Detection Engineer (German-speaking)

S-PRO

Polska

Hybrid

PLN 180,000 - 260,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible schedule
Remote work model
Medical insurance
Paid vacations
Paid Sick-leaves
Paid State holidays

Job summary

S-PRO is seeking an experienced SIEM/SOAR and detection engineering specialist to help further develop our existing SIEM setup. You will review and optimize the current configuration, analyze data sources, and enhance detection logic to reduce false positives.

You will work closely with cross-functional teams, apply MITRE ATT&CK mappings, and drive improvements across SOC processes. German language proficiency is required for collaboration with European clients, and remote work options are

Qualifications

  • Substantial hands-on experience with SIEM and detection engineering.
  • Experience with SOC processes and incident triage.
  • Experience with SOAR and security automation.
  • Strong knowledge of security data sources and integrations (identity, cloud, SaaS).
  • Detection engineering based on MITRE ATT&CK.
  • Experience with versioned, traceable maintenance of detections.
  • Hands-on mindset and ability to work independently.
  • Fluent in German.

Responsibilities

  • Review and critical evaluation of the existing SIEM setup.
  • Analysis of connected data sources and identification of gaps.
  • Analysis of existing detection rules, use cases, and cases.
  • Establishment of a baseline for case volume, processing effort, and false positives.
  • Identification of causes for high manual analysis effort.
  • Improvement of detection logic, prioritization, and case quality.
  • Design and implementation of additional data enrichment.
  • Identification and implementation of meaningful integrations.
  • Development or further development.

Skills

SIEM
SOAR
Detection engineering
MITRE ATT&CK
Sekoia
Incident triage
Automation
Data sources integration
German language

Tools

Sekoia platform
Detection-as-Code
SIEM tooling
SOAR tooling

Job description

S-PRO is a software development and IT consulting partner. We develop unique products tailored to the client’s needs to accelerate business. Our typical engagement is consultancy, discovery, build, and maintenance, with clients from fintech, healthcare, energy and other industries.

We are looking for an experienced SIEM/SOAR and detection engineering specialist to help further develop our existing SIEM setup.

Responsibilities:
  • Review and critical evaluation of the existing Sekoia/SIEM setup
  • Analysis of connected data sources and identification and resolution of relevant gaps
  • Analysis of existing detection rules, use cases, and cases
  • Establishment of a baseline for case volume, processing effort, and false positive rate at the start of the project
  • Identification of causes for high manual analysis effort
  • Improvement of detection logic, prioritization, and case quality
  • Design and implementation of additional data enrichment
  • Identification and implementation of meaningful integrations
  • Development or further development
Requirements:
  • Substantial hands‑on experience with SIEM and detection engineering
  • Experience with SOC processes and incident triage
  • Experience with SOAR and security automation
  • Strong knowledge of various security data sources and integrations, particularly identity, cloud (AWS), and SaaS
  • Detection engineering based on MITRE ATT&CK
  • Experience with versioned, traceable maintenance of detections (Detection-as-Code is a plus)
  • Experience with Sekoia
  • Hands‑on mindset and ability to work independently
  • Ability to critically analyze existing setups and implement pragmatic improvements
  • Willingness and ability to actively share knowledge
  • Fluent in German.
What we offer:
  • Long team focus: we create an environment of transparent communication, and minimal bureaucracy, which leads to long-term relationships.
  • Development of niche expertise: we are working in several niches, such as FinTech, healthcare, and logistics. Therefore, our employees can develop their own expertise in these domains.
  • Continuous learning: we create employee development plans / personal roadmaps /quick promotion processes.
  • Internal career development: 80% of our current executives were promoted to those positions within S‑PRO. We encourage initiative. If a person wants to set new challenges and grow, we will definitely support them.
Benefits and perks:
  • Flexible schedule.
  • Remote work model.
  • Medical insurance
  • Paid vacations
  • Paid Sick-leaves.
  • Paid State holidays.

By submitting your application for this position, you consent to the processing of your personal data for recruitment purposes in accordance with applicable data protection laws. Detailed information regarding the processing of personal data can be found at the following link: Сandidate Privacy

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Detection Engineer (SIEM/SOAR) — Remote & Flexible
Senior Detection Engineer (SIEM/SOAR) — Remote & Flexible

S-PRO • Polska

Hybrid
PLN 180,000 - 260,000
Flexible schedule
Remote work model
Medical insurance
+3
SSIEM Administrator / Engineer
SSIEM Administrator / Engineer

Andersen Lab • Kraków

On-site
PLN 180,000 - 240,000
Private health insurance
Sports compensation
Mentoring program
+2
Remote Cybersecurity Architect: SIEM & SOC Lead (German)
Remote Cybersecurity Architect: SIEM & SOC Lead (German)

Experis ManpowerGroup Sp. z o.o. • Poland

On-site
PLN 180,000 - 240,000
Cyber Threat Detection Analyst / Engineer (f/m)
Cyber Threat Detection Analyst / Engineer (f/m)

Bosch • Warszawa

Hybrid
PLN 180,000 - 240,000
Hybrid work with flexible hours
Private medical care
Life insurance
+1
Security Engineer - Detection Engineering and Threat Modeling
Security Engineer - Detection Engineering and Threat Modeling

Hitachi, Ltd. • Poland

On-site
PLN 110,000 - 140,000
AI Solution Architect
AI Solution Architect

S-PRO • Polska

Hybrid
PLN 180,000 - 240,000
Flexible schedule
Remote work model
Medical insurance
+3
Cyber Detection & Response Manager
Cyber Detection & Response Manager

Experis • Wrocław

Hybrid
PLN 262,000 - 276,000
MultiSport Plus
Group insurance
Medicover Premium
Cyber Threat Detection Analyst / Engineer (f/m)
Cyber Threat Detection Analyst / Engineer (f/m)

SmartRecruiters, Inc. • Warszawa

On-site
PLN 180,000 - 300,000
Hybrid work with flexible hours
Referral Bonus Program
Private medical care
+3
Principal Security Detection and Response Analyst (Tier 3 Analyst) German or French Speaker
Principal Security Detection and Response Analyst (Tier 3 Analyst) German or French Speaker

Trustwave • Polska

Remote
PLN 170,000 - 250,000
Life insurance
Medical insurance
Lunch card
+4
Python Engineer
Python Engineer

S-PRO • Polska

Hybrid
PLN 200,000 - 280,000
Flexible schedule
Remote work model
Medical insurance
+3