Skip to main content
Defensive Security

Detection Engineer.

Location
Spain
Hybrid/Remote, Barcelona
Employment
Full-time
Team
Defensive Security

You think like an attacker and build like a defender. At DEFION, you transform real Red Team findings into detection rules that actually catch threats in production.

Apply now
About the role

Where offense meets defense

DEFION has been protecting organizations since 2005. Our Detection Engineering team sits at the intersection of offense and defense: you take findings from real attacker simulations and Red Team exercises and translate them into detection rules that work across SIEM, EDR, and XDR platforms.

You will not just consume threat intelligence; you will generate it and apply it. You work in a multidisciplinary team alongside Red Teamers, Blue Teamers, and threat hunters in our Barcelona office (or remotely).

What you will do

  • Design, develop, and fine-tune detection rules in SIEM, EDR, and XDR platforms (Sentinel, CrowdStrike, Cortex, Splunk, and more)
  • Analyze results from attacker simulations to identify weaknesses in security controls
  • Develop detection and mitigation strategies for emerging threats using MITRE ATT&CK
  • Automate and optimize processes with Python, PowerShell, and Bash scripts

What you bring

Must have:

  • 1-2 years of experience as Detection Engineer or SOC Analyst creating/optimizing alerts in SIEM/EDR
  • Knowledge of KQL (Kusto Query Language) and/or CQL (CrowdStrike Query Language)
  • Deep knowledge of Windows logs, telemetry, and event analysis for proactive threat detection
  • Strong understanding of adversary TTPs based on MITRE ATT&CK
  • Scripting skills in Bash, Python, or PowerShell
  • Knowledge of Windows and Linux system administration, TCP/IP, DHCP, DNS
  • Purple-team mindset: think like an adversary, enhance defensive capabilities
  • Clear communication in English for international team collaboration

Nice to have:

  • Cybersecurity certifications or a master's degree in a related field
  • Degree in Engineering, Cybersecurity, or related field
What we offer

Why you will love working here

Red + Blue collaboration

Work closely with Red Team and Blue Team. Access to EDR, SIEMs, threat intelligence, and more.

Continuous training

Internal and external training, certifications, and annual conference attendance.

Career plan

A personalized professional development plan tailored to your interests and growth goals.

Barcelona office or remote

Flexible remote work or a comfortable office in central Barcelona. Summer reduced hours.

Health + benefits

Private health insurance, flexible compensation (meals, transport, childcare, training).

International team

Young, dynamic, and international team with an excellent work environment and work-life balance.

Apply now

Send your CV and motivation. We respond within 3 business days.

By applying you agree to our privacy policy.