Detection Engineer: SIEM, BAS & Threat Intel Expert

Philips

Best

Hybrid

EUR 61,000 - 102,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working
Paid time-off
Health and wellbeing benefits
Learning and development opportunities

Job summary

Philips is seeking a Detection Engineer to join the Cyber Defense Capabilities team. You will design, implement, and validate high-fidelity detection capabilities for CSIRT, building rules, correlating data, and performing BAS against evolving threat intel and TTPs.

You will map detections to MITRE ATT&CK, integrate threat intel, automate enrichment with SOAR, and collaborate with IR and threat hunting. A strong background in SIEMs and cloud security is required.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, or a related field.
  • Minimum 2 years of experience in security architecture, network security or related areas.
  • Strong experience with SIEM platforms (e.g., Splunk, Sentinel).
  • Proficiency in detection engineering, log parsing, and data normalization.
  • Knowledge of MITRE ATT&CK and threat intel integration.
  • Python or PowerShell scripting skills and cloud security exposure.

Responsibilities

  • Develop, test, and maintain detection rules, signatures, and correlation logic.
  • Conduct regression testing to ensure detections stay effective after updates.
  • Perform BAS to validate detections against threat intel and TTPs.
  • Map detection logic to MITRE ATT&CK techniques and prioritize coverage.
  • Integrate threat intel feeds, IOCs, and patterns into detection workflows.
  • Tune detections to reduce false positives and improve alert fidelity.
  • Collaborate with IR and threat hunting, conduct purple team exercises.
  • Automate enrichment, correlation, and triage with SOAR playbooks.
  • Document detections, maintain repositories, and test playbooks.
  • Contribute to SOC metrics like detection coverage and BAS validation.

Skills

SIEM proficiency
Threat intelligence
Purple team experience
Cloud security
Python scripting
PowerShell scripting

Education

Bachelor's degree in Cybersecurity or CS

Tools

Splunk
Microsoft Sentinel
AttackIQ
Caldera
SOAR platforms
Kubernetes

Job description

Philips is seeking a Detection Engineer to join the Cyber Defense Capabilities team. You will design, implement, and validate high-fidelity detection capabilities for CSIRT, building rules, correlating data, and performing BAS against evolving threat intel and TTPs.

You will map detections to MITRE ATT&CK, integrate threat intel, automate enrichment with SOAR, and collaborate with IR and threat hunting. A strong background in SIEMs and cloud security is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: SIEM, BAS & Threat Intelligence
Detection Engineer: SIEM, BAS & Threat Intelligence

Philips Iberica SAU • Netherlands

Remote
EUR 61,000 - 102,000
Hybrid working
Health & wellbeing benefits
Learning & development
+1
Detection Engineer
Detection Engineer

Philips • Best

Hybrid
EUR 61,000 - 102,000
Hybrid working
Paid time-off
Health and wellbeing benefits
+1
Detection Engineer
Detection Engineer

Philips Iberica SAU • Netherlands

Remote
EUR 61,000 - 102,000
Hybrid working
Health & wellbeing benefits
Learning & development
+1
Detection Engineer - Custom Detections & SIEM Expertise
Detection Engineer - Custom Detections & SIEM Expertise

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
MDR Threat Hunter & Detection Engineer
MDR Threat Hunter & Detection Engineer

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Detection Engineer
Detection Engineer

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
Detection Engineer
Detection Engineer

NCC Group • 't Haantje

On-site
EUR 65,000 - 95,000
Laptop and business phone
Remote work allowance
Lunch in office
+1
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Detection Engineer – SIEM & Cyber Defense
Detection Engineer – SIEM & Cyber Defense

Werken voor Nederland • Huis ter Heide

On-site
EUR 40,000 - 64,000