
Security Engineer - Detection Engineering and Threat Modeling
Hitachi, Ltd.2 months ago
Kraków, PolandMid Level / Senior
Responsibilities
- Design, develop, and tune SIEM detection rules to improve threat visibility and reduce false positives.
- Onboard new log sources by building ingestion pipelines, normalizing data, and integrating sources into the SIEM.
- Perform threat modeling to identify detection requirements and security gaps.
- Build and maintain automation for SOC workflows, reporting, and operational efficiency.
- Collaborate with cybersecurity and engineering teams to improve detection coverage against evolving threats.
- Apply threat intelligence and MITRE ATT&CK to strengthen monitoring and response capabilities.
- Support detection-as-code, CI/CD-driven security operations, and continuous improvement of security monitoring and alert quality.
Requirements
- 2–3 years of experience in detection engineering, security operations, or related cybersecurity engineering roles.
- Experience writing and tuning SIEM detection rules and developing actionable detection content.
- Knowledge of Python, KQL, SQL, or similar technologies used for security monitoring and automation.
- Understanding of endpoint, identity, network, cloud, and infrastructure log sources.
- Familiarity with threat modeling, MITRE ATT&CK, log ingestion pipelines, and security automation practices.
- Experience with Microsoft Sentinel, Defender Suite, Azure, AWS, Docker, or Linux is advantageous.
Benefits
- Private medical care and life insurance.
- Fitness and wellness programs.
- Benefits platform with discounts and perks.
- Employee Capital Plans (PPK).
- Equipment for working from home or allowances for setting up a home workplace.
- Spectacles and contact lens allowance.
- Company events and team-building activities.
- Psychological support program.
- Free parking.
- Full-time, on-site work in Krakow, Poland, under a 12-month maternity-coverage contract.