Назад
Company hidden
10 часов назад

Senior Detection Engineer (AI-Augumented)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Detection Engineer (AI-Augumented) (SIEM/Cybersecurity): Building, tuning, and scaling threat detection capabilities across enterprise SIEM and data lake platforms with an accent on MITRE ATT&CK mapping, detection-as-code, and AI-assisted rule development. Focus on validating detections against live telemetry, reducing false positives, analyzing coverage gaps, and translating emerging threats into reliable detection logic.

Location: Warsaw, Poland; hybrid work model with the option to work from home two days per week and regular office attendance.

Company

Procter & Gamble produces globally recognized consumer brands and operates in approximately 70 countries.

What you will do

  • Design, build, test, and tune SIEM and data lake detection rules mapped to MITRE ATT&CK, threat intelligence, and business risk.
  • Manage detection content as code through Git branching, pull requests, code reviews, and CI/CD deployment pipelines.
  • Investigate false positives, apply lookup-based suppression architectures, and improve alert fidelity.
  • Use AI agents, LLM-assisted workflows, and MCP tooling to accelerate rule development, validation, telemetry analysis, and coverage assessment.
  • Collaborate with Threat Intelligence, Threat Hunting, SOC, and data engineering teams on detection handovers, alert feedback, telemetry quality, and log-source onboarding.
  • Develop detections for emerging TTPs, CVEs, active campaigns, and AI-related threats.

Requirements

  • 5+ years of experience in detection engineering, security operations, or threat detection.
  • Hands-on experience writing and tuning SIEM detection rules and analytics, including correlation rules, scheduled queries, and real-time alerts.
  • Strong understanding of the MITRE ATT&CK framework and detection coverage measurement.
  • Proficiency in Python and experience with Git-based workflows for security content.
  • Familiarity with EDR, identity, cloud, network, and proxy security logs, plus strong analytical skills for distinguishing threats from noise.
  • Bachelor’s degree in a technical or IT field and/or at least 5 years of relevant experience.

Nice to have

  • Experience with multiple query languages, detection-as-code practices, YAML-based Sigma or custom rule formats, and SOAR platforms.
  • Knowledge of AI/LLM capabilities and security implications, including MCP servers, GitHub Copilot, or similar AI-assisted development workflows.
  • Understanding of Kubernetes, cloud-native architectures, and OT/ICS environments.
  • CISSP, CCSP, OSCP, GCDA, GCIA, or relevant cloud and ML/AI certifications.

Culture & Benefits

  • Large-scale projects with access to global IT partners and technologies from the first day.
  • Training and certification development paths.
  • Private healthcare, P&G stock, savings plans, and sports cards.
  • Regular salary reviews and potential promotions based on results and performance.
  • Employment is exclusively offered under an Umowa o Pracę full-time employment contract.

Hiring process

  • The recruiting process is described in the company’s recruiting materials.
  • Performance is reviewed through quarterly operational and project deliverables with ongoing mentoring and coaching.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →