EnglishWillDo

Detection Quality Engineer

Northwave Group · Utrecht, Netherlands

No Dutch requiredPosted today
Apply for this job

You apply on the site where the job is posted. I never handle applications.

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who loves turning threat intelligence, attack research and adversary behavior into high-quality detections that make a real-world impact.

If you get excited by attack chains, KQL, Purple Teaming, threat hunting, and continuous improvement of detection capabilities, this role was built for you.

What you'll be doing

Detection Engineering

  • Design, build and continuously improve detection rules and monitoring content.
  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.
  • Translate attack techniques and adversary behavior into actionable detections.
  • Tune, validate and optimize detections to maximize signal and minimize noise.

Threat Research

  • Research emerging threats, attack campaigns and TTPs.
  • Analyze intelligence from MISP, CERT advisories, Red Team exercises and threat reports.
  • Map threats to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.
  • Identify gaps in monitoring coverage and proactively address them.

Continuous Improvement

  • Improve SOC monitoring capabilities through automation and innovation.
  • Contribute to Purple Team initiatives and validation of detection coverage.
  • Work on strategic projects that enhance the quality, scalability and effectiveness of our MDR services.
  • Help shape the future of detection engineering within Northwave.

Collaboration & Communication

  • Work closely with analysts, engineers, threat intelligence specialists and Red Team members.
  • Document detections and provide guidance to operational teams.
  • Explain detection logic, use-case design choices and monitoring strategies to both technical and non-technical stakeholders.

Must-have experience

  • 3+ years of experience in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development.
  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.
  • Experience analyzing attack techniques and adversary behavior.

Technical expertise

  • Strong KQL skills.
  • Understanding of Microsoft Defender technologies.
  • Experience with Microsoft Sentinel.
  • Knowledge of attack chains, adversary TTPs and modern threat landscapes.
  • Experience with Suricata rules and/or Zeek scripts.
  • Scripting or programming experience, preferably Python.
  • Solid knowledge of Windows and Linux internals.
  • Familiarity with threat intelligence and detection use-case development.

Personal qualities

  • Analytical and curious by nature.
  • Able to work independently while being a strong team player.
  • Comfortable engaging with stakeholders across multiple teams.
  • Proactive and improvement-driven.
  • Strong communication skills.
  • Security-minded with a healthy critical attitude.

Extra points if you have

  • Experience with Purple Teaming.
  • Knowledge of the MITRE ATT&CK framework.
  • Experience validating detections against real attack simulations.
  • Experience in MDR, SOC or Incident Response environments.
  • Knowledge of detection-as-code methodologies.
  • Experience automating security workflows.

Who you'll join

You will become part of the Detection Quality team, a highly technical group of engineers responsible for the detections of our SOC.

Our values are simple:

  • Quality first
  • Continuous improvement
  • Efficiency through automation
  • Ownership and responsibility
  • Customer impact

We challenge each other, support each other and continuously push our detection capabilities to the next level.

Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at youri.roelofs@northwave-cybersecurity.com.