Detection Engineer.
You think like an attacker and build like a defender. At DEFION, you transform real Red Team findings into detection rules that actually catch threats in production.
Apply nowWhere offense meets defense
DEFION has been protecting organizations since 2005. Our Detection Engineering team sits at the intersection of offense and defense: you take findings from real attacker simulations and Red Team exercises and translate them into detection rules that work across SIEM, EDR, and XDR platforms.
You will not just consume threat intelligence; you will generate it and apply it. You work in a multidisciplinary team alongside Red Teamers, Blue Teamers, and threat hunters in our Barcelona office (or remotely).
What you will do
- Design, develop, and fine-tune detection rules in SIEM, EDR, and XDR platforms (Sentinel, CrowdStrike, Cortex, Splunk, and more)
- Analyze results from attacker simulations to identify weaknesses in security controls
- Develop detection and mitigation strategies for emerging threats using MITRE ATT&CK
- Automate and optimize processes with Python, PowerShell, and Bash scripts
What you bring
Must have:
- 1-2 years of experience as Detection Engineer or SOC Analyst creating/optimizing alerts in SIEM/EDR
- Knowledge of KQL (Kusto Query Language) and/or CQL (CrowdStrike Query Language)
- Deep knowledge of Windows logs, telemetry, and event analysis for proactive threat detection
- Strong understanding of adversary TTPs based on MITRE ATT&CK
- Scripting skills in Bash, Python, or PowerShell
- Knowledge of Windows and Linux system administration, TCP/IP, DHCP, DNS
- Purple-team mindset: think like an adversary, enhance defensive capabilities
- Clear communication in English for international team collaboration
Nice to have:
- Cybersecurity certifications or a master's degree in a related field
- Degree in Engineering, Cybersecurity, or related field
Why you will love working here
Red + Blue collaboration
Work closely with Red Team and Blue Team. Access to EDR, SIEMs, threat intelligence, and more.
Continuous training
Internal and external training, certifications, and annual conference attendance.
Career plan
A personalized professional development plan tailored to your interests and growth goals.
Barcelona office or remote
Flexible remote work or a comfortable office in central Barcelona. Summer reduced hours.
Health + benefits
Private health insurance, flexible compensation (meals, transport, childcare, training).
International team
Young, dynamic, and international team with an excellent work environment and work-life balance.
Apply now
Send your CV and motivation. We respond within 3 business days.
Other open positions
SOC Analyst (Barcelona)
Monitor and analyze security alerts. CrowdStrike, Sentinel, threat intelligence.
Defensive SecurityMedior SOC Analyst (NL)
Sharp eye in our Dutch SOC. Microsoft Defender, Sentinel, 24/7 MDR operations.
ResearchSr. Vulnerability Researcher / Hardware Hacker
Groundbreaking research at DEFION Research Labs. Pwn2Own, CVEs, conferences.
®