Eye Security
Detection Engineer (based in Netherlands or Germany; relocation needed)
Job Summary
The role involves developing, implementing, and maintaining detection mechanisms to identify and respond to security threats within a SOC environment. Candidates should have experience with security monitoring, detection rules, SIEM, and scripting languages for automation. The position emphasizes collaboration with the SOC team, staying updated on threat intelligence, and optimizing detection capabilities. Benefits include team activities, flexible time off, and stock options, supporting a balanced and engaging work experience.
Required Skills
Benefits
Job Description
About Us
Eye Security is a fast-growing cybersecurity scale-up founded in 2020 by three employees of the Dutch Secret Service with the mission to protect the digital assets of SMEs across Europe. With a robust portfolio under the Eye Cyber Guard product bundle, Eye Security offers customized cybersecurity solutions in a subscription-based SaaS model. The offering ranges from Managed Detection and Response, Incident Response and Attack Surface Management to Security Awareness Services and Insurance and is aimed at a customer base of over 450 companies. Eye Security currently employs over 140 ambitious IT experts in the Netherlands, Belgium, Germany and the UK.
About the team & role
We are seeking a skilled and motivated Detection Engineer to join our SOC team. The ideal candidate will be responsible for developing, implementing, and maintaining detection mechanisms to identify and respond to security threats and optimize the already existing detection flows. This role requires a deep understanding of cybersecurity principles, threat detection methodologies, and incident response.
Your role at Eye
Develop and maintain detection rules for the security products supported by our service offering and manage indicators to identify potential security threats.
Monitor security alerts and events to identify suspicious activities and potential breaches through our in-house built alerting dashboards.
Conduct thorough analysis of security incidents and provide detailed reports.
Collaborate with the SOC team to improve detection capabilities and response strategies based on real-world scenarios and threats.
Stay updated with the latest open- and closed-source threat intelligence and incorporate it into detection mechanisms.
Perform regular tuning and optimization of existing detection flows and technologies, both in-code and in formal processes.
Assist in the development and implementation of security policies and procedures.
Provide guidance and training to junior SOC analysts on detection techniques and best practices.
You'll be a great fit if you have
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 3 years of experience in a similar role within a SOC or cybersecurity environment.
Strong knowledge of security information and event management (SIEM) and security orchestration, automation, and response (SOAR) systems.
Proficiency in scripting languages (e.g. Bash, Python, PowerShell) and scripting languages (KQL and LogScale) for automation and detection rule creation.
Familiarity with various security tools and technologies (e.g., IDS/IPS, EDR, firewalls).
Excellent analytical and problem-solving skills.
Strong communication and teamwork abilities.
Relevant certifications (e.g., CISSP, CEH, GCIA, OSCP) are a plus.
Why Join Us?
Make an impact and help organisations in Europe be safe from cyber-attacks - as you get the opportunity to work alongside top talent with the Intelligence Agencies and Military background.
Quarterly get togethers & Annual company-wide retreat (in Spain, Portugal, Italy…).
Bond with teammates at exciting locations, learn more about the business, enjoy fun team activities.
Access to cutting-edge cybersecurity technologies and tools.
Generous time off policy (including volunteering day, floating holidays and wellbeing time off) to balance your work and personal life.
Base compensation and company’s stock (ESOP).
#LI-Remote
Eye Security
Eliminate cyber threats with a 24/7 SOC to mitigate every breach and connected cyber insurance to eliminate the remaining risk.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.