Back to search
Talentnet Corporation Linkedin · Posted 12d ago

SOC Detection Engineer

Ho Chi Minh City

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

We are seeking a hands-on SOC Content Detection Engineer to design, test, deploy, tune, and govern production detection content across Microsoft Sentinel and Microsoft Defender XDR within a multi-customer MSSP environment.



About the Role


The role owns the end-to-end detection lifecycle, including detection requirements, telemetry validation, KQL development, MITRE ATT&CK mapping, testing, peer review, controlled deployment, performance monitoring, tuning, documentation, and retirement. The engineer will develop reusable baseline content while supporting customer-specific data sources, risk profiles, licences, thresholds, and exceptions. The role requires strong practical experience in KQL and Microsoft security telemetry. Experience in threat hunting, Sigma translation, detection-as-code, parser validation, and measurable detection-quality improvement is highly desirable.


Responsibilities


  • Detection validation and quality assurance
  • Define the detection hypothesis, required telemetry, expected attacker behaviour, known limitations, and validation criteria for each rule.
  • Test detections using representative positive, negative, and boundary-condition datasets before production deployment.
  • Validate entity mapping, incident grouping, alert enrichment, time windows, suppression, and deduplication behaviour.
  • Perform retrospective validation against historical telemetry where permitted.
  • Maintain regression tests for critical detections and confirm that parser or schema changes do not silently break rule logic.


Detection lifecycle management

  • Manage content through development, peer review, testing, approval, production release, tuning, exception handling, and retirement.
  • Maintain rule ownership, content version, deployment state, last validation date, review frequency, and rollback instructions.
  • Identify obsolete, duplicate, low-value, or unsupported detections and coordinate controlled retirement.


Detection-as-code and deployment engineering

  • Maintain detection content in GitHub or an equivalent version-controlled repository.
  • Use structured peer review and approval workflows for production changes.
  • Support automated validation and deployment using APIs, CI/CD pipelines, infrastructure-as-code, or equivalent controlled mechanisms.
  • Ensure tenant-specific parameters and exceptions are preserved during shared-content updates.
  • Detection performance measurement
  • Track alert volume, true-positive disposition, false-positive disposition, analyst handling impact, telemetry dependencies, and detection health.
  • Define minimum observation periods and evidence requirements before declaring tuning successful.
  • Report detection changes using measurable outcomes rather than relying only on alert-volume reduction.
  • Identify detections that are silent because of telemetry failure, parsing changes, or logic defects.


MSSP content engineering

  • Design reusable detections that can be safely parameterised for multiple customers.
  • Maintain customer-specific thresholds, exclusions, risk conditions, data-source mappings, and deployment records.
  • Account for differences in licences, retention, ingestion architecture, business operations, and available telemetry.
  • Coordinate customer-impacting content changes through established approval and change-control processes.


Telemetry engineering

  • Validate data completeness, field consistency, timestamp integrity, event duplication, parsing quality, and schema stability.
  • Develop or maintain parsers and normalisation logic where required.
  • Map each detection to its mandatory and optional telemetry dependencies.
  • Implement monitoring for telemetry degradation that could affect critical detection coverage.


Collaboration & Enablement

  • Work closely with SOC analysts, onboarding consultants, and automation engineers.
  • Provide training and guidance on detection logic, rule writing, and tuning best practices.
  • Participate in incident post-mortems to identify detection gaps and improvement areas.


Qualifications


  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
  • At least 6+ years of relevant cybersecurity operations, detection engineering, threat hunting, incident response, or SIEM engineering experience.
  • At least 3+ years of hands-on production detection-content development.



Required Skills


  • Microsoft Certified: Security Operations Analyst Associate
  • Expert-level proficiency in KQL, Microsoft Sentinel, and Defender XDR.
  • Experience with Sigma rule development, UEBA, and SIEM tuning.
  • Strong understanding of log source telemetry, data normalization, and alert lifecycle.
  • Familiarity with threat intelligence platforms and MITRE ATT&CK mapping.
  • Analytical mindset with strong attention to detail.
  • Excellent documentation and presentation skills.
  • Ability to collaborate across technical and operational teams.
  • Fluent English communication skills (spoken and written).
  • Strong ability to develop, explain, troubleshoot, and optimise detection queries.
  • Demonstrable experience mapping detections to MITRE ATT&CK.
  • Experience testing, tuning, documenting, and maintaining production detections.



Preferred Skills


  • MITRE ATT&CK Defender (MAD), GIAC (GCIA, GMON), CompTIA CySA+



To apply, please submit your CV to Thinh Truong (Mr) at [email protected] or 0386729007 (Telegram/Zalo). We regret that only shortlisted candidates will be notified soon!


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search