Utforska
Externt jobbKälla: Arbetsförmedlingen

Ledig tjänst

Arbetsförmedlingen

SverigePublicerad: Uppdateras löpandeJobb-ID: 31361468

Läs jobbet på Marketplace

Den här rollen kommer från Arbetsförmedlingen. Vi visar den här först på Marketplace så att kandidaten kan läsa vidare, jämföra liknande roller och fortsätta till ansökan när det passar.

Rollöversikt

Matchad från extern källa med fokus på ledig tjänst i Sverige. Nästa steg är att öppna ansökan hos Arbetsförmedlingeneller fortsätta jämföra liknande jobb direkt här på Marketplace.

Villkor och krav
Anställningsform: Vanlig anställningArbetstid: HeltidOmfattning: 100-100%Lön: Lön enligt överenskommelseLönetyp: Fast månads- vecko- eller timlönSista ansökan: 13 februari 2027Erfarenhet: Krävs
Ansökan och signaler
Referens: 3P0HE5
Språk som krävs
Engelska NVxJ_hLg_TYS 283
Meriterande språk
Svenska zSLA_vw2_FXN 502
Full rollbeskrivning

Ready to lead a global detection migration? ASSA ABLOY in Malmö is looking for a Senior Detection Engineer to lead the transition of threat detection logic from Splunk and SentinelOne over to Microsoft Defender XDR & Sentinel.

About the role

This is a full-time consultancy assignment (40h/week) based in Malmö on a hybrid schedule, running initially through the end of the year with a strong potential for extension.

As a Detection Engineer, you will play a key role in consolidating and modernizing ASSA ABLOY’s global threat detection capability. You will evaluate existing rules in Splunk and SentinelOne, translate and optimize search queries into KQL, and build tailored detections in Microsoft Defender XDR and Microsoft Sentinel. The objective is to achieve high-fidelity threat detection with minimal false positives, accompanied by thorough documentation for the SOC team.

Work tasks

The role focuses on transforming and optimizing security detection rules from legacy systems into a modern Microsoft SIEM/XDR environment to ensure a threat-informed defense.

  • Logic Conversion & Optimization: Evaluate existing detection logic in Splunk (SPL) and SentinelOne, and re-engineer queries into efficient KQL rules.
  • Gap Analysis & MITRE Mapping: Identify detection gaps, eliminate redundant alerts, and align detections with the MITRE ATT&CK framework.
  • Tuning & Validation: Test and fine-tune detection rules within Microsoft Defender XDR and Sentinel to reduce noise.
  • Documentation & Enablement: Collaborate closely with SOC analysts, threat hunters, and platform engineers, creating clear standard operating procedures.

We are looking for

  • At least 5 years of experience within Cyber Security, SOC, Threat Hunting, or Detection Engineering.
  • Strong hands-on experience in KQL (Kusto Query Language) and custom detection creation.
  • In-depth practical knowledge of Microsoft Defender XDR and Microsoft Sentinel.
  • Demonstrated experience with Splunk (SPL) and/or SentinelOne to evaluate and migrate existing logic.
  • Fluency in English, both written and spoken (corporate language).

It is meritorious if you have

  • Relevant certifications such as Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Security Operations Analyst Associate (SC-200).

  • Experience with automated response workflows (SOAR / Logic Apps) and integrations in large-scale enterprise environments.

  • Proficiency in Swedish

To succeed in the role, your personal skills are:

  • Change oriented
  • Supportive
  • Orderly
  • Responsible
  • Intellectually curious

Our recruitment process

This recruitment process is handled by Academic Work and it is our client’s wish that all questions regarding the position is directed to Academic Work.

Our selection process is continuous and the advert may close before the recruitment process is completed if we have moved forward to the next phase. The process includes two tests: one personality test and one cognitive test. The tests are tools to find the right talent for the right position, to enable equality, diversity, and a fair process.