Назад
Company hidden
4 дня назад

Security Detection Engineer III (Cybersecurity)

Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Detection Engineer III (Cybersecurity): Developing, testing, deploying, and improving threat-driven security detections for Security Operations with an accent on Detection-as-Code, MITRE ATT&CK coverage, and AI and agentic system threats. Focus on validating detections through adversary emulation and purple-team exercises, automating detection workflows, onboarding telemetry, and reducing false positives.

Location: Warsaw, Poland

Company

hirify.global develops and secures application delivery technologies while helping organizations protect digital services and improve application operations.

What you will do

  • Develop, maintain, test, and deploy custom detections using Detection-as-Code practices, version control, peer review, and CI/CD workflows.
  • Analyze detection coverage against adversary behaviors and the MITRE ATT&CK framework, identify gaps, and prioritize improvements.
  • Collaborate with Incident Response, Threat Intelligence, Logging Engineering, and security platform teams to turn threats, investigations, and telemetry into actionable detections.
  • Validate and tune detections through adversary emulation, atomic testing, purple-team exercises, and production feedback to improve signal quality.
  • Automate detection workflows, alert enrichment, and operational activities, and support onboarding of new log sources across cloud, endpoint, network, identity, and SaaS environments.
  • Maintain documentation, runbooks, coverage assessments, and technical standards while participating in an engineering on-call rotation.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field, or equivalent practical experience.
  • At least 5 years of experience in cybersecurity, security engineering, detection engineering, security operations, threat hunting, or a related discipline.
  • Experience developing, tuning, or maintaining detections in SIEM, EDR, log analytics, or security monitoring platforms.
  • Experience with scripting, automation, or data analysis using Python, PowerShell, SQL, KQL, SPL, or similar technologies.
  • Strong understanding of attacker techniques, detection methodologies, and MITRE ATT&CK, plus analytical, communication, and collaboration skills.
  • Participation in an engineering on-call rotation is required; occasional support outside normal business hours may be needed.

Nice to have

  • Experience with Detection-as-Code, Git-based workflows, automated testing, CI/CD, adversary emulation, atomic testing, or purple-team exercises.
  • Experience with detection coverage roadmaps, log-source onboarding, and security technologies such as CrowdStrike, Splunk, Microsoft Sentinel, Chronicle, or Elastic.
  • Familiarity with AI/LLM threat models, MITRE ATLAS, or the OWASP LLM Top 10.

Culture & Benefits

  • Work as part of the Security Operations Platform Engineering team with cross-functional security and platform partners.
  • This is a full-time engineering role and is not shift-based.
  • Travel may be required up to 5%, including occasional international travel.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →