Posted on: 21/08/2026
Key Responsibilities :
- Develop and maintain KQL queries for threat detection and security monitoring within SIEM platforms.
- Design detection use cases aligned with the MITRE ATT&CK framework.
- Analyze and investigate security alerts to identify potential threats.
- Collaborate with the Incident Response team during security investigations.
- Tune and optimize detection rules to improve detection accuracy and reduce false positives.
- Identify gaps in existing detection coverage and develop new detection scenarios.
- Monitor emerging attack techniques and enhance detection capabilities accordingly.
- Document detection logic, investigation findings, and security use cases.
Mandatory Skills :
- KQL (Kusto Query Language)
- SIEM
- MITRE ATT&CK Framework
- Threat Detection
- Security Alert Investigation
- Incident Response
Good to Have :
- Microsoft Sentinel
- Threat Hunting
- Detection Engineering
- SOC experience
- Cloud Security
- Threat Intelligence
Candidate Profile :
- Strong analytical and problem-solving skills.
- Good understanding of cybersecurity threats and attack techniques.
- Ability to work closely with SOC and Incident Response teams.
- Strong communication and documentation skills.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1665029