Northwave Cyber Security logo

Detection Quality Engineer

Northwave Cyber Security
1 day ago
Full-time
On-site
Utrecht, 09
€43,200 - €69,600 EUR yearly

JobsCloseBy Editorial Insights

Northwave is seeking a Detection Quality Engineer (Medior/Senior) to join the Detection Quality team in Utrecht, full-time and onsite. You will design and refine detections using Microsoft Sentinel and Defender, translate attack techniques into actionable rules, and collaborate with analysts, threat intelligence specialists and Red Team members to strengthen our MDR capabilities. The role blends detection engineering, threat research and continuous improvement, with a strong emphasis on automation, scalability and staying ahead of adversaries through MITRE ATT&CK mapping. Must have 3+ years in detection focused cybersecurity, strong KQL, Defender and Sentinel experience, Suricata or Zeek and Python, plus solid Windows and Linux internals. To apply, tailor your CV with concrete detections and impact, show cross‑team collaboration, and highlight Purple Team, threat intel and detection‑as‑code experience. Reach out to Youri Roelofs at [email protected].


Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, creating and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who loves turning threat intelligence, attack research and adversary behavior into high-quality detections that make a real-world impact.

If you get excited by attack chains, KQL, Purple Teaming, threat hunting, and continuous improvement of detection capabilities, this role was built for you.

What you'll be doing

Detection Engineering

  • Design, build and continuously improve detection rules and monitoring content.

  • Develop advanced detection logic using Microsoft Sentinel, Microsoft Defender and other security platforms.

  • Translate attack techniques and adversary behavior into actionable detections.

  • Tune, validate and optimize detections to maximize signal and minimize noise.



Threat Research

  • Research emerging threats, attack campaigns and TTPs.

  • Analyze intelligence from MISP, CERT advisories, Red Team exercises and threat reports.

  • Map threats to frameworks such as MITRE ATT&CK and the Cyber Kill Chain.

  • Identify gaps in monitoring coverage and proactively address them.



Continuous Improvement

  • Improve SOC monitoring capabilities through automation and innovation.

  • Contribute to Purple Team initiatives and validation of detection coverage.

  • Work on strategic projects that enhance the quality, scalability and effectiveness of our MDR services.

  • Help shape the future of detection engineering within Northwave.



Collaboration & Communication

  • Work closely with analysts, engineers, threat intelligence specialists and Red Team members.

  • Document detections and provide guidance to operational teams.

  • Explain detection logic, use-case design choices and monitoring strategies to both technical and non-technical stakeholders.

Requirements

Must-have experience

  • 3+ years of experience in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development.

  • Experience designing and maintaining security detections within an EDR, XDR or SIEM environment.

  • Experience analyzing attack techniques and adversary behavior.



Technical expertise

  • Strong KQL skills.

  • Understanding of Microsoft Defender technologies.

  • Experience with Microsoft Sentinel.

  • Knowledge of attack chains, adversary TTPs and modern threat landscapes.

  • Experience with Suricata rules and/or Zeek scripts.

  • Scripting or programming experience, preferably Python.

  • Solid knowledge of Windows and Linux internals.

  • Familiarity with threat intelligence and detection use-case development.



Personal qualities

  • Analytical and curious by nature.

  • Able to work independently while being a strong team player.

  • Comfortable engaging with stakeholders across multiple teams.

  • Proactive and improvement-driven.

  • Strong communication skills.

  • Security-minded with a healthy critical attitude.



Extra points if you have

  • Experience with Purple Teaming.

  • Knowledge of the MITRE ATT&CK framework.

  • Experience validating detections against real attack simulations.

  • Experience in MDR, SOC or Incident Response environments.

  • Knowledge of detection-as-code methodologies.

  • Experience automating security workflows.



Who you'll join

You will become part of the Detection Quality team, a highly technical group of engineers responsible for the detections of our SOC.

Our values are simple:

  • Quality first

  • Continuous improvement

  • Efficiency through automation

  • Ownership and responsibility

  • Customer impact



We challenge each other, support each other and continuously push our detection capabilities to the next level.

Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at [email protected].