Detection Engineer
Indexed description
Build the detections that help stop tomorrow's cyber threatsAre you interested in understanding how attackers operate and turning that knowledge into practical security capabilities?
As a Detection Engineer in Atea's Cyber Security Operations Center (CSOC), you will develop, test and improve detection content across SIEM and security platforms. You will work closely with Detection & Response specialists, Security Operations, Incident Response, Threat Intelligence and Automation Engineers to transform threat intelligence, attacker behaviour and customer needs into effective detection capabilities.
You will join a Security Operations Center that is experiencing strong growth and has ambitious goals for the future. We are a positive, collaborative and highly motivated team with a shared focus on continuous development, teamwork and delivering the best possible security outcomes for our customers.
About The Role
As a Detection Engineer, you will be responsible for developing, testing and continuously improving detection content that helps protect our customers against emerging threats.
Your work will be driven by threat intelligence, customer requirements, attacker behaviours and frameworks such as MITRE ATT&CK. You will help ensure that detections are reliable, relevant and operationally valuable before they are released into production.
Detection engineering at Atea is built around a Detection as Code methodology. Detection content is developed, reviewed, tested, version controlled and deployed through structured engineering pipelines. This allows us to maintain high-quality detections while continuously improving and scaling our detection capabilities across customers and technologies.
This role is broader than the title might suggest. While Detection Engineering is at the core of the position, you will work across multiple areas of cyber security and develop an understanding of technologies, attack techniques and security operations. We are not looking for someone who knows everything from day one, but someone who is eager to learn, collaborate and continuously develop their expertise.
What You Will Be Doing
In this role, you will:
- Develop, test and improve detection content across SIEM and security platforms.
- Translate threat intelligence, attacker techniques and customer needs into effective detection capabilities.
- Tune, validate and maintain detections to improve reliability and operational value.
- Contribute to Detection as Code pipelines and detection engineering best practices.
- Collaborate with Security Operations, Incident Response, Threat Intelligence and Automation teams to strengthen detection and response capabilities.
- Identify detection gaps, contribute to security exercises and incidents, and share knowledge across the security community.
You enjoy learning, sharing knowledge and working closely with others to solve complex security problems. You understand that strong detection engineering combines technical expertise with collaboration, testing and continuous improvement.
Must-have Qualifications
- Experience within cyber security, security operations, detection engineering or a related security discipline.
- Experience with Microsoft Sentinel or other SIEM platforms.
- Strong understanding of cloud security, attacker behaviour and frameworks such as MITRE ATT&CK.
- Experience with scripting or automation, such as Python.
- Experience with Splunk, EDR, NDR or SOAR technologies.
- Experience with Detection as Code, Git, Terraform or Ansible.
- Experience writing Sigma or YARA rules.
- Relevant security certifications.
- Bachelor's degree in Information Technology, Information Security, Cyber Security, Data Science or a related field.
- Relevant experience may compensate for formal education.
- Requirements
- Applicants must be citizens of Norway, Sweden or Denmark.
You will join a highly motivated team that values collaboration, learning and continuous improvement. We believe the best security outcomes are created when talented people work together, share knowledge and challenge each other to grow.
As a Detection Engineer, you will have the opportunity to influence how we develop our detection capabilities, work with a wide range of security technologies and contribute directly to helping our customers respond to an evolving threat landscape.
At Atea, you will also benefit from:
- A strong professional community within Security Operations, Incident Response, Threat Intelligence and Cyber Security.
- Training, certifications and continuous learning opportunities.
- Modern security platforms and technologies.
- Opportunities for personal and professional development.
- Competitive compensation and attractive benefits.
Practical information
- Location: Drammen
- Employment type: Permanent
- Job role: Security Engineer
- Application deadline: 06.09.26
- Contact person: Joakim Kargaard, [email protected].
If you are excited about the opportunity but unsure whether you meet every requirement, we still encourage you to apply. We value motivation, learning ability and potential just as much as specific experience.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search