Detection Engineer

Philips Iberica SAU

Netherlands

Remote

EUR 61,000 - 102,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid working
Health & wellbeing benefits
Learning & development
Paid time off

Job summary

Philips is seeking a Detection Engineer to design, implement, and continuously validate high-fidelity detection capabilities within the Cyber Defense Capabilities team. You will develop, test, and tune SIEM detections, perform BAS exercises, and map coverage to MITRE ATT&CK.

You will work with incident responders, threat hunters, and threat intelligence teams to improve detections and reduce MTTD, in a primarily onsite/office environment in the Netherlands.

Qualifications

  • Minimum 2 years of experience in areas such as Security Architecture, Network Security, or Information Security.
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • Strong experience with SIEM platforms (e.g., Splunk, Sentinel).
  • Proficiency in detection engineering, log parsing, and data normalization.
  • Familiarity with AI/ML concepts in cybersecurity for threat analysis and automation.

Responsibilities

  • Develop, test, and maintain detection rules, signatures, and correlation logic in SIEM and related platforms.
  • Conduct regression testing of detection rules to ensure accuracy and resilience after updates.
  • Perform breach and attack simulations (BAS) to validate use cases tied to threat intel and TTPs.
  • Map detection logic to MITRE ATT&CK and ensure coverage of priority threat scenarios.
  • Integrate threat intelligence feeds, IOCs, and behavioral patterns into detection workflows.
  • Tune detection logic to reduce false positives and improve alert fidelity.
  • Collaborate with incident response and threat hunting teams to address gaps and validate detections.
  • Automate enrichment, correlation, and triage via SOAR playbooks and scripts.
  • Maintain documentation, repositories, and test playbooks for continuity.
  • Contribute to SOC metrics including coverage, false positives, and BAS validation.

Job description

Detection Engineer
Job Description

Thedetection engineeris a member of the Cyber Defense Capabilities team andis responsiblefordesigning, implementing, and continuously validating detection capabilitiesforCSIRT. This includes building high-fidelity detection logic, regression testing to ensure detectionsremaineffective over time, and executing breach and attack simulations (BAS) to align detection coverage with evolving adversary techniques and threat intelligence.

Thedetection engineerworks closely with incident responders, threat hunters, and threat intelligence analysts to drive continuous improvement and reduce mean time to detect (MTTD)

Your role:
  • Develop, test, and maintain detection rules, signatures, and correlation logic in SIEM and related platforms.
  • Conduct regression testing of detection rules to ensure accuracy, resilience, and functionality following system updates or logic changes.
  • Perform breach and attack simulations (BAS) to validate detection use cases, tied directly to threat intelligence and adversary TTPs.
  • Map detection logic to adversary techniques using frameworks such as MITRE ATT&CK and ensure coverage of priority threat scenarios.
  • Integrate threat intelligence feeds, IOCs, and behavioral patterns into detection workflows.
  • Regularly tune and refine detection logic to reduce false positives and optimize alert fidelity.
  • Partner with incident response and threat hunting teams to validate detections, perform purple team exercises, and address detection gaps.
  • Automate enrichment, correlation, and triage processes through SOAR playbooks and custom scripts.
  • Implement lessons learned from incidents and simulations into new or improved detections.
  • Maintain documentation, detection repositories, and test playbooks for operational continuity.
  • Contribute to SOC metrics, including detection coverage, false positive ratios, regression test outcomes, and BAS validation reports.
You're the right fit if:
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • Minimum 2 years of experience in areas such as Security Architecture, Network Security, Cybersecurity Technology, Information Security or equivalent
  • Strong experience with SIEM platforms (e.g., Splunk, Sentinel).
  • Proficiency in detection engineering, log parsing, and data normalization.
  • Working knowledge of artificial intelligence concepts and practical experience applying AI or machine learning techniques within cybersecurity functions, such as threat analysis, automation, or analytics.
  • Familiarity with adversary simulation tools (e.g., AttackIQ, Caldera, commercial BAS platforms).
  • Knowledge of threat intelligence integration and frameworks (MITRE ATT&CK).
  • Scripting ability in Python, PowerShell, or similar languages.
  • Experience with cloud environments (AWS, Azure, GCP, Aliyun) and associated security telemetry. Strong understanding of network protocols, endpoint security, and common attack techniques.
  • Hands-on experience with SOAR platforms and automation development.
  • Prior exposure to purple team exercises and continuous validation methodologies.
  • Familiarity with detection engineering in containerized or modern application environments (Kubernetes, serverless).

Compensation & benefits

Doing meaningful work should come with fair, transparent rewards. The base salary range for this role isEUR 61,200 - EUR 101,900. We determine pay within the range using objective factors, like the skills the role requires, your relevant experience and the responsibility you'll have in this role, alongside internal equity and local market considerations.

This role is eligible for3% short term incentive with your rewards linked to both individual performance and company results.We’ll share the full approach with you during the interview process, so you can make a clear, informed decision. Benefits includehybrid working, paid time-off, health and wellbeing benefits, learning and development opportunities.

How we work together

We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week. Onsite roles require full-time presence in the company’s facilities. Field roles are most effectively done outside of the company’s main facilities, generally at the customers’ or suppliers’ locations.

This role is an office role.

About Philips

We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others.

  • Learn more about our business here.
  • Discover our rich and exciting history here.
  • Learn more about our purpose here.

#LI-EU

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer
Detection Engineer

Philips • Best

Hybrid
EUR 61,000 - 102,000
Hybrid working
Paid time-off
Health and wellbeing benefits
+1
Detection Engineer
Detection Engineer

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
Detection Engineer
Detection Engineer

NCC Group • 't Haantje

On-site
EUR 65,000 - 95,000
Laptop and business phone
Remote work allowance
Lunch in office
+1
Detection Engineer: SIEM, BAS & Threat Intelligence
Detection Engineer: SIEM, BAS & Threat Intelligence

Philips Iberica SAU • Netherlands

Remote
EUR 61,000 - 102,000
Hybrid working
Health & wellbeing benefits
Learning & development
+1
Detection Engineer: SIEM, BAS & Threat Intel Expert
Detection Engineer: SIEM, BAS & Threat Intel Expert

Philips • Best

Hybrid
EUR 61,000 - 102,000
Hybrid working
Paid time-off
Health and wellbeing benefits
+1
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Detection Consultant
Detection Consultant

nccgroup • Rijswijk

On-site
EUR 50,000 - 70,000
Security Engineer (Blue Team)
Security Engineer (Blue Team)

Limina Hacking Company B.V. • Rotterdam

Hybrid
EUR 50,000 - 80,000
Salary €4,500–€7,200 gross/mo
8% holiday allowance
25 days annual leave
+9
Expert Security Analyst – Incident Coordinator
Expert Security Analyst – Incident Coordinator

ASML Germany GmbH • Netherlands

Hybrid
EUR 85,000 - 125,000