> Markdown version of [/jobs/ext/2799803-threat-detection-specialist-mitre-att-ck-coverage-for-nato-with-security-clearance](https://www.wearedevelopers.com/jobs/ext/2799803-threat-detection-specialist-mitre-att-ck-coverage-for-nato-with-security-clearance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Threat Detection Specialist - MITRE ATT&CK Coverage for NATO with security clearance - **Company:** WLG - **Location:** Bergen, Belgium - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Code Review, Information Model, Intrusion Detection and Prevention, Kusto Query Language, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, Purple Team (Cyber Security), Software Version Control - **Published:** September 9, 2026 - **Apply:** https://www.adzuna.be/details/5876189932 ## About the Role * Real detection engineering experience, and the version control and code review habits that make it repeatable. * Hands-on work with a major SIEM and with endpoint and network detection tooling. * Fluency in at least one detection language, and enough scripting to automate the rest. * Familiarity with adversary tradecraft and with the ATT&CK framework as a working tool rather than a poster. * Professional English, and the ability to explain a detection decision to people who did not write it. ## Description * Designing, building and maintaining detection rules, alerts and analytics across SIEM, EDR and XDR, network detection and cloud security tooling. * Writing detection logic in the languages that suit it - Sigma, SPL, KQL. * Building detections around adversary behaviour and mapping them to the MITRE ATT&CK framework, with advanced persistent threats in mind. * Turning threat intelligence and purple team findings into working automated detections. * Running a proper detection lifecycle - design, development, testing, deployment, monitoring, improvement, review - and improving the quality metrics behind it. * Assessing detection coverage across on-premise and cloud estates, and doing the gap analysis that says where to invest next. * Reviewing newly ingested log sources against the common information model, auditing field extractions and event mappings, and chasing data owners when something does not line up. * Supporting incident handlers and threat hunters when an investigation is live. ## Related Videos - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [OPC UA Updates and Trends](https://www.wearedevelopers.com/videos/1215-opc-ua-updates-and-trends) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Developer Experience, Platform Engineering and AI powered Apps](https://www.wearedevelopers.com/videos/990-developer-experience-platform-engineering-and-ai-powered-apps) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)