08 ago
|
XpertDirect
|
Barcelona
08 ago
XpertDirect
Barcelona
Cybersecurity Saa S | Detection Engineering | Cloud Security | Security AnalyticsOur client, an innovativeCybersecurity Saa Scompany based in Barcelona, is looking for aDetection Engineerto develop advanced detection logic, security analytics, and automated detection-as-code capabilities for cloud-native customer environments.You’ll work alongside Threat Researchers, Security Engineers, and Cloud Platform teams to build scalable detection content that identifies sophisticated threats, reduces false positives, and helps customers respond to attacks faster than ever before.If you’re passionate about cloud security, threat detection, automation, and engineering-driven security operations, this is an opportunity to make a real impact.Technical EnvironmentThreat Detection EngineeringWhat You’ll Be Working OnDeveloping high-quality detection rules for cloud-native enterprise environmentsBuilding Detection-as-Code workflows that enable scalable, version-controlled security contentCreating security analytics that identify advanced threats across AWS infrastructure and cloud workloadsWriting Python tooling to automate detection development, validation, and testingImproving SIEM content to reduce false positives while increasing detection accuracyDeveloping behavioural detections based on attacker techniques and real-world threat intelligenceCollaborating with Security Operations, Threat Intelligence,
and Product teams to continuously improve detection coverageBuilding automated testing pipelines to validate detection content before deploymentSupporting incident investigations by developing new detections based on emerging attack techniquesHelping shape the company’s cloud detection strategy across a rapidly growing cybersecurity platformExperience Required4+ years of experience in Detection Engineering, Security Engineering, Threat Detection, or Security OperationsStrong commercial experience working with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or similar solutionsStrong Python development skills for automation and security toolingExperience securing AWS cloud environments and understanding cloud attack techniquesGood understanding of MITRE ATT&CK;, threat hunting, incident response, and adversary behaviourExperience applying Detection-as-Code principles using Git-based workflows and CI/CD pipelinesPassion for building scalable security engineering solutions through automationNice to HaveExperience with cloud-native security platforms such as Microsoft Defender, Crowd Strike, Wiz, Lacework, or AWS Security HubKnowledge of Infrastructure as Code and Terraform security conceptsExperience with Kubernetes security monitoring and container threat detectionFamiliarity with SOAR platforms and automated incident response workflowsExperience contributing to threat research or detection engineering communitiesGIAC, GCTI, GCFA, GCIA, or similar cybersecurity certifications are an advantage
📌 Detection Engineer (Barcelona)
🏢 XpertDirect
📍 Barcelona