Detection Engineer

R&D Krakow , Poland


Description

Summary 
 
Data has never been more valuable and vulnerable. As cybercriminals become more sophisticated and regulations more strict, organizations struggle to answer one key question: “Is my data safe?"
At Varonis, we see the world of cybersecurity differently. Instead of chasing threats, we believe the most practical approach is protecting data from the inside out. We’ve built the industry’s first fully autonomous Data Security Platform to help our customers dramatically reduce risk with minimal human effort. 
 
At Varonis, we move fast. We’re an ultra-collaborative company with brilliant people who care deeply about the details. Together, we’re solving interesting and complex puzzles to keep the world’s data safe.
 
This is a 100% remote position 
 
We are seeking a highly skilled and motivated Detection Engineer to join our elite team. In this role, you will be responsible for researching emerging threats, designing and developing detection logic, and continuously improving security analytics that protect organizations around the globe.
As a Detection Engineer, you will transform threat research, real-world incidents, and customer feedback into scalable detection capabilities using our proprietary platform, You will work across the full detection lifecycle, from threat analysis and model design to validation, tuning, performance monitoring, and ongoing optimization.
You will collaborate closely with Forensics, Product Management, Engineering, and MDR teams to identify coverage gaps, refine existing detections, and deliver new security capabilities. Success in this role requires both a strong technical foundation and an investigative mindset, with the ability to translate attacker behavior into actionable detection logic.
The ideal candidate is comfortable working with large datasets, analyzing complex security scenarios, and making data-driven decisions to improve detection quality and customer outcomes. Experience with security monitoring, threat hunting, incident response, detection engineering, or SOC operations is highly valuable, along with hands-on experience of querying and analyzing large-scale data environments.
Beyond technical excellence, we are looking for someone who is curious, collaborative, and highly accountable. Strong communication skills, critical thinking, creativity, and a passion for solving difficult security problems are essential. This is an opportunity to make a significant impact on the future of security detection and help shape how modern threats are identified and stopped at scale.
Responsibilities
  • Research emerging threats, attacker techniques, and security trends, and translate them into scalable detection capabilities and security analytics.
  • Investigate detection gaps, real-world incidents to identify opportunities for improving coverage, accuracy, and customer outcomes.
  • Leverage diverse telemetry sources and security signals to identify malicious activity, improve threat visibility, and strengthen detection coverage across cloud, identity, SaaS, and data security environments.
  • Evaluate and improve the quality of existing detections by reducing false positives, increasing fidelity, and ensuring detections remain effective against evolving attacker techniques.
  • Contribute to strategic detection initiatives, including advanced threat analytics, detection enrichment, risk scoring, behavioral analytics, and next-generation detection approaches.
  • Communicate technical findings, detection logic, and investigation outcomes to both technical and non-technical stakeholders.
  • Stay current with emerging attack techniques, threat intelligence, security research, and industry best practices to continuously enhance detection capabilities.
Requirements
  • 4+ years of experience in Detection Engineering, Threat Hunting, Incident Response, Security Research, DFIR, MDR, or a related security discipline
  • Experience analyzing large-scale datasets and building data-driven solutions using Python, SQL, Spark, PySpark, or similar technologies
  • Proven ability to translate attacker techniques, security research, and real-world incidents into scalable and effective detection logic
  • Strong understanding of modern attack methodologies
  • Strong investigative and analytical skills, with the ability to analyze ambiguous security problems and drive them to resolution
  • Excellent communication and collaboration skills, with the ability to work effectively across Engineering, Product Management, MDR, Forensics, and Support teams
  • Demonstrated ownership mindset and ability to independently lead initiatives from problem identification through implementation and operationalization
  • Ability to balance research, execution, operational responsibilities, and long-term strategic work in a fast-paced environment
  • Passion for continuous learning, curiosity about attacker behavior, and a desire to stay at the forefront of the cybersecurity landscape
 
 
Preferred Qualifications
 
  • Experience building detections for identity, SaaS, data security, insider risk, or behavioral analytics use cases.
  • Experience evaluating detection quality, measuring effectiveness, improving precision and recall through data analysis and feedback loops.
  • Designing and developing scalable agentic pipelines to drive innovation across threat detection and security operations
We invite you to check out our Instagram Page to gain further insight into the Varonis culture!
@VaronisLife 
Varonis is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, and other legally protected characteristics.
#LI-Remote