Threat Detection Specialist - MITRE ATT&CK Coverage for NATO with security clearance

WLG
Bergen, Belgium
14 days ago
Apply on www.adzuna.be
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Code Review Information Model Intrusion Detection and Prevention Kusto Query Language Security Information and Event Management Mitre Att&ck Cyber Threat Analysis Purple Team (Cyber Security) Software Version Control

Job description

  • Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling.
  • Writing detection logic in the languages that suit it - Sigma, SPL, KQL.
  • Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind.
  • Turning threat intelligence and purple team findings into working automated detections.
  • Running a proper detection lifecycle - design, development, testing, deployment, monitoring, improvement, review - and improving the quality metrics behind it.
  • Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next.
  • Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up.
  • Supporting incident handlers and threat hunters when an investigation is live.

Requirements

  • Real detection engineering experience, and the version control and code review habits that make it repeatable.
  • Hands-on work with a major SIEM and with endpoint and network detection tooling.
  • Fluency in at least one detection language, and enough scripting to automate the rest.
  • Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster.
  • Professional English, and the ability to explain a detection decision to people who did not write it.

About the company

A multinational defence organisation is strengthening the detection engineering side of its security operations centre. This is not alert triage: you build the content the analysts depend on, measure whether it works, and close the gaps you find.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.adzuna.be
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:10 min

Defining data semantics through standardized information modeling

Alexander Allmendinger · LIVE

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:32 min

Pairing with teams for continuous threat modeling

Nazneen Rupawalla · World Congress 2022

1:22 min

Introduction to specialized document extraction models

Etienne Bernard Etienne Bernard · World Congress 2026 Europe

1:19 min

Enhancing product safety through continual red teaming operations

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

Videos

See all

Related articles

See all