Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

WLG

Henegouwen

Sur place

EUR 60 000 - 95 000

Plein temps

Il y a 2 jours
Soyez parmi les premiers à postuler
Générateur de candidature

Transformez ce poste en entretien — un CV et une lettre de motivation conçus selon ce que cet employeur recherche.

Passez les filtres ATS

Résumé du poste

WLG in Belgium is seeking a seasoned detection engineer to strengthen its security operations centre and to build reliable detections you can trust during incidents.

You design, build and tune detection rules across SIEM, EDR, XDR, network detection and cloud tooling; map detections to MITRE ATT&CK; and translate threat intel into automated detections. On-site near Mons, Belgium.

Qualifications

  • Proven detection engineering experience with repeatable processes.

Responsabilités

  • Design, build and maintain detection rules and analytics.
  • Write detection logic in Sigma, SPL, or KQL.
  • Map detections to MITRE ATT&CK.
  • Automate detections from threat intel and purple team findings.
  • Run detection lifecycle: design to review and improve metrics.
  • Assess coverage across on-prem and cloud.
  • Review ingested logs and coordinate data owners.
  • Support incident handlers and threat hunters.

Connaissances

Detection engineering
Version control
SIEM tooling
Detection language
Scripting
ATT&CK framework
Professional English

Outils

SIEM tooling
Endpoint detection
Network detection

Description du poste

A multinational defence organisation is strengthening the detection engineering side of its security operations centre. This is not alert triage: you build the content the analysts depend on, measure whether it works, and close the gaps you find.

What You Would Be Doing
  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 65 000 - 95 000
Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance
Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance
Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance
Second Line SOC Analyst (Splunk, Sentinel and Detection Engineering) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance
Senior Security Analyst (Threat Triage, PCAP and Escalation) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 95 000
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance
Security Data Engineer — SIEM Operations and Automation for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Detection Engineer
Detection Engineer

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
Detection Engineer: SIEM/EDR/XDR with Clearance
Detection Engineer: SIEM/EDR/XDR with Clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Threat Detection Engineer — On-Site in Mons
Threat Detection Engineer — On-Site in Mons

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000