
SOFTSWISS is looking for a Senior SOC Detection Engineer to enhance security detection capabilities across various environments. Responsibilities include developing detection rules, analyzing threats, and collaborating with multiple teams.
SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company’s ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.
- Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.
- Translate incident investigations, threat hunting, and attack research into effective detections.
- Analyze false positives, false negatives, and detection gaps.
- Improve detection coverage and map detections to MITRE ATT&CK techniques.
- Develop and optimize SPL queries, dashboards, reports, and risk-based detections.
- Define requirements for logging, parsing, normalization, enrichment, and data quality.
- Develop monitoring and health checks for detection rules and data sources.
- Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.
- Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.
- Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.
- Document detection logic, data sources, dependencies, limitations, and expected behavior.
- Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.
- Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.
- Strong proficiency in Splunk SPL or another enterprise SIEM platform.
- Experience developing complex queries, correlations, dashboards, and reports.
- Practical experience tuning detections and managing exceptions and allowlists.
- Ability to define and evaluate logging and telemetry requirements.
- Proficiency in Python, PowerShell, or Bash for automation.
- Experience with Git, code reviews, APIs, and basic CI/CD practices.
- Understanding of Windows and Linux security monitoring.
- Ability to independently investigate complex problems and drive solutions to completion.
- Strong communication skills and the ability to work effectively across teams.
- Nice to have: Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.
- Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.
- Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.
- Experience building detection quality metrics and automated validation frameworks.
- Experience with Terraform, Ansible, or other infrastructure-as-code tools.
- Participation in security research, conferences, or the broader security community.
- Private health insurance
- Sports benefits
- Comprehensive Mental Health Program
- Free English lessons (online)
- Local language courses
- Paid time off
- Maternity leave support
- Referral program rewards
- Upskilling, internal workshops, and participation in professional conferences and corporate events.