Security Detection Engineer
SoftServe · Remote - Poland · Full-time · 2026-08-20
Job description
ABOUT THE ROLE
In this role, you will work at the intersection of network security, machine learning, and software engineering, focusing on developing automated, code-like detection logic against real-world network telemetry. You will treat detections as code: version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives.
You will primarily work with network telemetry, including NetFlow, DNS queries, TLS certificate data, SMB filenames, and other L7 metadata extracted from firewall connection records. A significant part of the role is building and tuning behavioural/ML models on this telemetry, not just writing static rules. Over time, you will also help evolve detection capabilities as the platform incorporates endpoint and identity signals.
RESPONSIBILITIES
- Design and build behavioural / ML models (anomaly detection, classification, baseline profiling) to detect malicious activity and identify meaningful anomalies in network behaviour
- Develop automated detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunnelling, scanning, port hopping, and unusual remote administration activity
- Translate concrete detection use cases into production-ready detection logic, signatures, and behavioural indicators
- Build automation around NDR / network telemetry - pipelines, enrichment, and tuning workflows that operationalise detections at scale
- Build, evaluate, and continuously tune detections using efficacy metrics — precision, recall, false-positive rate, and MITRE ATT&CK coverage
- Use production-scale telemetry on Databricks to validate and improve detection performance
- Collaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into detection content
- Work with engineering teams to productionize detections as part of a SaaS service, with potential on-premise deployment
- Support threat hunting, investigations, and triage with detection expertise
- Use threat intelligence platforms and OSINT to enrich detections with current threat context, reputation data, and IOCs
- Apply networking and network security knowledge to model traffic behaviour and create precise, low-noise detection logic
- Document detection methodology, assumptions, and tuning decisions, and share knowledge across security and engineering teams
REQUIREMENTS
- Direct experience with NDR platforms (e.g., Vectra, Darktrace, Zeek/Corelith, Suricata) and raw network telemetry (NetFlow, DNS, TLS/JA3, SMB, PCAP, traffic analysis)
- Proven experience building rule/signature-based and behavioural detections as code: version-controlled, peer-reviewed, tested, and iteratively tuned, plus automation built around the detection lifecycle
- Practical, hands-on experience with anomaly detection, classification, or behavioural modelling on real telemetry, not solely static correlation rules
- Strong networking & network security fundamentals - TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors
- Coding/scripting: Python and SQL for detection development and data analysis
- Knowledge of Rule languages/detection formats: Sigma, Snort, Suricata, or similar
- MITRE ATT&CK - mapping detections to adversary tactics and techniques
- SecOps workflows: threat hunting, incident investigation support, and improving detections based on operational findings
- Threat intelligence & OSINT - using feeds/platforms to enrich and contextualise detection logic
- Strong analytical & problem-solving skills, attention to detail, and clear documentation / cross-team communication