Cyber Threat Detection Analyst / Engineer (f/m)
Core
Analyze cyber threat intelligence and attack surfaces to identify detection gaps, develop high-fidelity detection rules, and perform adversary emulation to validate security coverage.
Role type
Detection Engineer / Threat Hunter
Builds
Detection rules, preventive controls, and validated detection coverage
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
Adversary emulation, MITRE ATT&CK framework mapping, detection rule development, alert triage optimization, scripting (Python, PowerShell, Bash), query languages (KQL, SQL, Splunk SPL)
Preferred skills
Cyber Threat Intelligence (CTI), SOC Analyst experience, offensive security certifications (OSCP, OSEP, CRTO, GXPN, GPEN, GCIH)
Technologies
Python, PowerShell, Bash, KQL, SQL, Splunk SPL, MITRE ATT&CK
Responsibilities
Conduct visibility and detection gap analyses, perform adversary emulation and simulations, develop and tune detection rules, collaborate with SOC teams to optimize playbooks and reduce false positives
Seniority
Mid-Senior, hands-on IC