698,259open jobs
40,908companies
106,729added this week
Browse all
Location
In office
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
SOFTSWISS is an iGaming technology provider offering a full ecosystem of online casino and sportsbook software solutions and services.

Overview:

SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company’s ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.

Purpose of the role:

You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats.

Key responsibilities:

  • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.

  • Translate incident investigations, threat hunting, and attack research into effective detections.

  • Analyze false positives, false negatives, and detection gaps.

  • Improve detection coverage and map detections to MITRE ATT&CK techniques.

  • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.

  • Define requirements for logging, parsing, normalization, enrichment, and data quality.

  • Develop monitoring and health checks for detection rules and data sources.

  • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.

  • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.

  • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.

  • Document detection logic, data sources, dependencies, limitations, and expected behavior.

Required Experience:

  • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.

  • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.

  • Strong proficiency in Splunk SPL or another enterprise SIEM platform.

  • Experience developing complex queries, correlations, dashboards, and reports.

  • Practical experience tuning detections and managing exceptions and allowlists.

  • Ability to define and evaluate logging and telemetry requirements.

  • Proficiency in Python, PowerShell, or Bash for automation.

  • Experience with Git, code reviews, APIs, and basic CI/CD practices.

  • Understanding of Windows and Linux security monitoring.

  • Ability to independently investigate complex problems and drive solutions to completion.

  • Strong communication skills and the ability to work effectively across teams.

Nice to have:

  • Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.

  • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.

  • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.

  • Experience building detection quality metrics and automated validation frameworks.

  • Experience with Terraform, Ansible, or other infrastructure-as-code tools.

  • Participation in security research, conferences, or the broader security community.

Our technology focus:

Splunk Enterprise Security, MITRE ATT&CK, Windows and Linux telemetry, Kubernetes and container logs, Python, PowerShell, Bash, Git, and CI/CD.

Our Benefits:

  • Private health insurance

  • Sports benefits

  • Comprehensive Mental Health Program

  • Free English lessons (online)

  • Local language courses

  • Paid time off

  • Maternity leave support

  • Referral program rewards

  • Upskilling, internal workshops, and participation in professional conferences and corporate events

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
698,259 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
In office • 7+ years exp
Python
Go
Bash
DevOps
Ansible
Red Hat
Podman
VMWare
Azure
CI/CD
AWS
Docker
Kubernetes
Ubuntu
KVM
CentOS Stream
Linux
Cybersecurity
PCI DSS
GDPR
Apply
In office
Python
SQL
AI/ML
Machine Learning
Analytics
Dimensional Modeling
Apply
$111k – $225k per year (Estimated) • Equity • In office • Secret • 5+ years exp • High School Diploma • West Palm Beach
Python
MATLAB
Robotics
ArduPilot
MAVLink
Obstacle Avoidance
Apply
$190k – $265k per year • In office • Full-Time • 4+ years exp • San Francisco
JavaScript
Node JS
Databases
PostgreSQL
Redis
AI/ML
Anthropic
DevOps
CI/CD
AWS
Apply
In office • 8+ years exp
JavaScript
Java
SQL
Databases
RabbitMQ
Apache Kafka
Frontend
React.js
DevOps
Azure DevOps
Azure
CI/CD
Git
Management
Agile
Apply
$65k – $112k per year (Estimated) • In office • Full-Time • 5+ years exp • Warsaw
Python
Go
Bash
AI/ML
LLM
LLM Guardrails
DevOps
Helm
CI/CD
Kubernetes
Platform Engineering
Linux
Apply
$28k – $71k per year (Estimated) • In office • Full-Time • Belgrade
Management
Confluence
Jira
Gmail
Apply
Content Specialist 3 days ago
$17k – $46k per year (Estimated) • In office • Full-Time • 1+ year exp • Belgrade
Management
Slack
Jira
Google Sheets
Apply
$38k – $79k per year (Estimated) • In office • Full-Time • Warsaw
JavaScript
Java
TypeScript
SQL
Databases
RabbitMQ
Apache Kafka
Frontend
React.js
QA
Selenium
Cypress
Playwright
Apply
$63k – $105k per year (Estimated) • Remote • Full-Time • 7+ years exp • Warsaw
Python
Bash
Python
Asyncio
Databases
PostgreSQL
Redis
Milvus
pgvector
Qdrant
ElasticSearch
AI/ML
LangChain
LlamaIndex
Model Context Protocol
CrewAI
LLM
RAG
Semantic Search
Semantic Search
Agentic Workflows
DevOps
Kibana
Logstash
Docker
Kubernetes
Linux
Management
Agile
Scrum
Apply
See all jobs
This is one of many
698,259 more open roles from verified company boards, updated every day.