Experteer Overview
As a Detection Strategist in AXA’s SOC, you translate attacker behavior into durable detections and own the quality of our detection logic. You will work at the intersection of offensive tradecraft and blue-team outcomes, turning insights from red-teaming into high-fidelity SIEM alerts. You’ll craft complex KQL-based detections, analyze telemetry from EDR, IdP and Cloud, and drive visibility into data gaps. This role offers impact across a general security program, with opportunities to shape detection strategy, reduce noise, and strengthen incident response.
Compensaciones / Beneficios
• Author complex KQL-based detections to reveal sophisticated attacker techniques
• Analyze raw telemetry from EDR, Identity Providers, and Cloud to identify data gaps and specify logging policies
• Tune rules to reduce false positives while maintaining coverage for adversary behavior
• Validate new detections via targeted adversary emulation and manual attack sequences
• Perform gap analyses mapped to MITRE ATTu0026CK to uncover blind spots and implement fixes
• Review and optimize the detection rule library for accuracy and coverage
• Collaborate with Incident Response to understand past misses and engineer preventative rules
Responsabilidades
• Experience as a Red Teamer or in offensive security with the ability to translate attacker techniques into detections
• Proficiency in KQL and SIEM-based detection content creation
• Strong telemetry analysis across EDR, IdP, and Cloud infrastructure
• Ability to map threat intelligence to actionable detection logic
• Experience with MITRE ATTu0026CK and adversary emulation
• Collaborative mindset with Incident Response and cross-functional teams
Requisitos principales
•
📌 SOC Purple Team Expert (Madrid)
🏢 Axa Group
📍 Madrid
Postulate a este anuncio
Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.