Detection Engineer: Splunk SIEM & MITRE ATT&CK Expert

The Boston Consulting Group GmbH

Lisboa

Presencial

EUR 70 000 - 110 000

Tempo integral

14 dias+

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Resumo da oferta

Boston Consulting Group GmbH in Portugal is seeking an experienced Detection Engineer to fortify its security posture by building high-confidence detections grounded in real threat telemetry.

You'll translate threat intel and offensive findings into production-ready detections across a large enterprise, collaborate with CSIRT, Security Engineering, and providers, and continually validate against evolving adversary techniques.

Qualificações

  • Experience building production detection rules across enterprise security platforms.
  • Strong knowledge of MITRE ATT&CK and translating techniques into detections.
  • Proficient in Splunk SPL or similar query languages for security.
  • Understanding of offensive security and validating detections via purple testing.
  • Analytical mindset with ability to decide under evolving data.

Responsabilidades

  • Collaborate with Detection Engineering, CSIRT, Security Engineering, and providers to develop and improve detection content.
  • Develop and maintain detection rules using SIEM, EDR, and other platforms.
  • Translate red team findings and threat intel into production-ready detections.
  • Validate detections against telemetry before deployment.
  • Tune content using feedback to reduce false positives.
  • Contribute to ATT&CK coverage by identifying gaps.
  • Develop investigation guidance and runbooks for triage.
  • Partner with Security Engineering to ensure telemetry supports detection development.
  • Maintain detection documentation and lifecycle activities.

Conhecimentos

Detection rules
MITRE ATT&CK
Splunk SPL
Offensive security
Analytical thinking
Cross-team collaboration
Telemetry understanding

Ferramentas

Splunk
EDR
SIEM

Descrição da oferta de emprego

Boston Consulting Group GmbH in Portugal is seeking an experienced Detection Engineer to fortify its security posture by building high-confidence detections grounded in real threat telemetry.

You'll translate threat intel and offensive findings into production-ready detections across a large enterprise, collaborate with CSIRT, Security Engineering, and providers, and continually validate against evolving adversary techniques.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Detection Engineer: Build & Validate SIEM Detections
Detection Engineer: Build & Validate SIEM Detections

Boston Consulting Group • Portugal

Presencial
EUR 60 000 - 100 000
Detection Engineer: SIEM & Threat Detection
Detection Engineer: SIEM & Threat Detection

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 60 000 - 90 000
Threat Detection Content Architect
Threat Detection Content Architect

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 60 000 - 85 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

Boston Consulting Group • Portugal

Presencial
EUR 60 000 - 100 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

The Boston Consulting Group GmbH • Lisboa

Presencial
EUR 70 000 - 110 000
Global Cybersecurity Analyst - Security Engineer
Global Cybersecurity Analyst - Security Engineer

Boston Consulting Group (BCG) • Lisboa

Presencial
EUR 60 000 - 90 000
Threat Detection & Cyber Defense Analyst
Threat Detection & Cyber Defense Analyst

Siemens • Lisboa

Presencial
EUR 45 000 - 65 000
Threat Detection Content Architect
Threat Detection Content Architect

Boston Consulting Group • Portugal

Presencial
EUR 70 000 - 90 000
Global Cybersecurity Manager - Security Engineer
Global Cybersecurity Manager - Security Engineer

Boston Consulting Group • Portugal

Presencial
EUR 70 000 - 90 000
SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)
SOC Threat Hunter & SIEM Tuning Engineer (Lisbon/Porto)

Claranet limited • Lisboa

Híbrido
EUR 40 000 - 60 000