Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

Wlgroup

Henegouwen

Sur place

EUR 65 000 - 95 000

Plein temps

Il y a 8 jours
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV et une lettre de motivation personnalisés en environ une minute.

Passez les filtres ATS

Résumé du poste

Wlgroup is seeking a Detection Engineer to strengthen our security operations centre. You will design, build and test detections across SIEM, EDR and XDR, and measure their effectiveness.

You will map detections to MITRE ATT&CK, work with threat intel, and drive improvements through the full detection lifecycle on on-site systems near Mons in Belgium.

Qualifications

  • Real detection engineering experience with repeatable code review and version control
  • Hands-on work with a major SIEM and endpoint and network detection tooling
  • Fluency in at least one detection language and scripting to automate the rest
  • Familiarity with adversary tradecraft and the ATT&CK framework as a working tool

Responsabilités

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling
  • Writing detection logic in Sigma, SPL, KQL
  • Building detections around adversary behaviour and mapping them to MITRE ATT&CK
  • Turning threat intelligence into working automated detections
  • Running a detection lifecycle from design to review and improvements

Connaissances

Detection engineering
SIEM/EDR/XDR tooling
MITRE ATT&CK
Python/PowerShell

Outils

Sigma
KQL

Description du poste

A multinational defence organisation is strengthening the detection engineering side of its security operations centre. This is not alert triage: you build the content the analysts depend on, measure whether it works, and close the gaps you find.

What you would be doing
  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands‑on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 60 000 - 95 000
Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance
Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance
Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
Threat Detection Engineer — On-Site in Mons
Threat Detection Engineer — On-Site in Mons

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Detection Engineer
Detection Engineer

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
Detection Engineer: SIEM/EDR/XDR with Clearance
Detection Engineer: SIEM/EDR/XDR with Clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000