13 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
Security Detection Engineer (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Security Detection Engineer (Cybersecurity): Developing and productionizing code-like detections for malicious network activity using telemetry such as NetFlow, DNS queries, TLS certificate data, and SMB filenames with an accent on behavioral modeling, threat intelligence, and network security. Focus on tuning detection efficacy with precision, recall, false-positive rate, and MITRE ATT&CK coverage while deploying detections to SaaS and potential on-premise environments.
Location: Poland; remote or office work options available
Company
delivers engineering and technology services, including cybersecurity and SaaS solutions.
What you will do
- Design behavioral models and production-ready detections for malicious network activity and anomalies.
- Develop detection logic for beaconing, DGA, data staging, lateral movement, DNS tunneling, scanning, port hopping, and unusual remote administration.
- Build, evaluate, and continuously tune detections using precision, recall, false-positive rate, and MITRE ATT&CK coverage.
- Use production-scale telemetry in Databricks to validate detection performance.
- Collaborate with threat intelligence and engineering teams to turn threat research into detection content and productionize it in SaaS and potential on-premise environments.
- Support threat hunting, investigations, triage, and documentation of detection methodology and tuning decisions.
Requirements
- Experience developing rule-based, signature-based, or behavioral detection content for network threats.
- Strong knowledge of TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors.
- Proficiency in Python and SQL for detection development and data analysis.
- Experience with Sigma, Snort, Suricata, or similar detection formats.
- Practical experience applying AI/ML techniques to security detection, including anomaly detection, classification, or behavioral modeling.
- Experience with SecOps workflows, threat intelligence tools, NDR, security analytics or SIEM solutions, and MITRE ATT&CK mapping.
Nice to have
- Endpoint security experience.
Culture & Benefits
- Remote or office work format in Poland.
- Collaboration with threat intelligence teams, including Cisco Talos.
- Cross-team knowledge sharing across security and engineering functions.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β
ΠΠΎΡ ΠΎΠΆΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
6 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
Security & Compliance Engineer (Robotics)
7 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Security Engineer (Application Security)
145Β 196 - 223Β 379PLN
6 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄
Senior AI Security Engineer
Link Group
1 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄
ΠΠ»ΠΈΡΠ½ΡΠΉ ΠΏΠ΅Π½ΡΠ΅ΡΡΠ΅Ρ (Cybersecurity)
30 - 33β¬
5 ΡΠ°ΡΠΎΠ² Π½Π°Π·Π°Π΄
IT Risk & Compliance Engineer (DevOps/Agile)
9Β 600 - 12Β 000PLN