Security Engineer - Detection Engineering and Threat Modeling

Hitachi, Ltd.

Poland

On-site

PLN 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hitachi Energy in Krakow, Poland invites a Security Engineer specializing in Threat Modeling and Detection Engineering to strengthen our cybersecurity operations. You will design detection capabilities, onboard data sources, and drive automation to improve the effectiveness of the SOC.

In this role, you will implement detection rules within SIEM, build ingestion pipelines, and apply threat intelligence to enhance monitoring across endpoints, cloud, and networks.

Qualifications

  • 2–3 years of experience in detection engineering or security operations.
  • Experience writing and tuning SIEM detection rules and developing actionable detection content.
  • Knowledge in Python, KQL, SQL, or similar technologies used for security monitoring and automation.
  • Understanding of log sources across endpoint, identity, network, cloud, and infrastructure environments.
  • Experience with Microsoft Sentinel, Defender Suite, Azure, AWS, Docker, Linux, or similar security technologies is an advantage.
  • Familiarity with threat modeling, MITRE ATT&CK, log ingestion pipelines, and security automation practices.

Responsibilities

  • Design, develop, and tune detection rules within the SIEM to improve threat visibility.
  • Onboard new log sources by building ingestion pipelines, normalizing data, and ensuring high-quality integration into the SIEM.
  • Perform threat modeling of systems and log sources to identify detection requirements and security gaps.
  • Build and maintain automation solutions that improve SOC workflows, reporting, and operational efficiency.
  • Collaborate with cybersecurity and engineering teams to continuously enhance detection coverage against evolving threats.
  • Apply threat intelligence and frameworks such as MITRE ATT&CK to strengthen monitoring and response capabilities.
  • Contribute to detection-as-code practices and CI/CD‑driven security operations processes.
  • Support continuous improvement of security monitoring, alert quality, and overall cyber defense effectiveness.

Skills

Python
KQL
SQL
Threat modeling
MITRE ATT&CK
Log sources

Tools

Microsoft Sentinel
Defender Suite
Azure
AWS
Docker
Linux

Job description

Location

Krakow, Lesser Poland, Poland

The Opportunity

Join Hitachi Energy as a Security Engineer specializing in Threat Modeling and Detection Engineering, and play a critical role in strengthening our cybersecurity operations. In this position, you will design and enhance detection capabilities, onboard and secure new data sources, and drive automation that improves the effectiveness and efficiency of the Security Operations Center (SOC). Working at the intersection of threat detection, systems engineering, and cybersecurity, you will contribute to protecting critical infrastructure and enabling a proactive, intelligence-driven approach to cyber defense.

How You Will Make an Impact
  • Design, develop, and tune detection rules within the SIEM to improve threat visibility and reduce false positives
  • Onboard new log sources by building ingestion pipelines, normalizing data, and ensuring high-quality integration into the SIEM
  • Perform threat modeling of systems and log sources to identify detection requirements and security gaps
  • Build and maintain automation solutions that improve SOC workflows, reporting, and operational efficiency
  • Collaborate with cybersecurity and engineering teams to continuously enhance detection coverage against evolving threats
  • Apply threat intelligence and frameworks such as MITRE ATT&CK to strengthen monitoring and response capabilities
  • Contribute to detection-as-code practices and CI/CD‑driven security operations processes
  • Support continuous improvement of security monitoring, alert quality, and overall cyber defense effectiveness
Your Background
  • 2‑3 years of experience in detection engineering, security operations, or related cybersecurity engineering roles
  • Experience writing and tuning SIEM detection rules and developing actionable detection content
  • Knowledge in Python, KQL, SQL, or similar technologies used for security monitoring and automation
  • Understanding of log sources across endpoint, identity, network, cloud, and infrastructure environments
  • Experience with Microsoft Sentinel, Defender Suite, Azure, AWS, Docker, Linux, or similar security technologies is an advantage
  • Familiarity with threat modeling, MITRE ATT&CK, log ingestion pipelines, and security automation practices

NOTE: This is maternity coverage – 12 months contract.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Threat Modeling & SIEM Detection
Security Engineer - Threat Modeling & SIEM Detection

Hitachi Energy • Kraków

On-site
PLN 120,000 - 180,000
Private medical care
Life insurance
Home office equipment allowance
+2
Security Engineer - Detection Engineering and Threat Modeling
Security Engineer - Detection Engineering and Threat Modeling

Hitachi Energy • Kraków

On-site
PLN 120,000 - 180,000
Private medical care
Life insurance
Home office equipment allowance
+2
Threat Modeling & Detection Engineer — SIEM & Automation
Threat Modeling & Detection Engineer — SIEM & Automation

Hitachi, Ltd. • Poland

On-site
PLN 110,000 - 140,000
Cybersecurity Product Penetration Tester
Cybersecurity Product Penetration Tester

Hitachi, Ltd. • Poland

On-site
PLN 55,000 - 75,000
Engineer - Cybersecurity (Vulnerability & Threat Management)
Engineer - Cybersecurity (Vulnerability & Threat Management)

Sysco Corporation • Poland

Hybrid
PLN 40,000 - 60,000
Professional development opportunities
Collaborative culture
Modern security technologies
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Magnetics • Kraków

On-site
PLN 120,000 - 180,000
IT Engineer Cyber Security (m/k)
IT Engineer Cyber Security (m/k)

SMA Solar • Kraków

On-site
PLN 90,000 - 150,000
CyberSecurity Logging & Monitoring Service Specialist
CyberSecurity Logging & Monitoring Service Specialist

C&D Talent Advisory • Łódź

On-site
PLN 174,000 - 300,000
CyberSecurity Logging & Monitoring Service Specialist
CyberSecurity Logging & Monitoring Service Specialist

C&D Talent Advisory • Warszawa

On-site
PLN 174,000 - 300,000
CyberSecurity Logging & Monitoring Service Specialist
CyberSecurity Logging & Monitoring Service Specialist

C&D Talent Advisory • Katowice

On-site
PLN 174,000 - 300,000