Threat Detection Specialist - MITRE ATT&CK Coverage for NATO with security clearance
WLG
Bergen, Belgium
14 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Cloud Computing Security
Code Review
Information Model
Intrusion Detection and Prevention
Kusto Query Language
Security Information and Event Management
Mitre Att&ck
Cyber Threat Analysis
Purple Team (Cyber Security)
Software Version Control
Job description
- Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
- Writing detection logic in the languages that suit it - Sigma, SPL, KQL.
- Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
- Turning threat intelligence and purple team findings into working automated detections.
- Running a proper detection lifecycle - design, development, testing, deployment, monitoring, improvement, review - and improving the quality metrics behind it.
- Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
- Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
- Supporting incident handlers and threat hunters when an investigation is live.
Requirements
- Real detection engineering experience, and the version control and code review habits that make it repeatable.
- Hands-on work with a major SIEM and with endpoint and network detection tooling.
- Fluency in at least one detection language, and enough scripting to automate the rest.
- Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
- Professional English, and the ability to explain a detection decision to people who did not write it.
About the company
A multinational defence organisation is strengthening the detection engineering side of its security operations centre. This is not alert triage: you build the content the analysts depend on, measure whether it works, and close the gaps you find.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.be
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
CH
Chris Heilmann
about 2 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
11 months ago
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago