Threat Detection Engineer
Indexed description
Role Overview
Dev/Null Security is seeking a hands-on Threat Detection Engineer with strong experience in Microsoft Sentinel to design, build and optimise threat detections across enterprise environments. This role focuses on developing, maintaining and continuously improving high-quality security detections that enhance monitoring, incident response and security visibility.
The successful candidate will have strong Microsoft Sentinel experience and be comfortable working within a modern Security Operations environment. Experience with Splunk is also required, with at least one Splunk certification and the ability to discuss Splunk architecture, SPL, data ingestion and detection engineering concepts at a high level.
This position is ideal for someone who enjoys translating threat intelligence into actionable detections, improving detection coverage and collaborating with SOC, Infrastructure and Compliance teams.
Key Responsibilities
- Design, build and optimise detection rules and analytics within Microsoft Sentinel.
- Develop and maintain KQL queries for threat detection, threat hunting and operational reporting.
- Onboard and optimise log sources, data connectors and analytics rules.
- Create and tune correlation rules to reduce false positives and improve detection fidelity.
- Support incident investigations by developing detections based on emerging threats and attack techniques.
- Apply threat intelligence and the MITRE ATT&CK framework to detection engineering activities.
- Collaborate with SOC analysts, Infrastructure and Compliance teams to improve monitoring capabilities.
- Contribute to Detection-as-Code and DevOps practices using Git, GitLab or BitBucket.
Required Skills & Experience
- Strong hands-on experience with Microsoft Sentinel (primary SIEM).
- Advanced knowledge of Kusto Query Language (KQL).
- Experience onboarding log sources, data connectors and building analytics rules.
- Commercial experience designing and tuning security detections.
- Experience with Splunk including at least one Splunk certification.
- Ability to discuss Splunk architecture, SPL, data ingestion and detection engineering concepts.
- Good understanding of Security Operations, incident response and threat detection.
- Knowledge of the MITRE ATT&CK framework.
- Experience using Git, GitLab or BitBucket.
- Strong analytical, troubleshooting and communication skills.
Preferred / Nice-to-Have Skills
- Python and/or Shell scripting.
- Detection-as-Code experience.
- Threat hunting experience.
- Security automation.
- Compliance and governance awareness.
- Cloud security experience within Microsoft Azure.
Working at DevNull Security
Whilst DevNull Security is a remote-first company, our consulting team may be required to travel to client sites up to 3 times per week, depending on project and customer needs.
We believe that a career in cybersecurity should be accessible to everyone. We actively welcome applicants from all walks of life, regardless of race, ethnicity, gender identity, age, sexual orientation, disability, neurodiversity, socioeconomic background, or any other aspect of identity.
As a growing company, we’re committed to fostering an inclusive, equitable, and accessible hiring experience. We proactively offer adjustments during application and assessment - tell us what you need.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search