Detection Engineer

apartmentAllianz placeBarcelona calendar_month 

Experteer Overview

Join Allianz Technology’s Cyber Defense Center to advance 24/7 monitoring through advanced detection. You will own the detection use-case lifecycle, shaping what security signals are seen and investigated. You’ll design and maintain content for Google SecOps (YARA-L) and CrowdStrike Falcon, aligned to logging telemetry.

This role combines threat intelligence with security operations to continuously improve coverage and reduce false positives.

Compensaciones / Beneficios
  • Own the full detection use case lifecycle from concept to production-ready monitoring
  • Design, implement, and maintain detection content in Google SecOps (YARA-L) and CrowdStrike Falcon aligned with logging telemetry
  • Map detections to the MITRE ATTu0026CK framework and perform gap analyses to prioritize new use cases
  • Tune detections iteratively to minimize false positives while preserving fidelity
  • Write clear use case specification documents detailing scope, logging, threats, and analyst response
  • Collaborate with SOAR/automation engineers and CTI to ensure detections feed into playbooks and reflect current threat reporting
  • Validate detections through purple-team exercises and adversary emulation using Detection-as-Code
Responsabilidades
  • 3+ years in detection engineering, SOC engineering, threat hunting, or related security operations
  • Experience writing and tuning detection content in a modern SIEM (Google SecOps/Chronicle YARA-L preferred; Splunk SPL, Sentinel KQL, Elastic EQL valued)
  • Working knowledge of EDR platforms, ideally CrowdStrike Falcon (custom IOAs, event search, Falcon Query Language)
  • Strong understanding of MITRE ATTu0026CK and applying it to detection design
  • Solid grasp of attacker tradecraft across Windows, Linux, cloud (AWS/Azure/GCP), and identity (AD, Entra ID)
  • Proficiency in at least one scripting or query language (Python, PowerShell, SQL, regex) and familiarity with Detection-as-Code (Git, CI/CD)
  • Clear written English communication; ability to explain detection purpose, coverage, and triage steps
Requisitos principales
  • hybrid work model
  • up to 25 days abroad
  • bonus scheme
  • pension
  • employee shares program
  • learning and career mobility
apartmentMichael PageplaceBarcelona
and retests, supporting detection tuning, delivering metrics and runbooks that empower engineering teams to remediate efficiently, and engaging with product and platform stakeholders to facilitate triage, clarify ownership and coordinate remediation activities...
apartmentMichael PageplaceBarcelona
tooling improvements to support detection engineering - shared rule templates, test harnesses, linters, rule packaging - with related documentation and handover notes Manage infrastructure, data pipeline and content deployments using IaC tools (like...
starOferta destacada

Detection Engineer - AI/ML

apartmentAllianzplaceBarcelona
and SIEM telemetry  •  Build and maintain AI-powered detection pipelines that adapt to new threats  •  Collaborate with Detection Engineers to translate model outputs into actionable, explainable detections  •  Engineer features and curate training data from...