We are seeking a hands-on SOC Content Detection Engineer to design, test, deploy, tune, and govern production detection content across Microsoft Sentinel and Microsoft Defender XDR within a multi-customer MSSP environment.
About the Role
The role owns the end-to-end detection lifecycle, including detection requirements, telemetry validation, KQL development, MITRE ATT&CK mapping, testing, peer review, controlled deployment, performance monitoring, tuning, documentation, and retirement. The engineer will develop reusable baseline content while supporting customer-specific data sources, risk profiles, licences, thresholds, and exceptions. The role requires strong practical experience in KQL and Microsoft security telemetry. Experience in threat hunting, Sigma translation, detection-as-code, parser validation, and measurable detection-quality improvement is highly desirable.
Responsibilities
- Detection validation and quality assurance
- Define the detection hypothesis, required telemetry, expected attacker behaviour, known limitations, and validation criteria for each rule.
- Test detections using representative positive, negative, and boundary-condition datasets before production deployment.
- Validate entity mapping, incident grouping, alert enrichment, time windows, suppression, and deduplication behaviour.
- Perform retrospective validation against historical telemetry where permitted.
- Maintain regression tests for critical detections and confirm that parser or schema changes do not silently break rule logic.
Detection lifecycle management
- Manage content through development, peer review, testing, approval, production release, tuning, exception handling, and retirement.
- Maintain rule ownership, content version, deployment state, last validation date, review frequency, and rollback instructions.
- Identify obsolete, duplicate, low-value, or unsupported detections and coordinate controlled retirement.
Detection-as-code and deployment engineering
- Maintain detection content in GitHub or an equivalent version-controlled repository.
- Use structured peer review and approval workflows for production changes.
- Support automated validation and deployment using APIs, CI/CD pipelines, infrastructure-as-code, or equivalent controlled mechanisms.
- Ensure tenant-specific parameters and exceptions are preserved during shared-content updates.
- Detection performance measurement
- Track alert volume, true-positive disposition, false-positive disposition, analyst handling impact, telemetry dependencies, and detection health.
- Define minimum observation periods and evidence requirements before declaring tuning successful.
- Report detection changes using measurable outcomes rather than relying only on alert-volume reduction.
- Identify detections that are silent because of telemetry failure, parsing changes, or logic defects.
MSSP content engineering
- Design reusable detections that can be safely parameterised for multiple customers.
- Maintain customer-specific thresholds, exclusions, risk conditions, data-source mappings, and deployment records.
- Account for differences in licences, retention, ingestion architecture, business operations, and available telemetry.
- Coordinate customer-impacting content changes through established approval and change-control processes.
Telemetry engineering
- Validate data completeness, field consistency, timestamp integrity, event duplication, parsing quality, and schema stability.
- Develop or maintain parsers and normalisation logic where required.
- Map each detection to its mandatory and optional telemetry dependencies.
- Implement monitoring for telemetry degradation that could affect critical detection coverage.
Collaboration & Enablement
- Work closely with SOC analysts, onboarding consultants, and automation engineers.
- Provide training and guidance on detection logic, rule writing, and tuning best practices.
- Participate in incident post-mortems to identify detection gaps and improvement areas.
Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, or related field.
- At least 6+ years of relevant cybersecurity operations, detection engineering, threat hunting, incident response, or SIEM engineering experience.
- At least 3+ years of hands-on production detection-content development.
Required Skills
- Microsoft Certified: Security Operations Analyst Associate
- Expert-level proficiency in KQL, Microsoft Sentinel, and Defender XDR.
- Experience with Sigma rule development, UEBA, and SIEM tuning.
- Strong understanding of log source telemetry, data normalization, and alert lifecycle.
- Familiarity with threat intelligence platforms and MITRE ATT&CK mapping.
- Analytical mindset with strong attention to detail.
- Excellent documentation and presentation skills.
- Ability to collaborate across technical and operational teams.
- Fluent English communication skills (spoken and written).
- Strong ability to develop, explain, troubleshoot, and optimise detection queries.
- Demonstrable experience mapping detections to MITRE ATT&CK.
- Experience testing, tuning, documenting, and maintaining production detections.
Preferred Skills
- MITRE ATT&CK Defender (MAD), GIAC (GCIA, GMON), CompTIA CySA+
To apply, please submit your CV to Thinh Truong (Mr) at [Confidential Information] or 0386729007 (Telegram/Zalo). We regret that only shortlisted candidates will be notified soon!