Detection Engineer
Build detection that actually matters. Cyber threats don’t wait. Neither do you.
At our international Security client, you won’t be maintaining generic alerts or chasing noise. You’ll design and build detection that actually makes organizations more resilient. You turn threat intelligence into smart detection logic and make sure attackers are spotted — fast.
You’re close to the tech, but even closer to the impact. What you build directly improves how quickly threats are detected and stopped.
What you’ll do
- Design, build and continuously improve detection logic across SIEM, EDR and NDR platforms.
- Translate threat intelligence into practical, high-quality detection use cases.
- Test, validate and optimize detections for real-world effectiveness.
- Work closely with SOC, red team and threat intelligence specialists.
- Analyze logs, telemetry and behavior to uncover blind spots.
- Continuously raise the bar of detection engineering.
What you bring
- A degree in Engineering, Cybersecurity or similar — or equivalent hands-on experience.
- 1–2 years of experience in Detection Engineering, SOC, or Security Operations.
- Experience building or improving detections in SIEM and/or EDR environments.
- Familiarity with KQL and/or CQL is a strong plus.
- Strong understanding of Windows logs, telemetry and event analysis.
- Knowledge of attacker behavior and MITRE ATT&CK (TTPs).
- Experience with tools like Microsoft Sentinel, CrowdStrike, Splunk, Elastic, QRadar, Chronicle or similar.
- Scripting skills (Python, PowerShell, Bash) to automate and enhance detection.
- Solid understanding of systems (Windows/Linux) and networking fundamentals (TCP/IP, DNS, etc.).
- A purple-team mindset: you think like an attacker, but build like a defender.
- Strong analytical skills and attention to detail — you spot what others miss.
- Clear communication skills in English, working in technical and international environments.
- Certifications or advanced training are a plus, not a requirement.
Why this role stands out
- Real impact on the security posture of organizations.
- A highly technical, no-nonsense environment.
- Small, skilled team with a lot of autonomy.
- Plenty of room to grow in depth, skill and responsibility.