IW
Detection Engineering across SIEM / EDR / Cloud, Threat Analysis
Info Way Solutions LLC
đźđł India
On-site
Senior
1 month ago
- SIEM
- EDR
- Windows
- Linux
- MacOS
- AI
- Incident Response
- Threat Intelligence
- CI/CD
- Change Management
- Splunk
- Elastic
- Python
- PowerShell
1 month ago
| 7+ | Detection Engineering across SIEM / EDR / Cloud, Threat Analysis | Understanding of log normalization, parsing, and field mapping | Primary skills - Max. 3: Detection Engineering across SIEM / EDR / Cloud Advanced proficiency in Querying & Threat Analytics (SPL, AQL, ES|QL) Deep knowledge on most common security telemetry (Windows, Linux, MacOS, Containers, Network, Cloud) Secondary skills: DetectionâasâCode & Automation Detection Validation & Attack Simulation Understanding of log normalization, parsing, and field mapping Good to have skills: SOAR & Response Automation Purple Team / Advanced Threat Hunting Experience Red Team experience Experience with FIM, UBA tools Hands-on with monitoring and defending AI-based attacks (i.e. prompt injection) Job Description: # Senior Detection Engineer ## About the role Danske Bank is strengthening its threat detection engineering capability and is looking for a Senior Detection Engineer to design, build, and continuously improve highâfidelity security detections across our enterprise environment. You will focus on engineeringâled, threatâdriven detections, working closely with incident response, threat intelligence, and platform teams to ensure our detection capabilities evolve with the threat landscape. You will play a key role in reducing detection gaps, minimizing false positives, and ensuring our security monitoring is robust, testable, and auditable within a regulated financial environment. What you'll be doing ### Detection Engineering Design, develop, and maintain highâfidelity detections across SIEM, EDR, and cloud platforms Translate threat intelligence and incident learnings into actionable detection logic based on attacker TTPs mapped to the MITRE Telecommunication&CK framework Continuously tune and optimize detections to reduce false positives while maintaining coverage ### Threat Hunting & Validation Conduct proactive threatâhunting activities to identify detection gaps Validate detections using attack simulation, purpleâteam exercises, or controlled testing Measure detection coverage and effectiveness against defined KPIs ### DetectionâasâCode & Automation Manage detection content using version control and DetectionâasâCode principles Develop automation and tooling (CI/CD pipelines) to support detection lifecycle processes ### Data & Platform Engineering Work with logging and platform teams to onboard and optimize data sources Ensure log quality, normalization, and enrichment to support detection use cases Troubleshoot data or telemetry gaps impacting detection coverage ### Collaboration & Governance Partner with SOC, Incident Response, and Threat Intelligence teams Participate in postâincident reviews to derive new detection requirements Maintain documentation, runbooks, and detection design artefacts Operate within ITSM and changeâmanagement processes appropriate for a regulated bank ## What we're looking for ### Required 5+ years in detection engineering or threat detection roles Understanding of the full detection lifecycle Strong handsâon experience with SIEM platforms (e.g. Splunk, QRadar, Elastic) on developing rules, building dashboards, log parsing. Advanced proficiency in SPL, AQL, ES|QL query languages Solid understanding of Windows, Linux, MacOS, Network, Containers and Cloud Security telemetry Experience in building and maintaining CI/CD pipelines for detection engineering Scripting experience (Python, Powershell) for automation and detection support Detection validation using attack simulation Demonstrated ability to migrate detection logic between SIEM platforms ### Preferred Exposure to SOAR platforms and response automation Threatâhunting or purple/red team experience Experience operating in a regulated financial or large enterprise environment Relevant certifications (e.g. GCDA, GDAT, GCTD, GASAE), GIAC Advisory Board member. What we offer Opportunity to shape detection engineering maturity at enterprise scale Work on meaningful, attackerâdriven security problems Collaboration with senior security professionals across the bank |
Detection Engineering across SIEM / EDR / Cloud, Threat Analysis · Info Way Solutions LLC