Threat Detection Lead

E-Resourcing Belgium BV
Ixelles, Belgium
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
Dutch, English, French
Experience level
Senior

Job location

Ixelles, Belgium

Tech stack

Computer Security
Intrusion Detection and Prevention
Microsoft Security Essentials
Red Team (Cyber Security)
Security Information and Event Management
Scripting (Bash/Python/Go/Ruby)
Delivery Pipeline
Mitre Att&ck
QRadar
Cyber Threat Analysis
Cybercrime
Microsoft Sentinel
Purple Team (Cyber Security)
Splunk
Software Version Control
Blue Team (Cyber Security)

Job description

We are looking for an experienced security professional to lead our threat detection capabilities. This is a hands-on leadership role with real ownership: you will design detections that actually catch attackers, drive our threat hunting programme, and be the go-to person for continuous security improvement. You will have the opportunity to contribute to the broader security community and help build a team around you, shaping the future of our security operations in a highly regulated, mission-critical environment.

What You Will

  • Do Design, build, and maintain detection rules across SIEM and XDR platforms, with full lifecycle ownership from use case creation to retirement.
  • Conduct gap analyses against threat actor TTPs using the MITRE ATT&CK framework to identify and close coverage blind spots.
  • Lead and participate in incident response efforts, including containment, investigation, and remediation.
  • Run purple team exercises and breach & attack simulations to validate and improve detection coverage.
  • Build and maintain a Detection-as-Code framework with CI/CD pipelines and version control develop and execute threat hunting hypotheses based on threat intelligence and emerging attack research.
  • Translate threat intelligence feeds and reports into actionable detections.
  • Support red team, TIBER, and DORA testing as the blue team counterpart.
  • Contribute to incident response plan development and tabletop exercises.
  • Share knowledge internally and represent the organisation in relevant industry groups (ISACs, CSIRTs, working groups)

Requirements

  • Several years of hands-on experience in detection engineering, SOC, or CSIRT roles.
  • Deep familiarity with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, or similar.
  • Proven experience building and running SOAR playbooks and automation pipelines.
  • Solid understanding of attacker TTPs and how to operationalise threat intelligence.
  • Experience with forensics, threat hunting, and incident handling at L2/L3 level.
  • Ability to lead a team or a functional working group, combining technical depth with people leadership.
  • Active participation in the security community (conferences, working groups, open-source contributions) is a strong differentiator.
  • Trilingual proficiency in Dutch, English, and French (NL, EN, FR) is essential.

Nice to Have

  • Experience in Government, Defence, Financial Services, or Critical Infrastructure sectors.
  • Familiarity with OT/ICS security.
  • Python scripting for automation and tooling.
  • Involvement in inter-CSIRT coordination or security coalitions.
  • Relevant certifications such as: Microsoft Security certifications (e.g., SC-200)Threat Hunting or Threat Intelligence certificationsCISM, CISSP, or equivalent.

Apply for this position