Detection Quality Engineer
Summary
Build and refine cybersecurity detection rules and automation for a SOC using KQL, Microsoft Sentinel/Defender, and threat intelligence to turn adversary behavior into actionable alerts.
Attackers innovate every day. So do we.
At Northwave, we believe effective cybersecurity starts long before an incident occurs. Our Detection, Quality & Stack (DQS) team is responsible for the technical foundation of our SOC, building and maintaining the detections, tooling and automation that protect organizations across the Netherlands and Europe.
We're looking for a Detection Quality Engineer (Medior/Senior) who turns threat intelligence, attack research and adversary behavior into detections that make a real-world impact. If attack chains, KQL, Purple Teaming and threat hunting get you excited, this role was built for you.
What you'll be doing
Design, build and continuously improve detection rules and monitoring content in Microsoft Sentinel, Defender and other security platforms
Translate attack techniques, adversary behavior and threat intelligence (MISP, CERT advisories, Red Team exercises) into actionable, well-tuned detections
Map threats to frameworks like MITRE ATT&CK and the Cyber Kill Chain, and proactively close monitoring gaps
Contribute to Purple Team initiatives, detection coverage validation and strategic projects that scale our MDR services
Work closely with analysts, engineers, threat intel specialists and Red Team members, and explain detection logic to technical and non-technical stakeholders alike
What you bring
3+ years in cybersecurity with a strong focus on detection engineering, monitoring or detection rule development, within an EDR, XDR or SIEM environment
Strong KQL skills, solid understanding of Microsoft Defender and hands-on experience with Microsoft Sentinel
Knowledge of attack chains, adversary TTPs and the modern threat landscape
Experience with Suricata rules or Zeek scripts, scripting or programming (Python preferred), and solid Windows and Linux internals knowledge
Analytical, proactive and a strong communicator, comfortable working independently while engaging stakeholders across teams
Extra points if you have
Purple Teaming or MITRE ATT&CK experience
Experience validating detections against real attack simulations
Background in MDR, SOC or Incident Response
Knowledge of detection-as-code or experience automating security workflows
Who you'll join
You'll become part of the Detection Quality team, a highly technical group of engineers responsible for the detections behind our SOC. Our values: quality first, continuous improvement, efficiency through automation, ownership, and customer impact.
What we offer
Competitive salary, paid on the 25th, with annual review and 8% holiday allowance
Pension via Nationale Nederlanden, Northwave pays 50%, including partner pension
25 vacation days plus all national holidays, and generous special leave for marriage, birth, bereavement, care and pregnancy
Lease car based on salary scale (electric included), or €0.25/km plus 50% lease budget as a mobility allowance
MacBook, phone and accessories fully provided, plus €200 net annual allowance for flexible and remote working
Alleo budget for sports, wellness and leisure, plus a training budget
Referral bonus for bringing in a new colleague
Hybrid working from a modern office in Utrecht, with personal growth central through the Role Model and FeedForward cycle
We challenge each other, support each other and continuously push our detection capabilities to the next level.
Interested in building systems that are used under real pressure, not in theory? Contact Youri Roelofs at [email protected].