RemoteJobs.org mascotRemoteJobs.org
Remote JobsCompaniesAPISign inPost a Job
RemoteJobs.org mascotRemoteJobs.org

Find your dream remote job. Browse thousands of remote positions from top companies worldwide.

Job Categories

  • General
  • Programming
  • Design
  • Marketing
  • Sales
  • Customer Support

Resources

  • Browse Jobs
  • Companies
  • Post a Job
  • For Developers
  • Blog

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service
© 2026 RemoteJobs.org. All rights reserved.
    ← Back to all jobs
    SOFTSWISS

    SOC Detection Engineer – Senior

    SOFTSWISS
    Full-time
    Verified Remote
    WorldWideCyber SecurityToday

    About this role

    SOC Detection Engineer – Senior

    Position Type: Full time Location: WorldWide Posted: September 16, 2026

    Overview

    SOFTSWISS is hiring a Senior SOC Detection Engineer to join our Security Operations team. We are seeking a hands-on security professional to help build and develop our detection engineering function, strengthening the company's ability to identify, investigate, and respond to security threats across Windows, Linux, and Kubernetes environments.

    Purpose of the Role

    You will be responsible for owning the full lifecycle of security detections, from researching attack techniques and defining logging requirements to developing, testing, deploying, and continuously improving detection content in Splunk. Your work will help enhance detection coverage, improve telemetry quality, reduce false positives, and ensure that security teams can reliably identify and respond to real threats.

    Key Responsibilities

    • Develop, test, deploy, and maintain detection and correlation rules in Splunk or a similar SIEM.

    • Translate incident investigations, threat hunting, and attack research into effective detections.

    • Analyze false positives, false negatives, and detection gaps.

    • Improve detection coverage and map detections to MITRE ATT&CK techniques.

    • Develop and optimize SPL queries, dashboards, reports, and risk-based detections.

    • Define requirements for logging, parsing, normalization, enrichment, and data quality.

    • Develop monitoring and health checks for detection rules and data sources.

    • Contribute to automated detection testing, synthetic events, telemetry replay, and CI/CD workflows.

    • Participate in incident investigations, threat hunting, purple team exercises, and attack emulation.

    • Collaborate with SOC, Incident Response, Threat Intelligence, Infrastructure, and Engineering teams.

    • Document detection logic, data sources, dependencies, limitations, and expected behavior.

    Required Experience

    • Strong hands-on experience in SOC, Detection Engineering, Threat Hunting, Incident Response, or a related field.

    • Deep understanding of MITRE ATT&CK, common attack techniques, and detection methodologies.

    • Strong proficiency in Splunk SPL or another enterprise SIEM platform.

    • Experience developing complex queries, correlations, dashboards, and reports.

    • Practical experience tuning detections and managing exceptions and allowlists.

    • Ability to define and evaluate logging and telemetry requirements.

    • Proficiency in Python, PowerShell, or Bash for automation.

    • Experience with Git, code reviews, APIs, and basic CI/CD practices.

    • Understanding of Windows and Linux security monitoring.

    • Ability to independently investigate complex problems and drive solutions to completion.

    • Strong communication skills and the ability to work effectively across teams.

    Nice to Have

    • Experience with Splunk Enterprise Security, CIM, data models, macros, and lookups.

    • Experience with Sysmon, Windows security auditing, Active Directory, auditd, osquery, Tetragon, Docker, or Kubernetes.

    • Experience with YARA, CALDERA, Shuffle, or other security automation and attack emulation tools.

    • Experience building detection quality metrics and automated validation frameworks.

    • Experience with Terraform, Ansible, or other infrastructure-as-code tools.

    • Participation in security research, conferences, or the broader security community.

    Our Technology Focus

    Splunk Enterprise Security, MITRE ATT&CK, Windows and Linux telemetry, Kubernetes and container logs, Python, PowerShell, Bash, Git, and CI/CD.

    Main Advantages

    • Private health insurance

    • Sports benefits

    • Comprehensive Mental Health Program

    • Free English lessons (online)

    • Local language courses

    • Paid time off

    • Maternity leave support

    • Referral program rewards

    • Upskilling, internal workshops, and participation in professional conferences and corporate events

    About SOFTSWISS

    SOFTSWISS
    SOFTSWISS

    SOFTSWISS is an iGaming technology company that develops a secure, state-of-the-art Casino Platform designed to serve clients worldwide. The company has built a strong technical team that creates robust iGaming solutions with a focus on innovation and competitive edge through advanced technology. SOFTSWISS provides an unparalleled experience to clients through its platform, which ensures the highest quality of service and maintains constant innovation in the iGaming sector. The company operates with a distributed, international team and is actively expanding across multiple functional areas including project management, corporate initiatives, and infrastructure engineering.

    Hiring remote talent?

    Reach active remote job seekers from $149.

    Related Jobs

    Cybersecurity Engineer- Junior level

    CACI International Inc · USD 63,300 - 129,700

    Senior Security Engineer - Blue Team

    Olo

    Cybersecurity Specialist - 100% Remote

    BlockTXM Inc