Detection Engineer

Defion

Barcelona

Híbrido

EUR 40.000 - 60.000

Jornada completa

14 días+
Generador de candidaturas

Convierte este puesto en una entrevista — un currículum y una carta de presentación creados pensando en lo que quiere el empleador.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Flexible Compensation Plan
Private health insurance
Continuous training opportunities
Dynamic team environment

Descripción de la vacante

A cybersecurity firm is seeking a Detection Engineer to strengthen clients' security postures. You will design detection rules and analyze security threats while collaborating with both Red and Blue Teams. The ideal candidate should have a degree in Engineering or Cybersecurity with relevant experience in detection engineering, familiarity with various SIEM/EDR tools, and scripting skills in Bash, Python, or PowerShell. The position offers hybrid working options and continuous training opportunities.

Formación

  • 1-2 years of experience in detection or SOC roles.
  • Experience in creating/optimizing alerts in SIEM/EDR.
  • Strong understanding of adversarial Tactics and Techniques.

Responsabilidades

  • Design advanced detection rules for security threats.
  • Analyze attacker simulations to improve security controls.
  • Automate security assessment processes.

Conocimientos

Kusto Query Language (KQL)
CrowdStrike Query Language (CQL)
Bash scripting
Python scripting
PowerShell scripting
Windows logs analysis
TCP/IP knowledge
UNIX/Linux administration
Analytical skills
Attention to detail

Educación

Degree in Engineering or Cybersecurity

Herramientas

Microsoft Sentinel
CrowdStrike
Splunk
Elastic ELK
QRadar
Wazuh

Descripción del empleo

Location: Hybrid / Remote
Employment: Full-time
Team: Detection Engineering

ABOUT DEFION

At DEFION, we have been protecting organizations with advanced cybersecurity solutions since 2005. We are a reference in incident response, digital forensics, managed security services, threat intelligence, and offensive security projects (Red & Purple Team).
Our technical team is made up of highly qualified professionals with real experience in complex and critical environments. We work with cutting-edge technology, agile methodologies, automation, and a collaborative approach that fosters both technical and professional growth.

With an international presence and in full expansion, DEFION is committed to talent, continuous training, and career development. Here you won’t just consume intelligence — you will generate it and apply it to create effective detections. You will work in a multidisciplinary team, transforming findings from real offensive security projects into detection rules.

BACKGROUND

As part of our Detection Engineering and MDR-Extended service, we are looking for profiles with experience in creating rules (EDR/XDR/SIEM), behaviour-based detection, and TTP analysis. If you are passionate about designing detections that make a difference, DEFION is looking for you.

FUNCTIONS AND RESPONSIBILITIES

As a Detection Engineer, you will play a key role in strengthening our clients’ security posture. You will apply your knowledge of adversarial tactics and techniques to design and develop advanced detection rules that enable effective identification and response to security threats. Your responsibilities will include:

  • Designing, developing, and fine-tuning detection rules in SIEM, EDR, and XDR platforms to improve threat detection and incident response capabilities.
  • Analyzing results from attacker simulations to identify weaknesses in security controls.
  • Developing detection and mitigation strategies for emerging threats.
  • Automating and optimizing processes by creating tools and scripts that streamline security assessments and reporting.
REQUIREMENTS
  • Degree in Engineering, Cybersecurity, or a related field, or demonstrable equivalent professional experience.
  • 1–2 years of experience in one or more of the following roles: Detection Engineer, or SOC Analyst with experience creating and/or optimizing alerts in SIEM and/or EDR platforms, specifically with knowledge of Microsoft’s Kusto Query Language (KQL) and/or CrowdStrike Query Language (CQL).
  • Deep knowledge of Windows logs, telemetry, and event analysis, with specialization in identifying and analyzing adversarial tactics and techniques for proactive threat detection.
  • Strong understanding of adversary Tactics, Techniques and Procedures (TTPs), based on MITRE ATT&CK.
  • Experience with SIEM and EDR platforms such as Microsoft Sentinel, CrowdStrike, Cortex, Splunk, Elastic ELK, LogRhythm, QRadar, Chronicle, or Wazuh, among others.
  • Scripting skills (Bash, Python, PowerShell) to automate tasks and develop tools.
  • Knowledge of Windows and UNIX/Linux system administration.
  • Solid understanding of networks and communication protocols, including TCP/IP, DHCP, DNS, and other fundamental protocols.
  • Purple-team mindset: the ability to think like an adversary (Red Team) while enhancing defensive capabilities (Blue Team).
  • Ability to communicate clearly and effectively in English in technical environments and with international teams.
  • Analytical, organizational, and creative skills, with attention to detail, the ability to detect anomalies, and to solve problems.
  • Specialized training, such as cybersecurity certifications or a master's degree, will be a plus.
WHAT WE OFFER
  • Being part of an international, young, and dynamic team with an excellent working environment.
  • Close collaboration with the Red Team and the Blue Team to stay up to date on real attacks and the latest adversarial techniques, as well as access to various detection technologies such as EDR, SIEMs, threat intelligence, and other security tools.
  • Continuous internal and external training to keep you always up to date (certifications and attendance at annual conferences).
  • A personalized professional career plan tailored to your interests and development, ensuring your growth within the company.
  • Flexibility for remote work or access to comfortable offices in Barcelona.
  • Summer reduced working hours.
  • Flexible Compensation Plan, including benefits such as meal card, transport, childcare, and training.
  • Private health insurance.
Apply

First name*

Last name*

Email*

Phone

LinkedIn profile URL

Other website

CV* Upload your CV in .pdf format (max. 1MB)

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

SOC Analyst
SOC Analyst

Defion • Barcelona

Híbrido
EUR 35.000 - 50.000
Flexible Compensation Plan
Continuous training and certifications
Private health insurance
Senior SOC Engineer
Senior SOC Engineer

SmartRecruiters, Inc. • Terrassa

Presencial
EUR 65.000 - 90.000
Detection Engineer
Detection Engineer

adpinternalcareers • España

Híbrido
EUR 60.000 - 90.000
Principal Security & Detection Engineer
Principal Security & Detection Engineer

Integrity360 • Madrid

Presencial
EUR 90.000 - 130.000
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)

Tamarind Intelligence • Madrid

Presencial
EUR 70.000 - 100.000
Remote work 4 days / week
Healthcare benefits
Meal vouchers
+2
Detection Engineer
Detection Engineer

apply • España

Híbrido
EUR 55.000 - 90.000
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)

Ambit Iberia • Sant Cugat del Vallès

Híbrido
EUR 90.000 - 130.000
Ticket restaurant
Medical insurance
Public transport ticket
+3
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)
Senior Security Engineer (SIEM/XDR) | Pharma (Hybrid)

Ambit Iberia • Barcelona

Híbrido
EUR 60.000 - 90.000
Meal vouchers
Medical insurance
Public transport ticket
+3
Detection Engineer
Detection Engineer

ADP, Inc. • Madrid

Presencial
EUR 60.000 - 90.000
Hybrid work schedule
Detection Engineer
Detection Engineer

ADP, Inc. • Barcelona

Presencial
EUR 70.000 - 110.000