Senior Detection Engineer (KQL / Microsoft Sentinel & Defender XDR)

Publiceringsdatum: 2026-08-17

Är du på jakt efter en karriär inom data/it? Positionen som it-säkerhetschef hos ACADEMIC WORK SWEDEN AB är öppen och väntar på en lämplig kandidat - kan det vara du? ACADEMIC WORK SWEDEN AB söker efter en ny anställd på heltid under 6 månader eller längre som är redo att ta sin karriär till nästa nivå.

Platsen där jobbet finns ledigt är i Malmö. Företaget ACADEMIC WORK SWEDEN AB erbjuder just nu spännande karriärmöjligheter. Om du vill jobba som it-säkerhetschef har de nu ett ledigt jobb - kolla in annonsen för att se om du har rätt erfarenhet. Bli en del av teamet hos ACADEMIC WORK SWEDEN AB som it-säkerhetschef genom att ansöka senast lördag den trettonde februari 2027.


Jobbannons

Ready to lead a global detection migration? ASSA ABLOY in Malmö is looking for a Senior Detection Engineer to lead the transition of threat detection logic from Splunk and SentinelOne over to Microsoft Defender XDR & Sentinel.

About the role

This is a full-time consultancy assignment (40h/week) based in Malmö on a hybrid schedule, running initially through the end of the year with a strong potential for extension.

As a Detection Engineer, you will play a key role in consolidating and modernizing ASSA ABLOY’s global threat detection capability. You will evaluate existing rules in Splunk and SentinelOne, translate and optimize search queries into KQL, and build tailored detections in Microsoft Defender XDR and Microsoft Sentinel. The objective is to achieve high-fidelity threat detection with minimal false positives, accompanied by thorough documentation for the SOC team.

Work tasks

The role focuses on transforming and optimizing security detection rules from legacy systems into a modern Microsoft SIEM/XDR environment to ensure a threat-informed defense.

  • Logic Conversion & Optimization: Evaluate existing detection logic in Splunk (SPL) and SentinelOne, and re-engineer queries into efficient KQL rules.
  • Gap Analysis & MITRE Mapping: Identify detection gaps, eliminate redundant alerts, and align detections with the MITRE ATT&CK framework.
  • Tuning & Validation: Test and fine-tune detection rules within Microsoft Defender XDR and Sentinel to reduce noise.
  • Documentation & Enablement: Collaborate closely with SOC analysts, threat hunters, and platform engineers, creating clear standard operating procedures.

We are looking for

  • At least 5 years of experience within Cyber Security, SOC, Threat Hunting, or Detection Engineering.
  • Strong hands-on experience in KQL (Kusto Query Language) and custom detection creation.
  • In-depth practical knowledge of Microsoft Defender XDR and Microsoft Sentinel.
  • Demonstrated experience with Splunk (SPL) and/or SentinelOne to evaluate and migrate existing logic.
  • Fluency in English, both written and spoken (corporate language).

It is meritorious if you have

  • Relevant certifications such as Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Security Operations Analyst Associate (SC-200).

  • Experience with automated response workflows (SOAR / Logic Apps) and integrations in large-scale enterprise environments.

  • Proficiency in Swedish

To succeed in the role, your personal skills are

  • Change oriented
  • Supportive
  • Orderly
  • Responsible
  • Intellectually curious

Our recruitment process

This recruitment process is handled by Academic Work and it is our client’s wish that all questions regarding the position is directed to Academic Work.

Our selection process is continuous and the advert may close before the recruitment process is completed if we have moved forward to the next phase. The process includes two tests: one personality test and one cognitive test. The tests are tools to find the right talent for the right position, to enable equality, diversity, and a fair process.

Om jobbet

Antal tjänster1
ArbetstidHeltid
FöretagsnamnACADEMIC WORK SWEDEN AB
LönFast månads- vecko- eller timlön
Omfattning6 månader eller längre
Organisationsnummer5565595450
Typ av anställningVanlig anställning
YrkeIT-säkerhetschef
YrkesområdeData/IT

Ansökan

ACADEMIC WORK SWEDEN AB söker en person till denna tjänst som it-säkerhetschef med placerings i Malmö. Om det låter intressant att arbeta som it-säkerhetschef hos ACADEMIC WORK SWEDEN AB skickar du in din ansökan senast 2027-02-13.

Källa: Arbetsförmedlingen

Till webb­ansökan »