Source description
About the role
Role: Detection Engineer
Contract Duration (if TP)- 11 months + Extendable based on performance
Hiring Mode – TP/FTC
Primary Skill (mandatory skill)- refer below
Precise Work Location- Amsterdam, Netherlands
Language Preference, if any- English
Is Remote work allowed- 2 days hybrid work
Experience required- Senior 5+ years of experience
5-6 Years of Relevant Experience.
You will be involved in the Detect stream of the Cyber Resilience program, working on building detection use cases.
The role consists of the following activities
Transform data into informative Security alerts
Analyse threat actors’ techniques and develop resilient detection content
Participate in purple teaming exercises and improve existing detection
Develop machine learning models to detect behavioural aspects to drive Security Detection.
Requirements
-
Must have:
-
Experience in creating threat detection use cases/models.
-
Implementation of SOAR Playbooks preferably on Azure Sentinel else Siemplify, XSOAR (Demisto) etc..
-
Implementation of SOAR Automation for Incidents.
-
Experineced in integration of security devices, deployment of SIEM Tools – Splunk.
-
Integrating with MS Defender, Identity for O365, Azure etc.
-
Strong defensive mindset with good understanding of threat actors TTPs and how to defend against these
-
Experience in working with Microsoft security products (i.e. Sentinel)
-
Experience with programming (preferably Python, REST API), automation or machine learning
-
Strong skills in query languages like SPL, KQL
-
Good command of the English language, both written and verbally
-
Nice to have:
-
Security certifications such as OSCP, GPEN, GCFA, GMON, GCDA
-
Job type: Full Time/Contract Division: eTeam Workforce Limited - Netherland Reference: 23-02312
More at eTeam