*** Stay up to date with the GPC's latest opportunities ***  Upload your CV   Register   

[6323] Detection Engineer

Start date: Negotiable
Clearance: NATO Secret or equivalent
Location: Mons, BE

Skill, Knowledge & Experience:
• Minimum three years of hands-on experience in a Security Operations Centre (SOC, CSOC, GSOC or equivalent) or a closely related cyber monitoring environment.
• Minimum three years of hands-on experience in a Security Operations Centre (SOC, CSOC, GSOC or equivalent) or a closely related cyber monitoring environment.
• At least three years of experience designing, developing and maintaining detection rules, alerts and analytics across SIEM, EDR/XDR and cloud security tools (e.g., Splunk, Microsoft Sentinel, Azure, AWS).
• Experience translating attacker tactics, techniques, and procedures (TTPs) and threat intelligence into operational detection logic.
• Experience in analysis of raw telemetry and log data across multiple sources to identify detection opportunities and improve detection logic.
• Experience working with security monitoring and detection platforms such as Splunk, Microsoft Sentinel, Microsoft Defender XDR, Suricata, Snort, or comparable technologies.
• Experience working with log ingestion pipelines, normalization, and parsing processes used in security monitoring platforms.
• Adept at extracting, normalising and interrogating raw log data from diverse sources (e.g., Windows Event Logs, Linux syslog, Sysmon, EDR/XDR platforms such as Microsoft Defender, Sentinel One, or CrowdStrike) using SIEM and query tools (Splunk, Microsoft Sentinel, Elastic Kibana). Able to filter, correlate and visualise events to verify alerts, reconstruct attacker activity across hosts, and provide actionable evidence for escalation and remediation decision
• Hands-on packet-capture (PCAP) analysis experience – extracting, filtering and interpreting network traffic with tools such as Wireshark, tcpdump or Zeek to corroborate alerts, reconstruct attack timelines and support escalation decisions.
• Experience developing detections for network and edge security devices such as Cisco, Fortinet/Fortigate, Palo Alto, or comparable platforms.
• Experience supporting or mentoring less-experienced analysts and engineers, providing constructive feedback on investigation quality and reporting standards.
• Proven track record of conducting in-depth analysis of complex cyber-security incidents and delivering clear reports and recommendations to supporting teams and external partners.
• Relevant cyber security certifications (e.g., CISSP, CISM, GIAC certified credentials such as GCIH, GCFA, or GSEC; CompTIA CySA+) or equivalent recognised professional training.

Desirable
• A university degree (Bachelor's) in Cyber Security, Information Technology, Computer Science or a related discipline.
• Experience working in a regulated, high control environment such as defence, government, financial services or other enterprise sectors.
• Practical experience with automation or SOAR use cases, identifying repetitive manual tasks and creating enrichment or workflow improvements.
• Experience in working for or supporting a military or governmental organization.

Contract
Belgium
Negotiable
GPC006323
Emilio Perri
emilio@gpc.work
02031545027