MDR Security Engineer
Base Cyber Security · Amsterdam
Wat je gaat doen
- Develop and improve detection use cases based on relevant threats and observed behaviour.
- Perform proactive threat hunting to identify suspicious or abnormal activity.
- Analyse security logs and telemetry to investigate potential threats.
- Translate threat scenarios and security findings into practical detection approaches.
- Identify gaps in existing detection coverage and contribute to improvements.
- Refine detections to improve their accuracy and relevance.
- Help determine appropriate response, escalation, and automation actions when detections are triggered.
- Use threat intelligence and security developments to support new detection and hunting activities.
- Contribute to the continuous improvement of MDR and detection capabilities.
- Communicate relevant security findings and threat information to engineers and other stakeholders.
- Work with engineering teams to understand system behaviour and validate detection approaches.
- Collaborate with security, platform, and automation specialists to improve detection and response capabilities.
Wat ze zoeken
- Experience within security engineering, security operations, threat detection, infrastructure, or a related technical security field.
- Experience working with security logs, monitoring data, telemetry, or comparable technical data sources.
- General understanding of IT infrastructure, networking, operating systems, and system behaviour.
- Ability to investigate and distinguish expected activity from potentially suspicious behaviour.
- Familiarity with security monitoring, SIEM, log analytics, or comparable security technologies.
- Understanding of fundamental security principles related to threat detection and response.
- An analytical approach to investigating technical and security-related problems.
- Interest in automation and improving security processes at scale.
- Ability to take ownership of security investigations and improvements.
- Good communication skills and the ability to turn technical findings into actionable information.
General description
We are looking for a Security Engineer with a focus on Managed Detection & Response (MDR), threat hunting, and improving security detection capabilities. In this role, you help identify potential cyber threats and strengthen how suspicious activity is detected across complex IT environments.
You work with security data, threat information, and engineering teams to understand unusual behaviour, identify gaps in existing monitoring, and develop or improve detection scenarios. The position combines security analysis with an engineering mindset and provides room to further develop your expertise in threat hunting and detection engineering.
You do not need to be a specialist in every technology involved. More important is a solid understanding of security and IT environments, an analytical mindset, and the ability to investigate how threats and systems behave.
Competencies
- Analytical and investigative mindset.
- Curious about cybersecurity and how systems and threats behave.
- Proactive in identifying potential security improvements.
- Hands-on and comfortable investigating technical security problems.
- Strong sense of ownership and responsibility.
- Able to critically assess existing approaches and suggest improvements.
- Comfortable working independently and together with engineering and security teams.
- Able to clearly communicate findings to different stakeholders.
- Motivated to continuously develop cybersecurity knowledge.
- Interested in automation and continuous improvement.
Wishes
- Experience or a strong interest in threat hunting and detection engineering.
- Experience within a SOC, MDR, security operations, or comparable environment.
- Familiarity with scripting or automation, for example Python or Bash.
- Experience with SIEM or log analytics platforms such as Elastic, OpenSearch, Splunk, Microsoft Sentinel, or similar technologies.
- Familiarity with SOAR or security automation.
- Exposure to cloud environments such as AWS, Azure, or comparable platforms.
- Familiarity with modern engineering practices such as CI/CD, Git, or configuration tooling.
- Experience using threat intelligence to support security monitoring, detection, or investigations.
Relevant terms
Security Engineer, MDR, Managed Detection and Response, Threat Hunting, Detection Engineering, Threat Detection, Threat Intelligence, Security Operations, SOC, SIEM, SOAR, Security Monitoring, Security Automation, Detection Use Cases, Log Analysis, Security Telemetry, Incident Response, Security Analytics, Detection Coverage, Linux, Networking, Python, Bash, OpenSearch, Elastic, Splunk, Microsoft Sentinel, Cloud Security, AWS, Azure, CI/CD, Git, Security Engineering, Cyber Threats, Cybersecurity.
Base Cyber Security helps organizations build knowledge and capabilities in the field of information security. A key part of this involves supporting organizations in assembling strong information security teams or finding the right cybersecurity experts to meet their specific needs. We collaborate with security professionals worldwide to fill information and cybersecurity roles and projects across Europe. Whether you are just starting your career in information security, need advice on your next career steps, or want to know how to continue your professional development and make the right choices, we are here to help and would love to connect with you! If you haven’t registered yet, make sure to do so now! Send your details to [email protected] and follow us on X/Twitter @BaseCyberSec to stay updated on our activities and relevant information. By registering with our security community and expressing interest in a specific role, project, or team, you grant us explicit permission to use your data—which Base Cyber Security collects and processes ethically and discreetly, and, where applicable, in compliance with the General Data Protection Regulation (GDPR).