← Takaisin työpaikkoihin

Cyber Security Engineer

  • Etätyö
  • Ruotsi
  • Englanti
  • Julkaistu 03.09.26 11:23

Our client is a prestigious European institution with a Cyber Security Operations Centre whose mission is to strengthen the IT Security for the whole organization.The Institution is looking for a skilled Cybersecurity Engineer to reinforce their Threat Detection Engineering team. We are looking for a Cybersecurity Engineer professional who will be involved in the design, implementation, integration, configuration, administration, and maintenance of the client’s cybersecurity infrastructure and solutions. If you are looking for a big-impact cybersecurity opportunity, then we have the right one for you! Contract type: Freelancer agreement, with an initial contract duration of 220 days, with the possibility for renewal Workplace type: Remote within EU territory (besides 20 days of on-site office presence in Luxembourg at the client's site; trips are not compensated) Daily rate offer for this role: 430 euros Key Responsibilities: The Threat Detection Engineer will:Develop threat-informed detection content by translating cyber threat intelligence, incident reports and adversary techniques into documented threat vectors, detection hypotheses and measurable detection objectives.Design, implement and maintain managed detection rules using the internal Detection Engineering framework.Deploy detection rules across Security Operations Centre platforms, including SIEM and endpoint or runtime detection solutions.Develop detection use cases for physical, virtual and containerised Linux workloads.Address threats related to execution, persistence, privilege escalation, credential access, defence evasion, lateral movement and data exfiltration in container and Kubernetes environments.Integrate and validate container-security telemetry sources, including runtime events, Kubernetes audit logs, orchestration events and relevant cloud control-plane logs.Ensure that security data is properly normalised, enriched, ready for correlation and of sufficient quality for use within the corporate SIEM.Continuously tune and optimise deployed detections, including false-positive reduction, exception and exclusion management, suppression logic, risk scoring and performance monitoring.Conduct proactive threat-hunting and retro-hunting activities across containerised Linux workloads.Document threat-hunting results and convert validated detection prototypes into production-ready managed detection rules.Map detections to relevant threat techniques, identify detection coverage gaps and recommend improvements to logging and telemetry.

Minimum Education RequirementCandidates must hold a qualification corresponding to at least Level 5 of the European Qualifications Framework, which typically corresponds to two years of post-secondary education or higher for the Confirmed seniority level. Required Knowledge and ExperienceCandidates must demonstrate:In-depth knowledge of Linux operating systems and Linux security.Strong understanding of attacker techniques affecting Linux environments.Knowledge of process, file-system and network telemetry, audit sources, persistence techniques and privilege-escalation methods.Proven experience in detection engineering for containerised workloads.Understanding of container runtime concepts, including namespaces, cgroups, image lifecycle and isolation boundaries.Knowledge of common container attack paths, including container escape and breakout scenarios.Hands-on knowledge of Kubernetes security telemetry and threats.Experience with Kubernetes audit logging, RBAC abuse patterns, workload identities, admission controls and common security misconfigurations.Practical experience with at least one container runtime detection solution, such as Falco, Sysdig or an equivalent platform.Experience authoring and tuning runtime detection rules.Experience managing detection suppressions, exclusions and rule lifecycles in production environments.Demonstrated ability to design, test, validate, deploy and maintain detection logic through a structured detection lifecycle.Eligibility for a European Security Clearence at EU-LEVEL SECRET