Detection Quality Engineer

Northwave Cyber Security

Utrecht

On-site

EUR 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Northwave Cyber Security is seeking a Detection Quality Engineer (Medior/Senior) to turn threat intelligence and attacker behavior into high-quality detections that protect organisations across the Netherlands and Europe.

The role focuses on detection engineering, threat research and continuous improvement of MDR capabilities. You will collaborate with analysts, Red Team members and threat intelligence specialists to shape the future of detection engineering within Northwave.

Qualifications

  • 3+ years of experience in cybersecurity with a focus on detection engineering, monitoring or detection rule development.
  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.
  • Experience analyzing attack techniques and adversary behavior.

Responsibilities

  • Design, build and continuously improve detection rules and monitoring content.
  • Develop advanced detection logic using Microsoft Sentinel, Defender and other platforms.
  • Translate attack techniques and adversary behavior into actionable detections.
  • Tune, validate and optimize detections to maximize signal and minimize noise.
  • Research emerging threats, attack campaigns and TTPs.
  • Map threats to MITRE ATT&CK and the Cyber Kill Chain.
  • Collaborate with analysts, engineers and threat intel to enhance coverage.

Skills

KQL
Microsoft Defender
Microsoft Sentinel
Suricata
Zeek
Python
Windows internals
Linux internals
Threat intelligence
Threat detection

Tools

Suricata
Zeek
EDR
SIEM
MISP
MITRE ATT&CK

Job description

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

Job Description

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who loves turning threat intelligence, attack research and adversary behavior into high-quality detections that make a real-world impact.

If you get excited by attack chains, KQL, Purple Teaming, threat hunting, and continuous improvement of detection capabilities, this role was built for you.

What you'll be doing
Detection Engineering
  • Design, build and continuously improve detection rules and monitoring content.
  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.
  • Translate attack techniques and adversary behavior into actionable detections.
  • Tune, validate and optimize detections to maximize signal and minimize noise.
Threat Research
  • Research emerging threats, attack campaigns and TTPs.
  • Analyze intelligence from MISP, CERT advisories, Red Team exercises and threat reports.
  • Map threats to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Identify gaps in monitoring coverage and proactively address them.
Continuous Improvement
  • Improve SOC monitoring capabilities through automation and innovation.
  • Contribute to Purple Team initiatives and validation of detection coverage.
  • Work on strategic projects that enhance the quality, scalability and effectiveness of our MDR services.
  • Help shape the future of detection engineering within Northwave.
Collaboration & Communication
  • Work closely with analysts, engineers, threat intelligence specialists and Red Team members.
  • Document detections and provide guidance to operational teams.
  • Explain detection logic, use-case design choices and monitoring strategies to both technical and non-technical stakeholders.
Job Requirements
Must-have experience
  • 3+ years of experience in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development.
  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.
  • Experience analyzing attack techniques and adversary behavior.
Technical expertise
  • Strong KQL skills.
  • Understanding of Microsoft Defender technologies.
  • Experience with Microsoft Sentinel.
  • Knowledge of attack chains, adversary TTPs and modern threat landscapes.
  • Experience with Suricata rules and/or Zeek scripts.
  • Scripting or programming experience, preferably Python.
  • Solid knowledge of Windows and Linux internals.
  • Familiarity with threat intelligence and detection use-case development.
Personal qualities
  • Analytical and curious by nature.
  • Able to work independently while being a strong team player.
  • Comfortable engaging with stakeholders across multiple teams.
  • Proactive and improvement-driven.
  • Strong communication skills.
  • Security-minded with a healthy critical attitude.
Extra points if you have
  • Experience with Purple Teaming.
  • Knowledge of the MITRE ATT&CK framework.
  • Experience validating detections against real attack simulations.
  • Experience in MDR, SOC or Incident Response environments.
  • Knowledge of detection-as-code methodologies.
  • Experience automating security workflows.
Who You'll Join

You will become part of the Detection Quality team, a highly technical group of engineers responsible for the detections of our SOC.

Our values are simple:

  • Quality first
  • Continuous improvement
  • Efficiency through automation
  • Ownership and responsibility
  • Customer impact

We challenge each other, support each other and continuously push our detection capabilities to the next level.

Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at youri.roelofs@northwave-cybersecurity.com .

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Quality Engineer
Detection Quality Engineer

Northwave • Utrecht

On-site
EUR 70,000 - 110,000
Detection Quality Engineer: Build High‑Impact Threat Detections
Detection Quality Engineer: Build High‑Impact Threat Detections

Northwave • Utrecht

On-site
EUR 70,000 - 110,000
SOC Detection Quality Engineer - Threat Detection Innovator
SOC Detection Quality Engineer - Threat Detection Innovator

Northwave Cyber Security • Utrecht

On-site
EUR 70,000 - 110,000
Senior Stack Engineer
Senior Stack Engineer

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
Security Automation Engineer
Security Automation Engineer

Northwave • Utrecht

Hybrid
EUR 50,000 - 70,000
Competitive salary with annual review
Pension contributions
25 vacation days plus national holidays
+3
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Haarlemmermeer

On-site
EUR 70,000 - 110,000
Senior Stack Engineer
Senior Stack Engineer

Northwave • Utrecht

On-site
EUR 60,000 - 80,000
SOC Analyst
SOC Analyst

Northwave Cyber Security • Utrecht

On-site
EUR 55,000 - 75,000
25 vacation days plus all Dutch national holidays
€200 net annual allowance for flexible and remote working
Learning budget from €700 to €1,200 per year
Security Engineer - MDR
Security Engineer - MDR

Schuberg Philis • Netherlands

Hybrid
EUR 65,000 - 85,000
High-quality workspaces
Training and mentoring
Team outings
+1
Experienced Red Team Operator
Experienced Red Team Operator

Northwave Cyber Security • Utrecht

Hybrid
EUR 80,000 - 110,000
Hybrid working and international reloc
Training budget and certifications
Professional equipment provided
+1