Zum Inhalt springen

Detection Quality Engineer

  • Hybrid
    • Utrecht, Netherlands
  • €3,600 - €5,800 per month
  • Blue Team

Job description

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who loves turning threat intelligence, attack research and adversary behavior into high-quality detections that make a real-world impact.

If you get excited by attack chains, KQL, Purple Teaming, threat hunting, and continuous improvement of detection capabilities, this role was built for you.

What you'll be doing

Detection Engineering

  • Design, build and continuously improve detection rules and monitoring content.

  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.

  • Translate attack techniques and adversary behavior into actionable detections.

  • Tune, validate and optimize detections to maximize signal and minimize noise.



Threat Research

  • Research emerging threats, attack campaigns and TTPs.

  • Analyze intelligence from MISP, CERT advisories, Red Team exercises and threat reports.

  • Map threats to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.

  • Identify gaps in monitoring coverage and proactively address them.



Continuous Improvement

  • Improve SOC monitoring capabilities through automation and innovation.

  • Contribute to Purple Team initiatives and validation of detection coverage.

  • Work on strategic projects that enhance the quality, scalability and effectiveness of our MDR services.

  • Help shape the future of detection engineering within Northwave.



Collaboration & Communication

  • Work closely with analysts, engineers, threat intelligence specialists and Red Team members.

  • Document detections and provide guidance to operational teams.

  • Explain detection logic, use-case design choices and monitoring strategies to both technical and non-technical stakeholders.

Job requirements

Must-have experience

  • 3+ years of experience in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development.

  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.

  • Experience analyzing attack techniques and adversary behavior.



Technical expertise

  • Strong KQL skills.

  • Understanding of Microsoft Defender technologies.

  • Experience with Microsoft Sentinel.

  • Knowledge of attack chains, adversary TTPs and modern threat landscapes.

  • Experience with Suricata rules and/or Zeek scripts.

  • Scripting or programming experience, preferably Python.

  • Solid knowledge of Windows and Linux internals.

  • Familiarity with threat intelligence and detection use-case development.



Personal qualities

  • Analytical and curious by nature.

  • Able to work independently while being a strong team player.

  • Comfortable engaging with stakeholders across multiple teams.

  • Proactive and improvement-driven.

  • Strong communication skills.

  • Security-minded with a healthy critical attitude.



Extra points if you have

  • Experience with Purple Teaming.

  • Knowledge of the MITRE ATT&CK framework.

  • Experience validating detections against real attack simulations.

  • Experience in MDR, SOC or Incident Response environments.

  • Knowledge of detection-as-code methodologies.

  • Experience automating security workflows.



Who you'll join

You will become part of the Detection Quality team, a highly technical group of engineers responsible for the detections of our SOC.

Our values are simple:

  • Quality first

  • Continuous improvement

  • Efficiency through automation

  • Ownership and responsibility

  • Customer impact



We challenge each other, support each other and continuously push our detection capabilities to the next level.

Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at youri.roelofs@northwave-cybersecurity.com.

or

Hybrid
  • Utrecht, Utrecht, Netherlands
€3,600 - €5,800 per month
Blue Team

How we hire

Our hiring process is thorough, to ensure we make the right decision and to help you to decide if we're the right fit for you. Depending on the position and general conditions, steps may vary in individual cases - if you have any questions, please feel free to ask!

Your Application and Screening phase

After submitting your application, you will receive an automatic confirmation of receipt from us.

We review your application and give you feedback. This process takes some time but we try to give you feedback as quickly as possible.

First Interview - Getting to know you

In the first online meeting, let our recruiter learn about you and your story to check a potential fit. This is also a chance for you to ask first questions about the role and company.

Second Interview - Learning more about your skills

In this one site meeting, your future Leader takes a deeper dive into your experience and what you could bring to the team. You can expect questions on how knowledgeable you are in the business or technology area. For technical positions, you can expect a technical test. Further, you have the chance to meet the team and ask questions.

Job Offer and Onboarding

Congratulations, you made it to the very last stage! Here we have already decided to make you part of the Northwave team. We are sending you a job offer. We hope you also choose us! If so, Welcome to the Northwave family. We are ready to start with your Onboarding!