Detection Engineer and Escalation Analyst
Il y a 14 heures
Wallonia, Wallonia, Belgique
WLG
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
Second line is where an alert stops being noise and
becomes a decision. You would be the technical escalation point in
a large defence security operations centre in Mons, Belgium —
validating what the first line produces, digging into the cases
they cannot close, and building the detections that stop the same
thing reaching them twice. What you would be doing Reviewing and
validating investigations, supporting first-line analysts so that
alert closures, escalations, evidence and notes meet the standard —
complete, accurate and procedurally sound Acting as the technical
escalation point for security monitoring: in-depth log analysis and
threat triage across Splunk Enterprise Security, Splunk SOAR and
Microsoft Sentinel, plus the supporting data sources and security
appliances, and deciding what goes to incident handling Providing
on-call cover as part of a 24x7 roster, so second-line escalations
are answered round the clock Designing, developing, testing and
maintaining detection rules, alerts and analytics across the
monitoring tool-set — tuning logic, thresholds, allow-lists,
suppression and severity so false positives fall and coverage of
new threats rises Giving first-line analysts regular, constructive
feedback and coaching on technique, analytical approach and
reporting, and helping new joiners find their feet Supporting the
duty second-line analyst through the week — watching open tasks,
chasing pending actions, and flagging anything that threatens
service continuity Taking part in purple-team exercises to test and
improve detection coverage Working with the threat hunting team to
turn their findings into automated detections wherever that is
possible Contributing to service improvement: finding the workflow
inefficiencies, the monitoring blind spots, and saying what should
change Writing and updating the operational documentation,
procedures, run-books and knowledge-base articles the whole team
relies on Representing the monitoring function in project planning,
implementation and transition, so visibility requirements are
considered early, and advising on detection content, log-source
integration and security-tool configuration Working with colleagues
across the wider security organisation and with external partners
Ad-hoc work when it is needed — special investigations, projects,
whatever keeps the operation effective What you would bring At
least three years hands-on in a security operations centre or a
closely related monitoring environment A proven expert-level record
of analysing complex security incidents and writing clear,
authoritative reports and recommendations for the teams and
partners who act on them Real fluency extracting, normalising and
interrogating raw log data from varied sources — Windows event
logs, Linux syslog, Sysmon, endpoint detection platforms such as
Microsoft Defender, SentinelOne or CrowdStrike — using Splunk,
Microsoft Sentinel or Elastic Kibana. Filtering, correlating and
visualising events to verify an alert, reconstruct what an attacker
did across hosts, and hand over evidence someone can act on
Hands-on packet capture analysis with Wireshark, tcpdump or Zeek —
pulling traffic apart to corroborate an alert and rebuild a
timeline The ability to turn attacker techniques and threat
intelligence into working detection logic, and to run structured
peer reviews of other analysts' investigations that actually find
the gaps Designing, developing and maintaining detections across
monitoring, endpoint and cloud security tooling — Splunk, Microsoft
Sentinel, Azure, AWS Supporting or mentoring less experienced
analysts, with feedback they can use Practical automation work:
spotting the repetitive manual task and building the enrichment or
workflow that removes it Strong written and spoken communication —
investigation notes, escalation summaries and documentation that
read well under pressure Professional English A bachelor's degree
in a related discipline with three years of related experience —
or, exceptionally, five years of extensive and progressive
expertise in this kind of work A relevant certification such as
CISSP, CISM, a GIAC credential (GCIH, GCFA, GSEC) or CompTIA CySA+
Nice to have A degree in cyber security, IT or computer science
Time in a regulated, high-control environment — defence,
government, financial services or comparable Cloud-native security
monitoring on Azure or AWS, and hybrid estates Building detections
from network and edge devices such as Cisco, Fortinet, Palo Alto or
similar Work for or with a military or governmental organisation
Why this one is worth a look Detection engineering and deep
analysis in the same seat, at a scale where the telemetry is
genuinely interesting and the escalations are real.