Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance

Il y a 4 jours

Henegouwen, Henegouwen, Belgique WLG Temps plein 65 000 € - 90 000 € Contrat

What You Would Be Doing

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.

What you would bring

  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.