مهندس رصد التهديدات
Detection Engineer
اكتب قواعد الرصد التي يعتمد عليها مركز عملياتنا الأمنية وعملاؤنا، واختبرها وحافظ عليها. ستحوّل تقارير التهديدات ودروس الحوادث إلى حالات استخدام موثقة ومنخفضة الإنذارات الكاذبة.
الوصف الكامل متاح باللغة الإنجليزية، ويمكنك التقديم بلغتك.
About the role
Good monitoring depends on detections that fire on real threats and stay quiet otherwise. This role owns that content for our SOC and for clients who run their own. You analyse threat intelligence and incident findings, write detection logic for SIEM and EDR platforms, and test it against realistic data before release. You work with SOC analysts, incident responders and client security teams, and you keep a versioned library that others can review and reuse.
What you will do
- Develop and maintain detection rules in KQL, SPL or Sigma, mapped to MITRE ATT&CK
- Manage detection content as code with peer review, testing and version control
- Measure coverage and false positive rates and tune rules with SOC feedback
- Onboard new log sources and define the parsing and normalisation they need
- Document use cases and response guidance so analysts know what each alert means
What you bring
- 3+ years in a SOC, detection engineering or security monitoring role
- Hands-on experience with Microsoft Sentinel, Splunk or Elastic Security
- Good knowledge of Windows event logs, identity platforms and cloud audit logs
- Scripting skills in Python or PowerShell
- Working knowledge of MITRE ATT&CK and how to use it for coverage planning
Good to have
- Experience with detection-as-code pipelines in Git
- GIAC certification such as GCDA or GCIA
Languages
English (C1), German or French (B1) an advantage
Skills
تُرجمت هذه الصفحة بمساعدة الذكاء الاصطناعي. وفي حال وجود أي غموض، يُعتمد النص الإنجليزي.