Search...

Threat Detection Engineer

Speedinvest logo
Speedinvest

Speedinvest is a European venture capital firm that invests from seed to growth stage (Series B to pre-IPO), backing founders with sector-specific expertise and a large network of operational support. It leads the majority of its initial investments and continues to support portfolio companies through multiple follow-on rounds as they scale.

Distributed
About Speedinvest

Speedinvest is a pan-European venture capital investor with specialist investment teams organized around core sectors including AI & Infra, Climate Tech & Industrial Tech, Deep Tech, Fintech & DeFi, Health & Bio, and Marketplaces & Consumer, alongside a dedicated Growth team writing checks from Series B to pre-IPO. The firm emphasizes leading with conviction and long-term capital from day one, leading 85% of its initial investments, participating in 100+ follow-on rounds each year, and backing 70+ Series A companies over the past four years. Speedinvest works with startup founders across Europe and beyond, providing not just capital but network access and growth support, and counts companies like Bitpanda, Moove, cylib, Tide, Gigs, Upvest, and GoStudent among its portfolio.

View jobs by Speedinvest

Skills

About the Role

You will develop and implement threat-detection strategy, work hands-on with SIEM systems, build security automations, and hunt for threats across cloud infrastructure, applications, and endpoints. You will improve detection quality and platform uptime, lead complex incident investigations, develop internal tools, collaborate on detection rules, and participate in the incident-response on-call rotation.

Requirements

  • Strong knowledge of Splunk, Scanner, Sentinel, or SecOps
  • Strong understanding of modern cloud, SaaS, and desktop attack and defence techniques
  • Experience in security automation, scripting, SOAR platforms, and automated threat detection and response workflows
  • Excellent spoken and written communication skills
  • Ability to share knowledge with colleagues
  • Experience writing automation and scripts

Responsibilities

  • Support the development and implementation of a strategic vision for threat detection
  • Create custom SIEM log parsers, configure alert rules, analyze logs, and tune detections
  • Build security automations and services for enrichment and phishing-email removal
  • Hunt for threats across AWS, GCP, internal applications, and Windows and macOS endpoints
  • Develop and implement business-specific threat-detection rules with cross-functional teams
  • Ensure detection quality and ecosystem uptime through test-driven development and proactive health monitoring
  • Build or enhance internal tools that improve threat detection, data visibility, and response efficiency
  • Lead complex incident investigations and coordinate containment, remediation, and recovery
  • Participate in the security incident-response on-call rotation

Benefits

  • Remote-first work setup with flexibility to work from anywhere in Bulgaria
  • Performance-based incentives
  • 25 days of paid annual leave
  • 3 additional days for volunteering and learning
  • Private Health Insurance
  • Mental Health Support Platform
  • Company-sponsored Multisport Card
  • Family and Friendly Leave according to statutory requirements
  • Personal L&D budget