Cyber Threat Detection Analyst - Engineer (f/m)
Core
Conduct visibility and detection gap analysis, perform adversary emulation, and develop high-fidelity detection rules to strengthen security posture.
Role type
Detection Engineer
Builds
Detection rules, preventive controls, and detection coverage
Domain
Cybersecurity / Threat Detection
Required skills
MITRE ATT&CK framework, adversary emulation, scripting (Python, PowerShell, Bash), query languages (KQL, SQL, Splunk SPL), threat intelligence analysis
Preferred skills
Offensive security certifications (OSCP, OSEP, CRTO, GXPN, GPEN, GCIH), Cyber Threat Intelligence (CTI) training, SOC Analyst experience
Technologies
Python, PowerShell, Bash, SQL, KQL, Splunk SPL
Responsibilities
Conduct visibility and detection gap analysis based on Cyber Threat Intelligence (CTI) and attack surfaces; Perform adversary emulation and simulations to validate detection coverage; Develop, test, and tune high-fidelity detection rules and preventive controls; Collaborate with SOC and incident response teams to streamline alert triage and optimize playbooks
Seniority
Mid-Senior, hands-on IC