Founding Detection Engineer - Cloud Security (Azure & KQL)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Requirements
- Strong experience with Microsoft Sentinel and Defender for Cloud, Endpoint, or XDR
- Confidence writing KQL from scratch, and tuning it to reduce noise and improve signal
- Hands-on knowledge of MITRE ATT&CK and how it maps to real-world threats
- Experience scripting in PowerShell or Python
-
An ownership mindset - you’re proactive, technically curious, and comfortable building in the unknown
- Microsoft certifications (SC-200, AZ-500, or SC-100)
- Experience in startup, freelance, or early-stage environments
- A passion for sharing knowledge (brown-bags, tooling experiments, blog posts)
- Experience helping shape SOC processes or automation tooling
Benefits & conditions
58000-93600 per year Voltijd SLUIT BINNENKORT
What if you could build detection systems that protect critical national infrastructure - and shape the entire security stack from day one?
Cybersecurity is more than compliance - it’s infrastructure. We’re launching a new cybersecurity startup to protect cloud-native systems behind critical public services. As our first detection engineer, you’ll help define how we identify threats, respond to them, and build smart defenses from the ground up.
This isn’t about joining an existing team - you’ll shape the team. You’ll have full influence on how detection is built, automated, and scaled - with the freedom to choose the best tools for the job.
- Build and fine-tune threat detection strategies using Microsoft Sentinel and Defender tools
- Write and iterate on KQL queries to hunt signals and reduce alert fatigue
- Design and automate incident response workflows, using scripting and playbooks
- Work in Azure-based cloud environments, where security is core - not bolted on
- Translate threat intel into real detection logic, and share insights with team and clients
- Help shape how we think about Blue Team practices, from first draft to future roadmap, * A gross annual salary between €58,000 and €93,600, based on your experience
- 8% holiday allowance and a performance-based bonus
- Mobility budget or lease car option
- Hybrid working setup: remote flexibility with office access when needed
- 25 vacation days, solid pension scheme, and travel reimbursement
- €2,500 annual learning & development budget to stay current with the security landscape
- Access to professional hacker tools, cyber ranges, and internal labs
- Freedom to explore your ideas, contribute to open source, and participate in internal hackathons
- The chance to build from scratch - influencing not just tooling, but culture, process, and future hires
-
A real mission: helping protect national-level systems and making a measurable societal impact
- Step 1: Intro call
- Step 2: Meeting founder partners
- Step 3: Team interview + Technical deep-dive
- Step 4: Offer
We aim to complete the process within 5 working days of your first call.
Interested but not sure if you check every box? We’d still love to hear from you. No formal cover letter needed - just reach out and let’s start a conversation.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 138 - Are you secure about this?
Dev Digest 134 - Where pixels sing?
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents