Role
You will own and evolve the company’s threat detection and threat-hunting capability. This role defines what “good” looks like for detection and increasingly engineers it directly as capability shifts into Cyber Security.
This is not an alert-triage role. You are here to understand attacker behaviour, convert it into high-fidelity detection logic, and raise the security baseline for the entire organisation.
You will partner closely with Security Operations, GRC and Engineering—setting standards, direction, and expectations—while progressively taking ownership of the most complex and high-value detection and threat engineering work.
What you’ll be responsible for
- Engineering high-fidelity threat detections across endpoint, identity, cloud, and SaaS
- Defining detection standards, principles, and quality thresholds for Security Operations
- Conducting proactive threat hunting based on attacker behaviour, not vendor alerts
- Translating threat intelligence and incident learnings into durable, reusable detections
- Mapping detections to MITRE ATT & C K and real-world attack paths
- Reducing alert fatigue through logic refinement, correlation, and contextual enrichment
- Advising and supporting during high-severity security incidents; contribute to runbooks and escalation playbooks
- Driving the transition of advanced detection capability into Cyber Security ownership
What we’re looking for
- Proven experience in detection engineering, threat hunting, or advanced SOC roles
- Deep understanding of modern attacker tradecraft and intrusion techniques across the attack lifecycle
- Hands-on experience buidling detection logic in modern SIEM platforms (e.g Sentinel)
- Proficienty with scripting and programmaining (e.g. Python, KQL) to build detection pipelines and automation
- Willingness to challenge bad detections, weak assumptions, and vanity metrics
- Pragmatic mindset: precision and impact beat coverage theatre
- Experience operating beyond traditional SOC or MSSP models
- Hands‑on cloud detection experience (identity, control plane, SaaS)
- Familiarity with threat intelligence platforms and frameworks such as PCI DSS, NIST CSF, SOC 2, ISO27001, CIS Benchmarks, and MITRE ATT & C K for Cloud.