About the role
Our client is a prestigious European institution with a Cyber Security Operations Centre whose mission is to strengthen the IT Security for the whole organization.
The Institution is looking for a skilled Cybersecurity Engineer to reinforce their Threat Detection Engineering team. We are looking for a Cybersecurity Engineer professional who will be involved in the design, implementation, integration, configuration, administration, and maintenance of the client’s cybersecurity infrastructure and solutions.
If you are looking for a big-impact cybersecurity opportunity, then we have the right one for you!
Contract type: Freelancer agreement, with an initial contract duration of 220 days, with the possibility for renewal
Workplace type: Remote within EU territory (besides 20 days of on-site office presence in Luxembourg at the client's site; trips are not compensated )
Daily rate offer for this role: 430 euros
Key Responsibilities:
The Threat Detection Engineer will:
- Develop threat-informed detection content by translating cyber threat intelligence, incident reports and adversary techniques into documented threat vectors, detection hypotheses and measurable detection objectives.
- Design, implement and maintain managed detection rules using the internal Detection Engineering framework.
- Deploy detection rules across Security Operations Centre platforms, including SIEM and endpoint or runtime detection solutions.
- Develop detection use cases for physical, virtual and containerised Linux workloads.
- Address threats related to execution, persistence, privilege escalation, credential access, defence evasion, lateral movement and data exfiltration in container and Kubernetes environments.
- Integrate and validate container-security telemetry sources, including runtime events, Kubernetes audit logs, orchestration events and relevant cloud control-plane logs.
- Ensure that security data is properly normalised, enriched, ready for correlation and of sufficient quality for use within the corporate SIEM.
- Continuously tune and optimise deployed detections, including false-positive reduction, exception and exclusion management, suppression logic, risk scoring and performance monitoring.
- Conduct proactive threat-hunting and retro-hunting activities across containerised Linux workloads.
- Document threat-hunting results and convert validated detection prototypes into production-ready managed detection rules.
- Map detections to relevant threat techniques, identify detection coverage gaps and recommend improvements to logging and telemetry.
Minimum Education Requirement
Candidates must hold a qualification corresponding to at least Level 5 of the European Qualifications Framework , which typically corresponds to two years of post-secondary education or higher for the Confirmed seniority level.
Required Knowledge and Experience
Candidates must demonstrate:
- In-depth knowledge of Linux operating systems and Linux security.
- Strong understanding of attacker techniques affecting Linux environments.
- Knowledge of process, file-system and network telemetry, audit sources, persistence techniques and privilege-escalation methods.
- Proven experience in detection engineering for containerised workloads.
- Understanding of container runtime concepts, including namespaces, cgroups, image lifecycle and isolation boundaries.
- Knowledge of common container attack paths, including container escape and breakout scenarios.
- Hands-on knowledge of Kubernetes security telemetry and threats.
- Experience with Kubernetes audit logging, RBAC abuse patterns, workload identities, admission controls and common security misconfigurations.
- Practical experience with at least one container runtime detection solution, such as Falco, Sysdig or an equivalent platform .
- Experience authoring and tuning runtime detection rules.
- Experience managing detection suppressions, exclusions and rule lifecycles in production environments.
- Demonstrated ability to design, test, validate, deploy and maintain detection logic through a structured detection lifecycle.
- Eligibility for a European Security Clearence at EU-LEVEL SECRET
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Unisys was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
