Detection Quality Engineer

Northwave

Utrecht

On-site

EUR 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Northwave is seeking a Detection Quality Engineer (Medior/Senior) to turn threat intelligence into high-quality detections across the Netherlands and Europe. You will design detection rules, leverage Microsoft Sentinel and Defender, and translate adversary behavior into actionable detections.

Join a highly technical team, collaborate with analysts and Red Team, and drive automation and continuous improvements in MDR services while shaping the future of detection engineering at Northwave.

Qualifications

  • 3+ years in cybersecurity focusing on detection engineering, monitoring, or rule development.
  • Experience designing and maintaining detections within EDR/XDR/SIEM environments.
  • Experience analyzing attack techniques and adversary behavior.

Responsibilities

  • Design, build and continuously improve detection rules and monitoring content.
  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.
  • Translate attack techniques and adversary behavior into actionable detections.
  • Tune, validate and optimize detections to maximize signal and minimize noise.
  • Research emerging threats, attack campaigns and TTPs.
  • Map threats to MITRE ATT&CK and the Cyber Kill Chain.
  • Identify gaps in monitoring coverage and proactively address them.
  • Collaborate with analysts, threat intelligence specialists and Red Team members.
  • Document detections and provide guidance to operational teams.

Skills

KQL
Microsoft Defender
Microsoft Defender technologies
Microsoft Sentinel
Attack chains / TTPs
Suricata rules
Zeek scripts
Python
Windows internals
Linux internals

Tools

Microsoft Defender
Microsoft Sentinel
Suricata
Zeek
Python

Job description

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who loves turning threat intelligence, attack research and adversary behavior into high-quality detections that make a real-world impact.

If you get excited by attack chains, KQL, Purple Teaming, threat hunting, and continuous improvement of detection capabilities, this role was built for you.

What you'll be doing

Detection Engineering

  • Design, build and continuously improve detection rules and monitoring content.

  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.

  • Translate attack techniques and adversary behavior into actionable detections.

  • Tune, validate and optimize detections to maximize signal and minimize noise.

Threat Research

  • Research emerging threats, attack campaigns and TTPs.

  • Analyze intelligence from MISP, CERT advisories, Red Team exercises and threat reports.

  • Map threats to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.

  • Identify gaps in monitoring coverage and proactively address them.

Continuous Improvement

  • Improve SOC monitoring capabilities through automation and innovation.

  • Contribute to Purple Team initiatives and validation of detection coverage.

  • Work on strategic projects that enhance the quality, scalability and effectiveness of our MDR services.

  • Help shape the future of detection engineering within Northwave.

Collaboration & Communication

  • Work closely with analysts, engineers, threat intelligence specialists and Red Team members.

  • Document detections and provide guidance to operational teams.

  • Explain detection logic, use-case design choices and monitoring strategies to both technical and non-technical stakeholders.

Must-have experience

  • 3+ years of experience in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development.

  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.

  • Experience analyzing attack techniques and adversary behavior.

Technical expertise

  • Strong KQL skills.

  • Understanding of Microsoft Defender technologies.

  • Experience with Microsoft Sentinel.

  • Knowledge of attack chains, adversary TTPs and modern threat landscapes.

  • Experience with Suricata rules and/or Zeek scripts.

  • Scripting or programming experience, preferably Python.

  • Solid knowledge of Windows and Linux internals.

  • Familiarity with threat intelligence and detection use-case development.

Personal qualities

  • Analytical and curious by nature.

  • Able to work independently while being a strong team player.

  • Comfortable engaging with stakeholders across multiple teams.

  • Proactive and improvement-driven.

  • Strong communication skills.

  • Security-minded with a healthy critical attitude.

Extra points if you have

  • Experience with Purple Teaming.

  • Knowledge of the MITRE ATT&CK framework.

  • Experience validating detections against real attack simulations.

  • Experience in MDR, SOC or Incident Response environments.

  • Knowledge of detection-as-code methodologies.

  • Experience automating security workflows.

Who you'll join

You will become part of the Detection Quality team, a highly technical group of engineers responsible for the detections of our SOC.

Our values are simple:

  • Quality first

  • Continuous improvement

  • Efficiency through automation

  • Ownership and responsibility

  • Customer impact

We challenge each other, support each other and continuously push our detection capabilities to the next level.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Quality Engineer
Detection Quality Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
Detection Quality Engineer: Build High‑Impact Threat Detections
Detection Quality Engineer: Build High‑Impact Threat Detections

Northwave • Utrecht

On-site
EUR 70,000 - 110,000
SOC Detection Quality Engineer - Threat Detection Innovator
SOC Detection Quality Engineer - Threat Detection Innovator

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
SOC Analyst
SOC Analyst

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
25 vacation days plus all Dutch national holidays
€200 net annual allowance for flexible and remote working
Learning budget from €700 to €1,200 per year
Security Automation Engineer
Security Automation Engineer

Northwave • Utrecht

Hybrid
EUR 50,000 - 70,000
Competitive salary with annual review
Pension contributions
25 vacation days plus national holidays
+3
Senior Stack Engineer
Senior Stack Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
Experienced Red Team Operator
Experienced Red Team Operator

Northwave Cyber Security • Utrecht

Hybrid
EUR 80,000 - 110,000
Hybrid working and international reloc
Training budget and certifications
Professional equipment provided
+1
Senior Stack Engineer
Senior Stack Engineer

Northwave • Utrecht

On-site
EUR 60,000 - 80,000