JobbfinderJobbfinder

Senior Detection Engineer (KQL / Microsoft Sentinel & Defender XDR)

ACADEMIC WORK SWEDEN AB · Malmö · Heltid

Ansök med AI-brevAnsök hos arbetsgivaren
Ready to lead a global detection migration? ASSA ABLOY in Malmö is looking for a Senior Detection Engineer to lead the transition of threat detection logic from Splunk and SentinelOne over to Microsoft Defender XDR & Sentinel.About the roleThis is a full-time consultancy assignment (40h/week) based in Malmö on a hybrid schedule, running initially through the end of the year with a strong potential for extension.As a Detection Engineer, you will play a key role in consolidating and modernizing ASSA ABLOY’s global threat detection capability. You will evaluate existing rules in Splunk and SentinelOne, translate and optimize search queries into KQL, and build tailored detections in Microsoft Defender XDR and Microsoft Sentinel. The objective is to achieve high-fidelity threat detection with minimal false positives, accompanied by thorough documentation for the SOC team.Work tasksThe role focuses on transforming and optimizing security detection rules from legacy systems into a modern Microsoft SIEM/XDR environment to ensure a threat-informed defense.Logic Conversion & Optimization: Evaluate existing detection logic in Splunk (SPL) and SentinelOne, and re-engineer queries into efficient KQL rules. Gap Analysis & MITRE Mapping: Identify detection gaps, eliminate redundant alerts, and align detections with the MITRE ATT&CK framework. Tuning & Validation: Test and fine-tune detection rules within Microsoft Defender XDR and Sentinel to reduce noise. Documentation & Enablement: Collaborate closely with SOC analysts, threat hunters, and platform engineers, creating clear standard operating procedures.We are looking forAt least 5 years of experience within Cyber Security, SOC, Threat Hunting, or Detection Engineering.Strong hands-on experience in KQL (Kusto…
IT-säkerhetschefIT-säkerhetsspecialister