Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance

WLG

Henegouwen

Sur place

EUR 65 000 - 90 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Résumé du poste

WLG in Mons-area is seeking a Detection Engineer to design, build and run detections across SIEM, EDR and XDR, and to map them to the MITRE ATT&CK framework. You will write detection logic in Sigma, SPL or KQL and automate repetitive tasks to improve coverage.

Join a team that translates threat intel into actionable detections, supports incident handlers, and drives the detection lifecycle from design through deployment and continuous improvement.

Qualifications

  • Proven detection engineering experience across SIEM/EDR/XDR.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and the ATT&CK framework as a working tool.
  • Professional English, and the ability to explain a detection decision to non-authors.

Responsabilités

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping to MITRE ATT&CK.
  • Turning threat intelligence and purple team findings into automated detections.
  • Running a detection lifecycle from design to improvement and monitoring.

Connaissances

Detection engineering
SIEM tooling
Endpoint detection
Scripting & automation
Threat intel & ATT&CK
English communication

Outils

Sigma
SPL
KQL
MITRE ATT&CK

Description du poste

What You Would Be Doing
  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance
Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Detection Engineer – SIEM/EDR Threat Detection
Detection Engineer – SIEM/EDR Threat Detection

EMW • Henegouwen

Hybride
EUR 70 000 - 100 000
Detection Engineer
Detection Engineer

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
Detection Engineer — SIEM/EDR for NATO Security Ops
Detection Engineer — SIEM/EDR for NATO Security Ops

EMW, Inc. • Henegouwen

Sur place
EUR 70 000 - 100 000
Detection Engineer: SIEM/EDR/XDR with Clearance
Detection Engineer: SIEM/EDR/XDR with Clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Detection Engineer - SIEM/EDR, MITRE ATT&CK & NATO
Detection Engineer - SIEM/EDR, MITRE ATT&CK & NATO

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Threat Detection Engineer — On-Site in Mons
Threat Detection Engineer — On-Site in Mons

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
Detection Engineer – SIEM/EDR & Threat Hunting
Detection Engineer – SIEM/EDR & Threat Hunting

Spektrum • Henegouwen

Sur place
EUR 65 000 - 95 000