جميع الوظائف

مهندس رصد التهديدات

Detection Engineer

اكتب قواعد الرصد التي يعتمد عليها مركز عملياتنا الأمنية وعملاؤنا، واختبرها وحافظ عليها. ستحوّل تقارير التهديدات ودروس الحوادث إلى حالات استخدام موثقة ومنخفضة الإنذارات الكاذبة.

قدّم الآنيستغرق نحو 3 دقائق

الوصف الكامل متاح باللغة الإنجليزية، ويمكنك التقديم بلغتك.

About the role

Good monitoring depends on detections that fire on real threats and stay quiet otherwise. This role owns that content for our SOC and for clients who run their own. You analyse threat intelligence and incident findings, write detection logic for SIEM and EDR platforms, and test it against realistic data before release. You work with SOC analysts, incident responders and client security teams, and you keep a versioned library that others can review and reuse.

What you will do

  • Develop and maintain detection rules in KQL, SPL or Sigma, mapped to MITRE ATT&CK
  • Manage detection content as code with peer review, testing and version control
  • Measure coverage and false positive rates and tune rules with SOC feedback
  • Onboard new log sources and define the parsing and normalisation they need
  • Document use cases and response guidance so analysts know what each alert means

What you bring

  • 3+ years in a SOC, detection engineering or security monitoring role
  • Hands-on experience with Microsoft Sentinel, Splunk or Elastic Security
  • Good knowledge of Windows event logs, identity platforms and cloud audit logs
  • Scripting skills in Python or PowerShell
  • Working knowledge of MITRE ATT&CK and how to use it for coverage planning

Good to have

  • Experience with detection-as-code pipelines in Git
  • GIAC certification such as GCDA or GCIA

Languages

English (C1), German or French (B1) an advantage

Skills

  • KQL
  • Sigma
  • Splunk
  • Microsoft Sentinel
  • MITRE ATT&CK
  • Python
  • Detection as code

تُرجمت هذه الصفحة بمساعدة الذكاء الاصطناعي. وفي حال وجود أي غموض، يُعتمد النص الإنجليزي.