Cyber Security Detection Engineer
Arpya · Tirana
Job description
About the role
Arpya, the cybersecurity division of Global Technologies, is seeking a senior Detection Engineer to own and expand its detection and response automation capabilities. You will build a version‑controlled detection rule library, map coverage to MITRE ATT&CK, and create automation workflows that enrich alerts before analysts see them.
Key responsibilities
- Design, develop and maintain detection rules for Microsoft Sentinel and XDR/EDR platforms, managed as code in Git and deployed across all client environments.
- Tune the detection estate based on false‑positive rates and retire under‑performing rules.
- Map detection coverage to MITRE ATT&CK and close priority gaps for each client.
- Build and maintain SOAR‑style automation for alert enrichment, context assembly, case‑management integration and reporting.
- Define and document criteria for automated response actions.
- Review analyst incident records before client delivery and set the team’s technical standard.
- Mentor analysts according to the published career framework.
- Measure and report operational metrics monthly, including false‑positive rates and analyst effort per alert.
- Administer SIEM and EDR tenant configurations, respecting client change‑control processes.
Required profile
- Bachelor’s degree in Cybersecurity, Computer Science, or a related field, or equivalent work experience.
- Five or more years of experience in security operations with demonstrable detection‑engineering work.
- Strong KQL expertise and experience authoring analytics rules in Microsoft Sentinel, Wazuh, CrowdStrike, etc.
- Proficiency in Python for automation and API integration.
- Experience with a security orchestration or automation platform (e.g., Cortex XSOAR, Splunk SOAR, Tines, Azure Logic Apps).
- Disciplined version‑control practice with detection content stored in a repository.
- Senior‑level ability to review and provide precise feedback on analysts’ incident work.
Required skills
- Microsoft Sentinel
- XDR / EDR platforms
- Git
- MITRE ATT&CK
- SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines, Azure Logic Apps)
- KQL
- Python
- Wazuh
- CrowdStrike
- API integration
- SIEM administration
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Albania.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 2 weeks from now
10 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Arpya
Tirana