freehire launches on Product Hunt on 26 August.

Follow →

Detection Quality Engineer

Open 18d

Summary

Build and refine cybersecurity detection rules and automation for a SOC using KQL, Microsoft Sentinel/Defender, and threat intelligence to turn adversary behavior into actionable alerts.

Attackers innovate every day. So do we.

At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, building and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.

We're looking for a Detection Quality Engineer (Medior/Senior) who turns threat intelligence, attack research and adversary behavior into detections that make a real-world impact. If attack chains, KQL, Purple Teaming and threat hunting get you excited, this role was built for you.


What you'll be doing

  • Design, build and continuously improve detection rules and monitoring content in Microsoft Sentinel, Defender and other security platforms

  • Translate attack techniques, adversary behavior and threat intelligence (MISP, CERT advisories, Red Team exercises) into actionable, well-tuned detections

  • Map threats to frameworks like MITRE ATT&CK and the Cyber Kill Chain, and proactively close monitoring gaps

  • Contribute to Purple Team initiatives, detection coverage validation and strategic projects that scale our MDR services

  • Work closely with analysts, engineers, threat intel specialists and Red Team members, and explain detection logic to technical and non-technical stakeholders alike

What you bring

  • 3+ years in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development, within an EDR, XDR or SIEM environment

  • Strong KQL skills, solid understanding of Microsoft Defender and hands-on experience with Microsoft Sentinel

  • Knowledge of attack chains, adversary TTPs and the modern threat landscape

  • Experience with Suricata rules or Zeek scripts, scripting or programming (Python preferred), and solid Windows and Linux internals knowledge

  • Analytical, proactive and a strong communicator, comfortable working independently while engaging stakeholders across teams


Extra points if you have

  • Purple Teaming or MITRE ATT&CK experience

  • Experience validating detections against real attack simulations

  • Background in MDR, SOC or Incident Response

  • Knowledge of detection-as-code or experience automating security workflows


Who you'll join

You'll become part of the Detection Quality team, a highly technical group of engineers responsible for the detections behind our SOC. Our values: quality first, continuous improvement, efficiency through automation, ownership, and customer impact.


What we offer

  • Competitive salary, paid on the 25th, with annual review and 8% holiday allowance

  • Pension via Nationale Nederlanden, Northwave pays 50%, including partner pension

  • 25 vacation days plus all national holidays, and generous special leave for marriage, birth, bereavement, care and pregnancy

  • Lease car based on salary scale (electric included), or €0.25/km plus 50% lease budget as a mobility allowance

  • MacBook, phone and accessories fully provided, plus €200 net annual allowance for flexible and remote working

  • Alleo budget for sports, wellness and leisure, plus a training budget

  • Referral bonus for bringing in a new colleague

  • Hybrid working from a modern office in Utrecht, with personal growth central through the Role Model and FeedForward cycle


We challenge each other, support each other and continuously push our detection capabilities to the next level.

Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at [email protected].

What this application asks

recruitee

Full name, Email, CV, Cover letter, Phone

  • Are you current a Dutch resident? yes / no
  • What is your salary range?

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available