Search by job, company or skills

SOC Detection Engineer

  • Posted 5 hours ago
  • Be among the first 10 applicants

Job Description

We are seeking a hands-on SOC Content Detection Engineer to design, test, deploy, tune, and govern production detection content across Microsoft Sentinel and Microsoft Defender XDR within a multi-customer MSSP environment.

About the Role

The role owns the end-to-end detection lifecycle, including detection requirements, telemetry validation, KQL development, MITRE ATT&CK mapping, testing, peer review, controlled deployment, performance monitoring, tuning, documentation, and retirement. The engineer will develop reusable baseline content while supporting customer-specific data sources, risk profiles, licences, thresholds, and exceptions. The role requires strong practical experience in KQL and Microsoft security telemetry. Experience in threat hunting, Sigma translation, detection-as-code, parser validation, and measurable detection-quality improvement is highly desirable.

Responsibilities

  • Detection validation and quality assurance
  • Define the detection hypothesis, required telemetry, expected attacker behaviour, known limitations, and validation criteria for each rule.
  • Test detections using representative positive, negative, and boundary-condition datasets before production deployment.
  • Validate entity mapping, incident grouping, alert enrichment, time windows, suppression, and deduplication behaviour.
  • Perform retrospective validation against historical telemetry where permitted.
  • Maintain regression tests for critical detections and confirm that parser or schema changes do not silently break rule logic.

Detection lifecycle management

  • Manage content through development, peer review, testing, approval, production release, tuning, exception handling, and retirement.
  • Maintain rule ownership, content version, deployment state, last validation date, review frequency, and rollback instructions.
  • Identify obsolete, duplicate, low-value, or unsupported detections and coordinate controlled retirement.

Detection-as-code and deployment engineering

  • Maintain detection content in GitHub or an equivalent version-controlled repository.
  • Use structured peer review and approval workflows for production changes.
  • Support automated validation and deployment using APIs, CI/CD pipelines, infrastructure-as-code, or equivalent controlled mechanisms.
  • Ensure tenant-specific parameters and exceptions are preserved during shared-content updates.
  • Detection performance measurement
  • Track alert volume, true-positive disposition, false-positive disposition, analyst handling impact, telemetry dependencies, and detection health.
  • Define minimum observation periods and evidence requirements before declaring tuning successful.
  • Report detection changes using measurable outcomes rather than relying only on alert-volume reduction.
  • Identify detections that are silent because of telemetry failure, parsing changes, or logic defects.

MSSP content engineering

  • Design reusable detections that can be safely parameterised for multiple customers.
  • Maintain customer-specific thresholds, exclusions, risk conditions, data-source mappings, and deployment records.
  • Account for differences in licences, retention, ingestion architecture, business operations, and available telemetry.
  • Coordinate customer-impacting content changes through established approval and change-control processes.

Telemetry engineering

  • Validate data completeness, field consistency, timestamp integrity, event duplication, parsing quality, and schema stability.
  • Develop or maintain parsers and normalisation logic where required.
  • Map each detection to its mandatory and optional telemetry dependencies.
  • Implement monitoring for telemetry degradation that could affect critical detection coverage.

Collaboration & Enablement

  • Work closely with SOC analysts, onboarding consultants, and automation engineers.
  • Provide training and guidance on detection logic, rule writing, and tuning best practices.
  • Participate in incident post-mortems to identify detection gaps and improvement areas.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field.
  • At least 6+ years of relevant cybersecurity operations, detection engineering, threat hunting, incident response, or SIEM engineering experience.
  • At least 3+ years of hands-on production detection-content development.

Required Skills

  • Microsoft Certified: Security Operations Analyst Associate
  • Expert-level proficiency in KQL, Microsoft Sentinel, and Defender XDR.
  • Experience with Sigma rule development, UEBA, and SIEM tuning.
  • Strong understanding of log source telemetry, data normalization, and alert lifecycle.
  • Familiarity with threat intelligence platforms and MITRE ATT&CK mapping.
  • Analytical mindset with strong attention to detail.
  • Excellent documentation and presentation skills.
  • Ability to collaborate across technical and operational teams.
  • Fluent English communication skills (spoken and written).
  • Strong ability to develop, explain, troubleshoot, and optimise detection queries.
  • Demonstrable experience mapping detections to MITRE ATT&CK.
  • Experience testing, tuning, documenting, and maintaining production detections.

Preferred Skills

  • MITRE ATT&CK Defender (MAD), GIAC (GCIA, GMON), CompTIA CySA+

To apply, please submit your CV to Thinh Truong (Mr) at [Confidential Information] or 0386729007 (Telegram/Zalo). We regret that only shortlisted candidates will be notified soon!

More Info

Job Type:
Industry:
Function:
Employment Type:

Job ID: 152624599

Beware of Scammers

We don’t charge money for job offers