Cyber Detection Engineer
Core
Develop detection rules and scenarios in SIEM/EDR platforms to identify real threats and stop attacks before they gain a foothold.
Role type
Cyber Detection Engineer (SOC/Threat Hunting)
Builds
Detection rules, Use Cases, and threat hunting scenarios for Microsoft Sentinel, Splunk ES, and SentinelOne.
Domain
Cybersecurity, Threat Intelligence, Log Analysis
Deliverable
production ML models | product features | dashboards & analysis
Required skills
SIEM (Microsoft Sentinel, Splunk ES), EDR (SentinelOne), log analysis, threat hunting, MITRE ATT&CK, Sigma, anomaly detection, pattern recognition
Preferred skills
SOC/CSIRT experience, deep log analysis expertise, experimental mindset, new technology exploration
Responsibilities
Develop detection rules in Microsoft Sentinel, Splunk ES, and SentinelOne; Analyze raw data and log streams to detect anomalies and patterns; Contribute to Threat Hunting activities and develop Use Cases; Collaborate with SOC and IRT teams for testing and improvement; Document and share insights to strengthen the technical environment.
Seniority
Mid-level (3+ years experience)