Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance

Il y a 7 heures

Mons, Walloon Region, Belgique WLG Temps plein

A multinational defence organisation is strengthening the detection engineering side of its security operations centre. This is not alert triage: you build the content the analysts depend on, measure whether it works, and close the gaps you find.

What you would be doing

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.

What you would bring

  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.