Threat Detection Specialist — MITRE ATT&CK Coverage for NATO with security clearance

WLG

Henegouwen

Sur place

EUR 60 000 - 90 000

Plein temps

Il y a 11 jours
Générateur de candidature

Une candidature sur mesure pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Résumé du poste

WLG seeks a detection engineer to design, build and maintain rules and analytics across SIEM, EDR and XDR, plus network and cloud tooling. You will write detection logic in Sigma, SPL, or KQL and map findings to MITRE ATT&CK with adversary tradecraft in mind.

You will translate threat intelligence and purple team results into automated detections, manage the detection lifecycle, and collaborate with incident handlers and threat hunters during live investigations. On-site work is near Mons.

Qualifications

  • Experience designing and building detection pipelines and alerts.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluent in at least one detection language and capable of scripting for automation.

Responsabilités

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud tooling.
  • Writing detection logic in Sigma, SPL, KQL or equivalent languages.
  • Mapping detections to MITRE ATT&CK and adversary tradecraft concepts.

Connaissances

Detection engineering
Version control
Code review
Scripting for automation
Threat intel familiarity

Formation

Bachelor's degree in CS or related

Outils

SIEM platforms
EDR tools
NDR tools

Description du poste

What You Would Be Doing
  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle — design, development, testing, deployment, monitoring, improvement, review — and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

The assignment is on-site near Mons.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance
Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

WLG • Henegouwen

Sur place
EUR 60 000 - 95 000
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance
Security Content Engineer — Sigma, SPL and KQL for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 65 000 - 95 000
Incident Response Specialist (Threat Hunting and Malware Analysis) for NATO with security clearance
Incident Response Specialist (Threat Hunting and Malware Analysis) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000
Detection Engineer - SIEM/EDR, MITRE ATT&CK & NATO
Detection Engineer - SIEM/EDR, MITRE ATT&CK & NATO

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
Threat Detection Engineer — On-Site in Mons
Threat Detection Engineer — On-Site in Mons

WLG • Henegouwen

Sur place
EUR 60 000 - 90 000
Detection Engineer
Detection Engineer

Hunter International, Inc. • Brussel

Sur place
EUR 65 000 - 95 000
CSIRT Analyst (Intrusion Detection and Digital Forensics) for NATO with security clearance
CSIRT Analyst (Intrusion Detection and Digital Forensics) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 90 000 - 120 000
Detection Engineer: SIEM/EDR/XDR with Clearance
Detection Engineer: SIEM/EDR/XDR with Clearance

WLG • Henegouwen

Sur place
EUR 65 000 - 90 000
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance
Detection Engineer and Escalation Analyst (SIEM, EDR and SOAR) for NATO with security clearance

Wlgroup • Henegouwen

Sur place
EUR 70 000 - 110 000