Engineering & Technology
Middle
Poland

Security Detection Engineer

ABOUT THE ROLE

In this role, you will work at the intersection of network security, machine learning, and software engineering, focusing on developing automated, code-like detection logic against real-world network telemetry. You will treat detections as code: version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives.

You will primarily work with network telemetry, including NetFlow, DNS queries, TLS certificate data, SMB filenames, and other L7 metadata extracted from firewall connection records. A significant part of the role is building and tuning behavioural/ML models on this telemetry, not just writing static rules. Over time, you will also help evolve detection capabilities as the platform incorporates endpoint and identity signals.

RESPONSIBILITIES

  • Design and build behavioural / ML models (anomaly detection, classification, baseline profiling) to detect malicious activity and identify meaningful anomalies in network behaviour
  • Develop automated detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunnelling, scanning, port hopping, and unusual remote administration activity
  • Translate concrete detection use cases into production-ready detection logic, signatures, and behavioural indicators
  • Build automation around NDR / network telemetry - pipelines, enrichment, and tuning workflows that operationalise detections at scale
  • Build, evaluate, and continuously tune detections using efficacy metrics — precision, recall, false-positive rate, and MITRE ATT&CK coverage
  • Use production-scale telemetry on Databricks to validate and improve detection performance
  • Collaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into detection content
  • Work with engineering teams to productionize detections as part of a SaaS service, with potential on-premise deployment
  • Support threat hunting, investigations, and triage with detection expertise
  • Use threat intelligence platforms and OSINT to enrich detections with current threat context, reputation data, and IOCs
  • Apply networking and network security knowledge to model traffic behaviour and create precise, low-noise detection logic
  • Document detection methodology, assumptions, and tuning decisions, and share knowledge across security and engineering teams

REQUIREMENTS

  • Direct experience with NDR platforms (e.g., Vectra, Darktrace, Zeek/Corelith, Suricata) and raw network telemetry (NetFlow, DNS, TLS/JA3, SMB, PCAP, traffic analysis)
  • Proven experience building rule/signature-based and behavioural detections as code: version-controlled, peer-reviewed, tested, and iteratively tuned, plus automation built around the detection lifecycle
  • Practical, hands-on experience with anomaly detection, classification, or behavioural modelling on real telemetry, not solely static correlation rules
  • Strong networking & network security fundamentals - TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors
  • Coding/scripting: Python and SQL for detection development and data analysis
  • Knowledge of Rule languages/detection formats: Sigma, Snort, Suricata, or similar
  • MITRE ATT&CK - mapping detections to adversary tactics and techniques
  • SecOps workflows: threat hunting, incident investigation support, and improving detections based on operational findings
  • Threat intelligence & OSINT - using feeds/platforms to enrich and contextualise detection logic
  • Strong analytical & problem-solving skills, attention to detail, and clear documentation / cross-team communication

SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

#LI-Remote

Role Summary

Location

Poland

Work type

Remote/Office

Direction

Engineering & Technology

Subdirection

Cybersecurity

Tech level

Middle

Personal recruiter:

Radek Kozlowski

Personal recruiter

Apply Now

Fill out the form, and we'll be in touch shortly.

CV/Resume in English will speed up its processing time
Upload file

About us

We are a digital engineering and technology consulting company where expertise grows alongside people. For more than 30 years, we have been elevating technology: helping organizations navigate complex business challenges by combining deep engineering knowledge with thoughtful, research-backed innovation. Our teams work across key areas: digital engineering, data and analytics, Сloud, and AI/ML. In each, we deliver practical, scalable solutions rooted in real business needs and measurable human impact.

You bring your perspective and ambition. We create an environment where your work meets clarity, confidence, and purpose.

About us

We offer

Flexible work model

Work from home, from the office, or in a hybrid format that supports focus and collaboration.

Compensation & Benefits

Competitive, market-based pay, benchmarked by role and location — plus health coverage, paid time off, wellness support, and learning opportunities.

People-first Leadership

Approachable leaders who communicate openly, keep teams close to the strategy, and support long-term planning.

Advanced tech communities

Stay close to AI/ML, Cloud, Quantum Computing, IoT, and Robotics communities, with projects built on modern frameworks.

More opportunities available

Browse all open positions to find the best fit for your experience.

Browse all positions
102405