Senior Detection Engineer (KQL / Microsoft Sentinel & Defender XDR)

ACADEMIC WORK SWEDEN AB Malmö, Skåne län, Sverige Publicerat 17 augusti 2026
full_timehybridsenior
Ready to lead a global detection migration? ASSA ABLOY in Malmö is looking for a Senior Detection Engineer to lead the transition of threat detection logic from Splunk and SentinelOne over to Microsoft Defender XDR & Sentinel. About the role This is a full-time consultancy assignment (40h/week) based in Malmö on a hybrid schedule, running initially through the end of the year with a strong potential for extension. As a Detection Engineer, you will play a key role in consolidating and modernizing ASSA ABLOY’s global threat detection capability. You will evaluate existing rules in Splunk and SentinelOne, translate and optimize search queries into KQL, and build tailored detections in Microsoft Defender XDR and Microsoft Sentinel. The objective is to achieve high-fidelity threat detection with minimal false positives, accompanied by thorough documentation for the SOC team. Work tasks The role focuses on transforming and optimizing security detection rules from legacy systems into a modern Microsoft SIEM/XDR environment to ensure a threat-informed defense. Logic Conversion & Optimization: Evaluate existing detection logic in Splunk (SPL) and SentinelOne, and re-engineer queries into efficient KQL rules. Gap Analysis & MITRE Mapping: Identify detection gaps, eliminate redundant alerts, and align detections with the MITRE ATT&CK framework. Tuning & Validation: Test and fine-tune detection rules within Microsoft Defender XDR and Sentinel to reduce noise. Documentation & Enablement: Collaborate closely with SOC analysts, threat hunters, and platform engineers, creating clear standard operating procedures. We are looking for At least 5 years of experience within Cyber Security, SOC, Threat Hunting, or Detection Engineering. Strong hands-on experience in KQL (Kusto Query Language) and custom detection creation. In-depth practical knowledge of Microsoft Defender XDR and Microsoft Sentinel. Demonstrated experience with Splunk (SPL) and/or SentinelOne to evaluate and migrate existing logic. Fluency in English, both written and spoken (corporate language). It is meritorious if you have Relevant certifications such as Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Security Operations Analyst Associate (SC-200). Experience with automated response workflows (SOAR / Logic Apps) and integrations in large-scale enterprise environments. Proficiency in Swedish To succeed in the role, your personal skills are: Change oriented Supportive Orderly Responsible Intellectually curious Our recruitment process This recruitment process is handled by Academic Work and it is our client’s wish that all questions regarding the position is directed to Academic Work. Our selection process is continuous and the advert may close before the recruitment process is completed if we have moved forward to the next phase. The process includes two tests: one personality test and one cognitive test. The tests are tools to find the right talent for the right position, to enable equality, diversity, and a fair process.

Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.

Visa jobbet och ansök

Ursprunglig annons: arbetsformedlingen.se