03 ago
|
XpertDirect
|
Barcelona
03 ago
XpertDirect
Barcelona
Cybersecurity SaaS | Detection Engineering | Cloud Security | Security Analytics
Our client, an innovative Cybersecurity SaaS company based in Barcelona, is looking for a Detection Engineer to develop advanced detection logic, security analytics, and automated detection-as-code capabilities for cloud-native customer environments.
You’ll work alongside Threat Researchers, Security Engineers, and Cloud Platform teams to build scalable detection content that identifies sophisticated threats, reduces false positives, and helps customers respond to attacks faster than ever before.
If you’re passionate about cloud security, threat detection, automation, and engineering-driven security operations, this is an opportunity to make a real impact.
Technical Environment
- Threat Detection Engineering
What You’ll Be Working On
- Developing high-quality detection rules for cloud-native enterprise environments
- Building Detection-as-Code workflows that enable scalable, version-controlled security content
- Creating security analytics that identify advanced threats across AWS infrastructure and cloud workloads
- Writing Python tooling to automate detection development, validation, and testing
- Improving SIEM content to reduce false positives while increasing detection accuracy
- Developing behavioural detections based on attacker techniques and real-world threat intelligence
- Collaborating with Security Operations, Threat Intelligence, and Product teams to continuously improve detection coverage
- Building automated testing pipelines to validate detection content before deployment
- Supporting incident investigations by developing new detections based on emerging attack techniques
- Helping shape the company’s cloud detection strategy across a rapidly growing cybersecurity platform
Experience Required
- 4+ years of experience in Detection Engineering, Security Engineering, Threat Detection, or Security Operations
- Strong commercial experience working with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or similar solutions
- Strong Python development skills for automation and security tooling
- Experience securing AWS cloud environments and understanding cloud attack techniques
- Good understanding of MITRE ATT&CK;, threat hunting, incident response, and adversary behaviour
- Experience applying Detection-as-Code principles using Git-based workflows and CI/CD pipelines
- Passion for building scalable security engineering solutions through automation
Nice to Have
- Experience with cloud-native security platforms such as Microsoft Defender, CrowdStrike, Wiz, Lacework, or AWS Security Hub
- Knowledge of Infrastructure as Code and Terraform security concepts
- Experience with Kubernetes security monitoring and container threat detection
- Familiarity with SOAR platforms and automated incident response workflows
- Experience contributing to threat research or detection engineering communities
- GIAC, GCTI, GCFA, GCIA, or similar cybersecurity certifications are an advantage
#J-18808-Ljbffr
📌 Detection Engineer (Barcelona)
🏢 XpertDirect
📍 Barcelona