead

Job in 50010, Trespiano, Toscana, Italy
Listing for: team.blue
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Location: Trespiano

team.blue is an ecosystem of 60+ successful brands working together across 22 European countries to provide its 3.5 million SMB customers with everything they need to succeed online by offering best-in-class expertise and services.team.blue's brands are a mix of traditional hosting businesses that offer services from domain names, email, shared hosting, e-commerce, and server hosting solutions and, as specialist SaaS providers, adjacent products such as compliance, marketing tools, and team collaboration products.

This broad product offering makes it a one-stop partner for online businesses and entrepreneurs across Europe.

The role

We are looking for a Detection & Response Platform Lead to drive our endpoint security strategy and evolve our detection capabilities s is an opportunity to shape the future of teamb.blue’s Security Operations.

You will own our detection and response platforms as the foundation, while building scalable detection solutions, automating workflows, and collaborating across Dev Ops, Operations, and SaaS portfolio companies to reduce threats upstream.

Your objectives are:

Strategically manage our endpoint detection platforms – Own detection & response platforms configurations, optimization, and vendor relationships to maximize detection efficacy across team.blue infrastructure

Engineer scalable detection solutions – Automate alert triage and enrichment, and continuously improve detection coverage

Drive cross-functional influence – Partner with Dev Ops, vulnerability management, and SaaS companies to reduce alert volume by strengthening preventive controls and threat modeling upstream

The position can be based anywhere within the EU as fully remote or hybrid working from one of our many offices.

Your Responsibilities Platform Ownership & Strategy Own the strategic direction, configuration, and optimization of detection & response platforms across team.blue infrastructure

Maintain and continuously improve the services, reviewing incidents and collaborating with the vendor to enhance service quality

Monitor alert trends and tune detection policies to optimize true positive rates while reducing alert fatigue

Detection Engineering & Automation Conduct threat hunting to identify gaps in detection coverage and validate detection efficacy

Build custom detection rules based on threat intelligence, hunting findings, and incident learnings

Cross-Functional Collaboration & Influence Partner with Operations and Infrastructure teams to ensure consistent endpoint protection standards

Work with vulnerability management to prioritize patching based on active threats and detection findings

Provide threat context to upstream teams to improve preventive controls and reduce alert volume

Continuous Improvement & Knowledge Sharing Implement blameless postmortems after incidents to drive continuous improvement

Sharing detection content and learnings within team.blue Document detection logic, playbooks, runbooks, and configuration standards

Stay current on endpoint threat landscape, attack techniques, and detection methodologies

Your Skillset Required Experience & Skills5+ years in technical security roles – security operations, detection engineering, incident response, or system administration with security focus

Endpoint security expertise – Good understanding of operating systems such as Windows (Server), Linux, and macOSDetection engineering capabilities – Experience developing detection rules, alerts, and response workflows

Hands-on EDR/XDR experience – Practical experience with EDR platforms (Sentinel One experience valued)
Threat analysis skills – Ability to analyze attack patterns, understand attacker TTPs, and translate to detections

Collaborative approach – Experience working across organizational boundaries with IT, Dev Ops, and business teams

Good English – Both verbal and written communication skills

Nice to Have Automation mindset – Scripting skills (Power Shell, Python) and enthusiasm for automating repetitive tasks

Security certificationsSOC/MDR service experience – Working with external SOC or MDR providersMITRE ATT&CK knowledge – Practical experience mapping detections to the MITRE ATT&CK framework

Clo…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary