Security Detection Engineer

Softserve — Poland · Posted ~3 hours ago

Mid Full-time

Skills

Network security Machine learning Detection engineering Threat detection Machine Learning Network telemetry Security analytics

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A cybersecurity-focused organization is hiring an engineer to build automated detection logic and machine learning models using network data. The role involves improving security analytics and developing reliable threat identification systems.

Highlights

Work at the intersection of cybersecurity, machine learning, and software engineering to develop advanced threat detection capabilities.

Description

About The Role In this role, you will work at the intersection of network security, machine learning, and software engineering, focusing on developing automated, code-like detection logic against real-world network telemetry. You will treat detections as code: version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives. You will primarily work with network telemetry, including NetFlow, DNS queries, TLS certificate data, SMB filenames, and other L7 metadata extracted from firewall connection records. A significant part of the role is building and tuning behavioural/ML models on this telemetry, not just writing static rules. Over time, you will also help evolve detection capabilities as the platform incorporates endpoint and identity signals. Responsibilities Design and build behavioural / ML models (anomaly detection, classification, baseline profiling) to detect malicious activity and identify meaningful anomalies in network behaviourDevelop automated detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunnelling, scanning, port hopping, and unusual remote administration activityTranslate concrete detection use cases into production-ready detection logic, signatures, and behavioural indicatorsBuild automation around NDR / network telemetry - pipelines, enrichment, and tuning workflows that operationalise detections at scaleBuild, evaluate, and continuously tune detections using efficacy metrics — precision, recall, false-positive rate, and MITRE ATT&CK coverageUse production-scale telemetry on Databricks to validate and improve detection performanceCollaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into detection contentWork with engineering teams to productionize detections as part of a SaaS service, with potential on-premise deploymentSupport threat hunting, investigations, and triage with detection expertiseUse threat intelligence platforms and OSINT to enrich detections with current threat context, reputation data, and IOCsApply networking and network security knowledge to model traffic behaviour and create precise, low-noise detection logicDocument detection methodology, assumptions, and tuning decisions, and share knowledge across security and engineering teams Requirements Direct experience with NDR platforms (e.g., Vectra, Darktrace, Zeek/Corelith, Suricata) and raw network telemetry (NetFlow, DNS, TLS/JA3, SMB, PCAP, traffic analysis)Proven experience building rule/signature-based and behavioural detections as code: version-controlled, peer-reviewed, tested, and iteratively tuned, plus automation built around the detection lifecyclePractical, hands-on experience with anomaly detection, classification, or behavioural modelling on real telemetry, not solely static correlation rulesStrong networking & network security fundamentals - TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectorsCoding/scripting: Python and SQL for detection development and data analysisKnowledge of Rule languages/detection formats: Sigma, Snort, Suricata, or similarMITRE ATT&CK - mapping detections to adversary tactics and techniquesSecOps workflows: threat hunting, incident investigation support, and improving detections based on operational findingsThreat intelligence & OSINT - using feeds/platforms to enrich and contextualise detection logicStrong analytical & problem-solving skills, attention to detail, and clear documentation / cross-team communication SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.