Unisys logo

Cyber Security Engineer

Unisys

RemoteFull timeMid levelPosted today
Apply with JobAssist

About the role

Our client is a prestigious European institution with a Cyber Security Operations Centre whose mission is to strengthen the IT Security for the whole organization.

The Institution is looking for a skilled Cybersecurity Engineer to reinforce their Threat Detection Engineering team. We are looking for a Cybersecurity Engineer professional who will be involved in the design, implementation, integration, configuration, administration, and maintenance of the client’s cybersecurity infrastructure and solutions.

If you are looking for a big-impact cybersecurity opportunity, then we have the right one for you!

Contract type: Freelancer agreement, with an initial contract duration of 220 days, with the possibility for renewal

Workplace type: Remote within EU territory (besides 20 days of on-site office presence in Luxembourg at the client's site; trips are not compensated )

Daily rate offer for this role: 430 euros

Key Responsibilities:

The Threat Detection Engineer will:

  • Develop threat-informed detection content by translating cyber threat intelligence, incident reports and adversary techniques into documented threat vectors, detection hypotheses and measurable detection objectives.
  • Design, implement and maintain managed detection rules using the internal Detection Engineering framework.
  • Deploy detection rules across Security Operations Centre platforms, including SIEM and endpoint or runtime detection solutions.
  • Develop detection use cases for physical, virtual and containerised Linux workloads.
  • Address threats related to execution, persistence, privilege escalation, credential access, defence evasion, lateral movement and data exfiltration in container and Kubernetes environments.
  • Integrate and validate container-security telemetry sources, including runtime events, Kubernetes audit logs, orchestration events and relevant cloud control-plane logs.
  • Ensure that security data is properly normalised, enriched, ready for correlation and of sufficient quality for use within the corporate SIEM.
  • Continuously tune and optimise deployed detections, including false-positive reduction, exception and exclusion management, suppression logic, risk scoring and performance monitoring.
  • Conduct proactive threat-hunting and retro-hunting activities across containerised Linux workloads.
  • Document threat-hunting results and convert validated detection prototypes into production-ready managed detection rules.
  • Map detections to relevant threat techniques, identify detection coverage gaps and recommend improvements to logging and telemetry.

Minimum Education Requirement

Candidates must hold a qualification corresponding to at least Level 5 of the European Qualifications Framework , which typically corresponds to two years of post-secondary education or higher for the Confirmed seniority level.

Required Knowledge and Experience

Candidates must demonstrate:

  • In-depth knowledge of Linux operating systems and Linux security.
  • Strong understanding of attacker techniques affecting Linux environments.
  • Knowledge of process, file-system and network telemetry, audit sources, persistence techniques and privilege-escalation methods.
  • Proven experience in detection engineering for containerised workloads.
  • Understanding of container runtime concepts, including namespaces, cgroups, image lifecycle and isolation boundaries.
  • Knowledge of common container attack paths, including container escape and breakout scenarios.
  • Hands-on knowledge of Kubernetes security telemetry and threats.
  • Experience with Kubernetes audit logging, RBAC abuse patterns, workload identities, admission controls and common security misconfigurations.
  • Practical experience with at least one container runtime detection solution, such as Falco, Sysdig or an equivalent platform .
  • Experience authoring and tuning runtime detection rules.
  • Experience managing detection suppressions, exclusions and rule lifecycles in production environments.
  • Demonstrated ability to design, test, validate, deploy and maintain detection logic through a structured detection lifecycle.
  • Eligibility for a European Security Clearence at EU-LEVEL SECRET

Millions of jobs, with real people getting hired every day

20,000+
New jobs added daily
7,000,000+
Verified job listings
500,000+
Tailored applications submitted
FAQ

Questions, answered

Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.

Yes. This role at Unisys was screened before publishing – we confirmed the employer before listing it.

The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.

This position can be done from anywhere, with no in-office requirement.

Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.