Detection Engineer: SIEM, BAS & Threat Intelligence

Philips Iberica SAU

Netherlands

Remote

EUR 61,000 - 102,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid working
Health & wellbeing benefits
Learning & development
Paid time off

Job summary

Philips is seeking a Detection Engineer to design, implement, and continuously validate high-fidelity detection capabilities within the Cyber Defense Capabilities team. You will develop, test, and tune SIEM detections, perform BAS exercises, and map coverage to MITRE ATT&CK.

You will work with incident responders, threat hunters, and threat intelligence teams to improve detections and reduce MTTD, in a primarily onsite/office environment in the Netherlands.

Qualifications

  • Minimum 2 years of experience in areas such as Security Architecture, Network Security, or Information Security.
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • Strong experience with SIEM platforms (e.g., Splunk, Sentinel).
  • Proficiency in detection engineering, log parsing, and data normalization.
  • Familiarity with AI/ML concepts in cybersecurity for threat analysis and automation.

Responsibilities

  • Develop, test, and maintain detection rules, signatures, and correlation logic in SIEM and related platforms.
  • Conduct regression testing of detection rules to ensure accuracy and resilience after updates.
  • Perform breach and attack simulations (BAS) to validate use cases tied to threat intel and TTPs.
  • Map detection logic to MITRE ATT&CK and ensure coverage of priority threat scenarios.
  • Integrate threat intelligence feeds, IOCs, and behavioral patterns into detection workflows.
  • Tune detection logic to reduce false positives and improve alert fidelity.
  • Collaborate with incident response and threat hunting teams to address gaps and validate detections.
  • Automate enrichment, correlation, and triage via SOAR playbooks and scripts.
  • Maintain documentation, repositories, and test playbooks for continuity.
  • Contribute to SOC metrics including coverage, false positives, and BAS validation.

Job description

Philips is seeking a Detection Engineer to design, implement, and continuously validate high-fidelity detection capabilities within the Cyber Defense Capabilities team. You will develop, test, and tune SIEM detections, perform BAS exercises, and map coverage to MITRE ATT&CK.

You will work with incident responders, threat hunters, and threat intelligence teams to improve detections and reduce MTTD, in a primarily onsite/office environment in the Netherlands.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer: SIEM, BAS & Threat Intel Expert
Detection Engineer: SIEM, BAS & Threat Intel Expert

Philips • Best

Hybrid
EUR 61,000 - 102,000
Hybrid working
Paid time-off
Health and wellbeing benefits
+1
Detection Engineer
Detection Engineer

Philips Iberica SAU • Netherlands

Remote
EUR 61,000 - 102,000
Hybrid working
Health & wellbeing benefits
Learning & development
+1
Detection Engineer
Detection Engineer

Philips • Best

Hybrid
EUR 61,000 - 102,000
Hybrid working
Paid time-off
Health and wellbeing benefits
+1
Detection Engineer - Custom Detections & SIEM Expertise
Detection Engineer - Custom Detections & SIEM Expertise

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
Detection Engineer
Detection Engineer

NCC Group • Rijswijk

Hybrid
EUR 70,000 - 100,000
Flexible working hours
Remote work allowance
Laptop and business phone
+2
MDR Threat Hunter & Detection Engineer
MDR Threat Hunter & Detection Engineer

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
Detection Engineer
Detection Engineer

NCC Group • 't Haantje

On-site
EUR 65,000 - 95,000
Laptop and business phone
Remote work allowance
Lunch in office
+1
Detection Engineer — Custom Threat Detections (Remote)
Detection Engineer — Custom Threat Detections (Remote)

NCC Group • Netherlands

Remote
EUR 60,000 - 90,000
Flexible working hours
Pension scheme
26 vacation days
+5
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
Detection Engineer – SIEM & Cyber Defense
Detection Engineer – SIEM & Cyber Defense

Werken voor Nederland • Huis ter Heide

On-site
EUR 40,000 - 64,000