Detection Engineer — SIEM, EDR and Detection-as-Code for NATO with security clearance
WLG Mons, Wallonia, Belgium
Financial Services · 2-10 employees
About the role
You will design, build, and maintain detection rules and analytics across SIEM, EDR, and cloud security platforms. Additionally, you will manage the full detection lifecycle, including testing, deployment, and gap analysis to improve security coverage.
What they look for
Requirements
The role requires professional experience in detection engineering and hands-on proficiency with SIEM and endpoint detection tools. Candidates must be fluent in detection languages like Sigma, SPL, or KQL and possess a strong understanding of adversary tradecraft and the MITRE ATT&CK framework.
Full description
A multinational defence organisation is strengthening the detection engineering sideof its security operations centre. This is not alert triage: you build the content the analystsdepend on, measure whether it works, and close the gaps you find.
What you would be doing
- Designing, building and maintaining detection rules, alerts and analytics across SIEM,EDR and XDR, network detection and cloud security tooling.
- Writing detection logic in the languages that suit it — Sigma, SPL, KQL.
- Building detections around adversary behaviour and mapping them to the MITRE ATT&CKframework, with advanced persistent threats in mind.
- Turning threat intelligence and purple team findings into working automated detections.
- Running a proper detection lifecycle — design, development, testing, deployment, monitoring,improvement, review — and improving the quality metrics behind it.
- Assessing detection coverage across on-premise and cloud estates, and doing the gap analysisthat says where to invest next.
- Reviewing newly ingested log sources against the common information model, auditing fieldextractions and event mappings, and chasing data owners when something does not line up.
- Supporting incident handlers and threat hunters when an investigation is live.
What you would bring
- Real detection engineering experience, and the version control and code review habits thatmake it repeatable.
- Hands-on work with a major SIEM and with endpoint and network detection tooling.
- Fluency in at least one detection language, and enough scripting to automate the rest.
- Familiarity with adversary tradecraft and with the ATT&CK framework as a working toolrather than a poster.
- Professional English, and the ability to explain a detection decision to people who did notwrite it.
The assignment is on-site near Mons.