
Senior Detection Engineer
Senior Detection Engineer
Be the true you
Join us in protecting the Netherlands' critical infrastructure from cyber attacks. Work within the Netherlands' leading Security Operations Centers (SOCs). We leverage the latest technologies to structurally strengthen the cyber resilience of vital organizations. At Deloitte.
Benefits
- You’ll receive a profit-sharing bonus. On top of your fixed salary.
- Continuous professional growth. Join our development program.
- A work-from-home office setup allowance to make sure you have everything you need for an ergonomically designed workstation and internet allowance.
- Work part-time (32 hours a week) or full-time (40 hours a week).
- Flexible working hours, you are in charge of your own calendar.
- 26 days of paid annual leave, and the opportunity to purchase additional leave.
- The option to exchange three national holidays for three non-national holidays.
- A good mobility scheme: the choice of various options such as a lease car, travel by public transport, a cash option or a combination of these.
- A laptop and iPhone. The iPhone can be for personal use.
- A good pension scheme with a personal contribution of only 2%. For a comfortable future.
- An opportunity to take part in our collective health insurance scheme.
- An opportunity to benefit from tax-efficient facilities such as fitness, a bicycle scheme or the opportunity to lease a bicycle.
- The opportunity to use 55 hours of babysitting service per calendar year, if your child is 12 years old or younger.
- An opportunity to benefit from tax-efficient facilities, such as company fitness and a bicycle scheme.
- A flexible budget, which you can use to make choices in flexible benefits, for example: purchasing extra leave days or financing a bicycle plan.
- Six weeks of fully paid birth leave for traditional households and rainbow families.
Be the true you
- 3–6 years of hands-on experience in detection engineering, threat hunting, or incident response.
- At least three years of experience with at least one of: Elastic (SIEM/EDR), Suricata, Zeek.
- Demonstrable experience writing, tuning and validating detection logic in at least two of: Sigma, YARA‑L, ESQL.
- Strong understanding of detection deployment across the Detection Engineering Spectrum.
- Experience with telemetry sources and threat modelling.
- Comfortable working in a fast‑paced environment where threat‑driven detection and rapid iteration are the norm.
- Strong familiarity with MITRE ATT&CK and detection mapping of adversarial techniques.
What impact will you make?
As a Senior Detection Engineer you develop and implement advanced detection rules and monitoring solutions to quickly and effectively identify cyber threats. You build monitoring capabilities for network traffic, security logs, EDR/NDR data and OT environments. You also translate threat intelligence and Red Team reports into innovative detection options and coach your colleagues to promote knowledge sharing and stimulate innovation.
Do you want to play a key role in protecting the Netherlands? Apply as a Senior Detection Engineer and join us in our cutting‑edge, intelligence‑driven SOCs that are leading the way in automation and innovation. Your work will have a direct impact on the digital security of vital organisations.
For this position, candidates must be an EU resident and fluent in Dutch. We do not offer relocation packages for this position.

Together makes progress
Connect your future to Deloitte
How do you do this?
- Own the delivery of high‑quality detection content.
- Guide the Detection Engineering team on prioritisation, coverage and detection choke‑points.
- Partner with CTI and Red Teams and guide the process of converting regular assessments into refined detection strategies.
- Play a key role in shaping a comprehensive threat detection strategy aligned with business objectives and industry best practice.
- Mentor and support junior to medior detection engineers.
- Contribute to threat modelling efforts to identify high‑value detection opportunities and coverage gaps.
- Analyse telemetry sources (e.g. Windows Event Logs, Sysmon, cloud logs, network traffic) to identify detection use cases and ensure telemetry readiness.

We would like to meet you!
Our application process
Select one of the steps for more information
Step 1: Preparation
Step 2: CV and motivation
Step 3: The assessment
Step 4: The interview
Step 5: The offer
Questions or doubts? Get in touch.




