Engineering & Technology
Middle
Poland

Security Detection Engineer

ABOUT THE ROLE

In this role, you will work at the intersection of network security, data science, and software engineering, focusing on developing detection logic against real-world telemetry. You will treat detections as code, meaning they will be version-controlled, peer-reviewed, tested, measured, and continuously improved to maximize true-positive coverage while reducing false positives.

You will primarily work with network telemetry, including NetFlow, DNS queries, TLS certificate data, SMB filenames, and other L7 metadata extracted from firewall connection records. Over time, you will also help evolve detection capabilities as the platform incorporates endpoint and identity signals.

RESPONSIBILITIES

  • Design and build behavioral models to detect malicious activity and identify meaningful anomalies in network behavior
  • Develop detections for attack techniques such as beaconing, DGA, data staging, lateral movement, DNS tunneling, scanning, port hopping, and unusual remote administration activity
  • Translate concrete detection use cases into production-ready detection logic, signatures, and behavioral indicators
  • Collaborate with threat intelligence teams, including Cisco Talos, to convert emerging threat research into actionable detection content
  • Build, evaluate, and continuously tune detections using efficacy metrics such as precision, recall, false-positive rate, and MITRE ATT&CK coverage
  • Use production-scale telemetry on Databricks to validate and improve detection performance
  • Work with engineering teams to productionize detections as part of a SaaS service, with potential deployment to on-premise environments
  • Support threat hunting, investigations, and triage activities with detection expertise
  • Use threat intelligence platforms and OSINT sources to enrich detections with current threat context, reputation data, and IOCs
  • Apply networking and network security knowledge to model traffic behavior and create precise, low-noise detection logic
  • Document detection methodology, assumptions, tuning decisions, and share knowledge across security and engineering teams

REQUIREMENTS

  • Proven experience developing code-like detection content for network threats, including rule-based, signature-based, or behavioral detections
  • Strong knowledge of networking and network security, including TCP/IP, DNS, HTTP/S, TLS, SSH, traffic analysis, network architecture, and common attack vectors
  • Coding or scripting proficiency for detection development and data analysis, especially with Python and SQL
  • Experience with rule languages or detection formats such as Sigma, Snort, Suricata, or similar
  • Practical experience applying AI/ML techniques to security detection, including anomaly detection, classification, or behavioral modeling
  • Experience with SecOps workflows, including threat hunting, incident investigation support, and improving detections based on operational findings
  • Experience using threat intelligence tools, feeds, and OSINT sources to enrich and contextualize detection logic
  • Familiarity with detection frameworks such as MITRE ATT&CK and mapping detections to adversary tactics and techniques
  • Experience with NDR platforms, security analytics, or SIEM solutions
  • Strong analytical and problem-solving skills, with high attention to detail
  • Clear documentation and cross-team communication skills
  • Endpoint security experience is a strong plus, but not mandatory

SoftServe is an equal opportunity employer. Qualified applicants will receive consideration regardless of race, color, ancestry, ethnicity, national origin, religion, sex, sexual orientation, gender identity or expression, age, citizenship, disability, health condition, marital or family status, veteran status, or any other characteristic protected by applicable law.

#LI-Remote

Role Summary

Location

Poland

Work type

Remote/Office

Direction

Engineering & Technology

Subdirection

Cybersecurity

Tech level

Middle

Personal recruiter:

Radek Kozlowski

Personal recruiter

Apply Now

Fill out the form, and we'll be in touch shortly.

CV/Resume in English will speed up its processing time
Upload file

About us

We are a digital engineering and technology consulting company where expertise grows alongside people. For more than 30 years, we have been elevating technology: helping organizations navigate complex business challenges by combining deep engineering knowledge with thoughtful, research-backed innovation. Our teams work across key areas: digital engineering, data and analytics, Сloud, and AI/ML. In each, we deliver practical, scalable solutions rooted in real business needs and measurable human impact.

You bring your perspective and ambition. We create an environment where your work meets clarity, confidence, and purpose.

About us

We offer

Flexible work model

Work from home, from the office, or in a hybrid format that supports focus and collaboration.

Compensation & Benefits

Competitive, market-based pay, benchmarked by role and location — plus health coverage, paid time off, wellness support, and learning opportunities.

People-first Leadership

Approachable leaders who communicate openly, keep teams close to the strategy, and support long-term planning.

Advanced tech communities

Stay close to AI/ML, Cloud, Quantum Computing, IoT, and Robotics communities, with projects built on modern frameworks.

More opportunities available

Browse all open positions to find the best fit for your experience.

Browse all positions
102405