SOFTSWISS
SOC Detection Engineer – Senior
About this role
# SOC Detection Engineer – Senior **Position Type:** Full time **Location:** WorldWide **Posted:** September 16, 2026 ## Overview SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company's ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments. ## Purpose of the Role You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats. ## Key Responsibilities
- Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.
- Translate incident investigations, threat hunting, and attack research into effective detections.
- Analyze false positives, false negatives, and detection gaps.
- Improve detection coverage and map detections to MITRE ATT&CK techniques.
- Develop and optimize SPL queries, dashboards, reports, and risk-based detections.
- Define requirements for logging, parsing, normalization, enrichment, and data quality.
- Develop monitoring and health checks for detection rules and data sources.
- Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.
- Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.
- Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.
- Document detection logic, data sources, dependencies, limitations, and expected behavior. ## Required Experience
- Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.
- Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.
- Strong proficiency in Splunk SPL or another enterprise SIEM platform.
- Experience developing complex queries, correlations, dashboards, and reports.
- Practical experience tuning detections and managing exceptions and allowlists.