Cyber Detection Engineer
Core
Develop detection rules and scenarios in SIEM/EDR platforms to identify real threats and stop attacks before they gain a foothold.
Role type
Cyber Detection Engineer (SOC/Threat Hunting)
Builds
Detection rules, Use Cases, and threat hunting scenarios for Microsoft Sentinel, Splunk ES, and SentinelOne.
Domain
Cybersecurity, Threat Intelligence, Log Analysis
Required skills
SIEM (Microsoft Sentinel, Splunk ES), EDR (SentinelOne), log analysis, threat hunting, MITRE ATT&CK, Sigma, anomaly detection, pattern recognition
Preferred skills
SOC/CSIRT experience, deep log analysis expertise, experimental mindset, new technology exploration
Responsibilities
Develop detection rules in Microsoft Sentinel, Splunk ES, and SentinelOne; Analyze raw data and log streams to detect anomalies and patterns; Contribute to Threat Hunting activities and develop Use Cases; Collaborate with SOC and IRT teams for testing and improvement; Document and share insights to strengthen the technical environment.
Seniority
Mid-level (3+ years experience)