Detection Engineer

NCC Group

Rijswijk

Hybrid

EUR 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working hours
Remote work allowance
Laptop and business phone
Pension scheme
26 vacation days + 4 days off

Job summary

NCC Group in Rijswijk, NL is seeking a Detection Engineer to join our Global Detection Engineering Team. You will tailor detections for our 24/7 managed monitoring service, bridging customers and detection engineers to define gaps and build custom detections beyond NCC’s library.

You will work with SIEM/EDR technologies, engage with customers, and contribute to expanding our detection library while ensuring effective delivery and testing of new analytics.

Qualifications

  • Experience in detection engineering on SIEM/EDR
  • SOC or Managed Detection Services experience preferred
  • Analytically-minded IT systems/network administration background an asset
  • Excellent written and spoken communication skills

Responsibilities

  • Schedule and host threat workshops using approved methodologies
  • Correlate log events in SIEM to application/tech activities
  • Query data in SIEM environments to assess detection feasibility
  • Write pseudo-logic and work packages for detections-as-code
  • Derive new detection opportunities from threat intelligence reports
  • Identify potential abuse patterns in customer applications
  • Explain attack paths to customers
  • Track detections in development and share status with customers
  • Obtain customer feedback during testing of new analytics
  • Ensure work is tracked in internal ticketing systems

Skills

Detection engineering
SIEM
EDR
SOC experience

Tools

Splunk
Microsoft Sentinel

Job description

Detection Engineer

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: NLD Rijswijk


Description

Our Global Detection Engineering Team provides detection capabilities for various security products used in our 24/7 managed monitoring service with customers all over the world. This role will be to join our detection engineering team, where you will focus on providing a tailored experience of custom detections to all our customers.

All customers have the benefit of access to NCC’s wide library of detections but there are many cases for exceptions and requirements for custom detections. This role sits at the pivotal point between our customers and the detection engineers. Together with (representatives of our) customers you will focus on assessing the gap and need for custom detections (on top of the deployment of detections from NCC’s detection library) to provide the appropriate level of detection each customer desires.


Key Responsibilities
  • Schedule and host threat workshops utilizing industry-approved methodologies such as DREAD or STRIDE.
  • Correlate log events in SIEM solutions with activities which have taken place in the (business) application or technology.
  • Query data ingested into customer SIEM environments to assess the practical feasibility of newly proposed detections.
  • Prepare pseudo-logic and work packages for detection engineers who write detections-as-code within the NCC detection repository.
  • Derive new generic detection opportunities from Threat Intelligence reports to further expand NCC’s detection library.
  • Identify potential abuse patterns in customer applications.
  • Query large datasets of data in SIEMs (Sentinel & Splunk).
  • Explain (potential) attack paths to customers.
  • Write pseudo-logic for the development of new detections.
  • Track the status of detections under development and share status updates with the customer.
  • Obtain feedback from customers on exceptions and allowed behavior during the testing phase of the development of new analytics.
  • Ensure work is up-to-date and tracked in (internal) ticketing system(s).

Skills, Knowledge & Expertise
  • Experience in detection engineering on a range of technologies (SIEM and EDR)
  • OR
  • Experience in SOC or Managed Detection Services
  • OR
  • Experience in Analytically-minded IT Systems administration/Network Administration and looking for a change in career/focus on Security
  • Excellent oral and written communication skills.
  • Ability to work with client engagement teams and NCC colleagues to continuously improve the service we deliver.
  • Good understanding of IT Systems and platforms from a security context.

Desired Requirements:

  • A security mindset and demonstrable experience or knowledge of contemporary attack tactics and techniques.
  • Forensics or Incident Response competency would be considered valuable.
  • Strong knowledge of the latest threats in security.
  • The skills to translate technical attacks to effects in the business (and vice versa).
  • Experience in simulating attacks is considered an advantageous skill to enhance other skills
  • Experience with SIEM tools, preferably Splunk and Microsoft Sentinel.
  • Azure or other cloud technologies,
  • Windows Active Directory,
  • Windows Operating System fundamentals,
  • Networking fundamentals.
  • System management technologies
  • Identity and access management procedures and technologies

Job Benefits
  • A good salary that matches the things you have already done and will do;
  • Flexible working hours and flexibility in working from home or at the office, allowing you to optimally combine your private life with your work;
  • A favorable pension scheme, 26 vacation days (+4 mandatory days off), and 8% holiday pay with a full-time contract;
  • Plenty of development opportunities: you can gain and share knowledge through training, TechTalks, events, and our own Fox Academy;
  • A laptop and business phone. If you use your own phone, you will receive a reimbursement of up to €25 per month;
  • A remote work allowance (for hybrid working);
  • A performance bonus and profit sharing because we value your effort;
  • When we work in the office, we gather every day for a delicious lunch.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AD - Global Detection Engineering
AD - Global Detection Engineering

Qabird • Rijswijk

Hybrid
EUR 60,000 - 80,000
Flexible Working
Enhanced Holiday Allowance
Medicash & Critical Illness Scheme
+6
Detection Engineer - Custom Detections & SIEM Expertise
Detection Engineer - Custom Detections & SIEM Expertise

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
Detection Engineer — Custom Threat Detections (Remote)
Detection Engineer — Custom Threat Detections (Remote)

NCC Group • Netherlands

Remote
EUR 60,000 - 90,000
Flexible working hours
Pension scheme
26 vacation days
+5
Custom Detection Engineer – Client Solutions
Custom Detection Engineer – Client Solutions

nccgroup • Rijswijk

On-site
EUR 50,000 - 70,000
Detection Consultant
Detection Consultant

nccgroup • Rijswijk

On-site
EUR 50,000 - 70,000
Detection Quality Engineer
Detection Quality Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
Senior Security Engineer
Senior Security Engineer

Qabird • Rijswijk

Hybrid
EUR 90,000 - 120,000
Flexible Working
25 days holiday
Medicash & Critical Illness Scheme
+3
Senior Security Engineer
Senior Security Engineer

NCC Group • Netherlands

On-site
EUR 90,000 - 130,000
Flexible Working
25 days holiday plus bank holidays
Pension
+5
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1