Security Detection Engineer

SoftServe

Poland

On-site

PLN 180,000 - 280,000

Full time

12 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SoftServe is seeking a proactive security data scientist to develop detection logic against real-world telemetry. You will treat detections as code, with versioning, peer review, testing and continuous improvement across network data and platform telemetry.

You will collaborate with threat intelligence teams to convert research into actionable content, build scalable detections on Databricks, and help deploy them in SaaS and on‑prem environments, while enabling threat hunting and investigations.

Qualifications

  • Proven experience writing detection content for network threats.
  • Strong networking knowledge including TCP/IP, DNS, HTTP/S, TLS.
  • Proficient in Python and SQL for data analysis and detection development.
  • Experience with Sigma/Snort/Suricata detection formats.

Responsibilities

  • Design and build behavioral models to detect malicious network activity.
  • Develop detections for beaconing, DGA, data staging, lateral movement, DNS tunneling.
  • Translate use cases into production-grade detection logic and indicators.
  • Collaborate with threat intel teams to turnkey new content.
  • Tune detections using metrics like precision, recall, and MITRE ATT&CK coverage.
  • Use Telemetry on Databricks to validate and improve performance.
  • Work with engineering to productionize detections in a SaaS service.

Skills

Python
SQL
Network security
Threat detection
Data analysis
MITRE ATT&CK

Education

Bachelor's degree in CS/Engineering

Tools

Sigma
Snort
Suricata
Databricks

Job description

About The Role

In this role, you will work at the intersection of network security, data science, and software engineering, focusing on developing detection logic against real-world telemetry. You will treat detections as code, meaning they will be version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives.

In this role, you will work at the intersection of network security, data science, and software engineering, focusing on developing detection logic against real-world telemetry. You will treat detections as code, meaning they will be version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives. You will primarily work with network telemetry, including NetFlow, DNS queries, TLS certificate data, SMB filenames, and other L7 metadata extracted from firewall connection records. Over time, you will also help evolve detection capabilities as the platform incorporates endpoint and identity signals.

Responsibilities
  • Design and build behavioral models to detect malicious activity and identify meaningful anomalies in network behavior
  • Develop detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunneling, scanning, port hopping, and unusual remote administration activity
  • Translate concrete detection use cases into production-ready detection logic, signatures, and behavioral indicators
  • Collaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into actionable detection content
  • Build, evaluate, and continuously tune detections using efficacy metrics such as precision, recall, false-positive rate, and MITRE ATT&CK coverage
  • Use production-scale telemetry on Databricks to validate and improve detection performance
  • Work with engineering teams to productionize detections as part of a SaaS service, with potential deployment to on-premise environments
  • Support threat hunting, investigations, and triage activities with detection expertise
  • Use threat intelligence platforms and OSINT sources to enrich detections with current threat context, reputation data, and IOCs
  • Apply networking and network security knowledge to model traffic behavior and create precise, low-noise detection logic
  • Document detection methodology, assumptions, tuning decisions, and share knowledge across security and engineering teams
Requirements
  • Proven experience developing code-like detection content for network threats, including rule-based, signature-based, or behavioral detections
  • Strong knowledge of networking and network security, including TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors
  • Coding or scripting proficiency for detection development and data analysis, especially with Python and SQL
  • Experience with rule languages or detection formats such as Sigma, Snort, Suricata, or similar
  • Practical experience applying AI/ML techniques to security detection, including anomaly detection, classification, or behavioral modeling
  • Experience with SecOps workflows, including threat hunting, incident investigation support, and improving detections based on operational findings
  • Experience using threat intelligence tools, feeds, and OSINT sources to enrich and contextualize detection logic
  • Familiarity with detection frameworks such as MITRE ATT&CK and mapping detections to adversary tactics and techniques
  • Experience with NDR platforms, security analytics, or SIEM solutions
  • Strong analytical and problem-solving skills, with high attention to detail
  • Clear documentation and cross-team communication skills
  • Endpoint security experience is a strong plus, but not mandatory

SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer (AI-Augumented)
Senior Detection Engineer (AI-Augumented)

Procter & Gamble • Poland

On-site
PLN 240,000 - 360,000
P&G-sized projects
Self-development opportunities
Competitive salary & benefits
Network Threat Detection Engineer
Network Threat Detection Engineer

SoftServe • Poland

On-site
PLN 180,000 - 280,000
Security Detection Engineer III
Security Detection Engineer III

F5 Networks, Inc.  • Warszawa

Hybrid
PLN 260,000 - 380,000
Staff Product Manager - AI SIEM, Detection and Response
Staff Product Manager - AI SIEM, Detection and Response

SentinelOne • Poland

On-site
PLN 240,000 - 340,000
RSUs
ESPP
Leave benefits
+6
Security Engineer - Detection Engineering and Threat Modeling
Security Engineer - Detection Engineering and Threat Modeling

Hitachi, Ltd. • Poland

On-site
PLN 110,000 - 140,000
Security Engineer - Detection Engineering and Threat Modeling
Security Engineer - Detection Engineering and Threat Modeling

Hitachi Energy • Kraków

On-site
PLN 120,000 - 180,000
Private medical care
Life insurance
Home office equipment allowance
+2
Network Security Engineer
Network Security Engineer

Uvation • Poland

On-site
PLN 100,000 - 120,000
Senior Networking Engineer
Senior Networking Engineer

SoftServe • Poland

On-site
PLN 180,000 - 300,000
Security Consulting Engineer
Security Consulting Engineer

Cisco • Kraków

On-site
PLN 180,000 - 260,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000