Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance
Il y a 4 jours
Henegouwen, Henegouwen, Belgique
WLG
Temps plein
65 000 € - 90 000 € Contrat
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
What You Would Be Doing
- Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
- Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
- Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
- Turning threat intelligence and purple team findings into working automated detections.
- Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
- Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
- Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
- Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
- Real detection engineering experience, and the version control and code review habits that make it repeatable.
- Hands-on work with a major SIEM and with endpoint and network detection tooling.
- Fluency in at least one detection language, and enough scripting to automate the rest.
- Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
- Professional English, and the ability to explain a detection decision to people who did not write it.
The assignment is on-site near Mons.