Detection Quality Engineer
$43,200–$69,600 year
HybridUtrecht, Utrecht, The Netherlands
Job Summary
Design, build, and continuously improve detection rules and monitoring content using Microsoft Sentinel, Defender, and other security platforms. Translate attack techniques and adversary behavior into actionable detections, then tune, validate, and optimize them to maximize signal while minimizing noise. Research emerging threats, attack campaigns, and TTPs by analyzing intelligence from MISP, CERT advisories, and Red Team exercises to map gaps in coverage and proactively address them. Contribute to Purple Team initiatives, automate SOC monitoring capabilities, and document detection logic for operational teams. Work closely with analysts, engineers, and threat intelligence specialists to enhance the quality and scalability of MDR services.
Required Qualifications
- 3+ years of experience in cybersecurity with a strong focus in detection engineering, monitoring or detection rule development
- Experience designing and maintaining security detections within an EDR, XDR or SIEM environment
- Experience analyzing attack techniques and adversary behavior
- Strong KQL skills
- Understanding of Microsoft Defender technologies
- Experience with Microsoft Sentinel
- Knowledge of attack chains, adversary TTPs and modern threat landscapes
- Experience with Suricata rules and/or Zeek scripts
- Scripting or programming experience, preferably Python
- Solid knowledge of Windows and Linux internals
- Familiarity with threat intelligence and detection use-case development
- Analytical and curious by nature
- Able to work independently while being a strong team player
- Comfortable engaging with stakeholders across multiple teams
- Proactive and improvement-driven
- Strong communication skills
- Security-minded with a healthy critical attitude
Desired Qualifications
- Experience with Purple Teaming
- Knowledge of the MITRE ATT&CK framework
- Experience validating detections against real attack simulations
- Experience in MDR, SOC or Incident Response environments
- Knowledge of detection-as-code methodologies
- Experience automating security workflows
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.