AD - Global Detection Engineering

Qabird

Rijswijk

On-site

EUR 60,000 - 80,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible Working
Enhanced Holiday Allowance
Medicash & Critical Illness Scheme
Financial & Investment Benefits
Community & Volunteering Programmes
Green Car Scheme
Cycle Scheme
Special Time Off
Family Planning Benefits

Job summary

Qabird is seeking a skilled Detection Engineer to develop and manage sophisticated detection logic. You will lead a global team to enhance detection capabilities across various technologies, ensuring high-quality coverage against advanced cyber threats.

Key responsibilities include continuous improvement of detection logic, collaboration with teams to gather relevant inputs, and ensuring client transparency. Ideal candidates will possess strong communication skills, experience in detection engineering, and inspiring leadership qualities.

Qualifications

  • Experience in a range of technologies: SIEM, EDR, ideally NDR.
  • Experience in a complex international environment.
  • Hands-on experience with various technologies in cybersecurity.

Responsibilities

  • Develop new detection logic for our engineering content repository.
  • Improve existing detection logic continuously.
  • Lead a global implementation team for detection logic.

Skills

Experience in detection engineering
Excellent oral and written communication skills
Ability to work with clients
Experience with data science in cybersecurity
Inspiring leadership qualities

Tools

Sentinel
Defender for End-point
Carbon Black
Splunk

Job description

Key Responsibilities
  • Develop new detection logic to contribute to Detection Engineering content repository.
  • Continuously improve existing detection logic.
  • Write and maintain detection test cases.
  • Review findings of TI, CERT, and Red Team activities and evaluate from a detection engineering improvement perspective.
  • Lead a global implementation team that builds, maintains and continuously improves detection logic across a variety of MXDR technologies.
  • Be part of the GMS DevSecOps leadership team and actively contribute to setting vision, direction and feature set of our technology platforms.
  • Ensure that our detection logic is a differentiator in the market, providing extensive and high quality coverage for advanced cyber attacks.
  • Manage senior detection engineers who each manage a number of detection engineers on a specific technology set (EDR, NDR, SIEM).
  • Work pro‑actively with wider NCC teams to ensure all relevant inputs are available (TI, DFIR, RTO etc) to build top‑notch detection logic and to ensure other teams (like solution architecture and implementations) have the required information to deploy high quality MXDR systems with the best possible coverage.
  • Ensure that we can always provide transparency to clients about the detection coverage they receive.
  • Ensure that we develop new ways of applying data science to our vast data sets in order to further improve detection of cyber attacks, correlation of alerts and other efficiencies and improvements that provide improved coverage to clients and improved efficiency to our SOC.
Skills, Knowledge & Expertise
  • Experience in detection engineering on a range of technologies (SIEM and EDR, ideally NDR as well).
  • Experience in working in a global firm in a multi‑cultural context.
  • Experience in working in a complex international environment, that’s subjected to a significant amount of change.
  • Excellent oral and written communication skills.
  • Ability to work with clients and NCC colleagues to continuously improve the service we deliver.
  • Experience with and knowledge of application of data science within a cyber security context.
  • Inspiring leader, with ability to communicate effectively at all levels, creating an approachable and supportive environment for colleagues.

Desirable skills:

  • Have hands‑on experience with a variety of technologies we use: Sentinel, Defender for End‑point, Carbon Black, Splunk, etc.
  • Experience with purple teaming and other adjacent cyber security practices/topics that strengthen detection engineering.
  • Forensics and/or incident response experience.
Job Benefits
  • Flexible Working: Balance your work and personal life with our flexible working options.
  • Enhanced Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
  • Medicash & Critical Illness Scheme.
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
  • Green Car Scheme: Drive green and save money with our eco‑friendly car scheme.
  • Cycle Scheme: Stay fit and healthy with our cycle‑to‑work scheme.
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.

Mandatory background checks are required for this role. Candidates must be willing and able to undergo the vetting process.

We are committed to diversity and flexibility in the workplace.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

Qabird • Rijswijk

Hybrid
EUR 60,000 - 80,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Senior Analyst - Tactical Intelligence
Senior Analyst - Tactical Intelligence

NCC Group • Rijswijk

On-site
EUR 70,000 - 100,000
Flexible Working
Holiday Allowance
Medicash
+6
Senior Manager - MXDR
Senior Manager - MXDR

Fox iT • Rijswijk

On-site
EUR 105,000 - 176,000
Pension scheme
Vacation days: 26 + 4 days off
Tech development opportunities
+4
Detection Quality Engineer
Detection Quality Engineer

Northwave • Utrecht

On-site
EUR 70,000 - 110,000
Detection Consultant
Detection Consultant

nccgroup • Rijswijk

On-site
EUR 50,000 - 70,000
Technical Account Manager
Technical Account Manager

Qabird • Rijswijk

Hybrid
EUR 70,000 - 95,000
Flexible Working
Generous Holiday Allowance
Medicash & Critical Illness Scheme
+6
Detection Quality Engineer
Detection Quality Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Qabird • Rijswijk

Hybrid
EUR 90,000 - 120,000
Flexible Working
25 days holiday
Medicash & Critical Illness Scheme
+3
Senior Threat Intelligence Consultant
Senior Threat Intelligence Consultant

Qabird • Rijswijk

Hybrid
EUR 85,000 - 110,000
Flexible Working
Generous Holiday Allowance: 25 days +
Pension, Life Assurance & Share Save
+3
Senior Security Engineer
Senior Security Engineer

Fox-IT • Rijswijk

On-site
EUR 70,000 - 110,000
Flexible Working
25 days holiday + bank holidays
Medicash & Critical Illness
+4