Login Enter

Nomios Poland Sp. z o.o.

2 months ago

Detection & Quality Lead

Sign up free Log in

Sign up to save this job, get alerts, and apply with an optimized CV.

Company information

Company
Nomios Poland Sp. z o.o.
Location
Polska, mazowieckie, Warszawa Poland
Posted
2 months ago
View all jobs at Nomios Poland Sp. z o.o.

Job description

About this role The Detection & Quality Lead is a new role within the Build team, created as part of the SOC operational model transformation. This position is responsible for the technical quality of the entire Detection & Response team. The position is performed during standard business hours (9-to-5) within the Build team. The main area of responsibility is to ensure the highest level of work of the Detection & Response team: timeliness and effectiveness of detection rules, precision of reports, and translation of research results into real operational improvements. The role involves close cooperation with individuals in Principal positions (forensics, intelligence, threat hunting), and the Service Delivery Manager (client context, delivery). Together, they form the core of the new SOC model. Scope of Responsibility • Quality review - cyclical incident review on a monthly basis, trend analysis, identification of gaps in detection and processes. • Detection engineering - review and development of detection rules, correlations, and alerts in SIEM/EDR; maintenance of a feedback loop with the DRT team regarding alert quality and false positive rate. • Reporting - coordination of monthly security reports for clients, ensuring data consistency and precision. • Research → Action - translating research results (quarterly and ad hoc) into concrete changes in detection, playbooks, and operational processes. • Training and research program - oversight of the analysts' quarterly research program and its translation into ATT&CK coverage, new detections, and expert content (blogs, webinars). What we expect from you • 4+ years of experience in SOC / Blue Team / Detection Engineering / IR. • Technical background - knowledge of SIEM (correlation rules, parsers, log management), EDR/XDR (CrowdStrike Falcon is a plus), SOAR (playbooks, integrations). • MITRE ATT&CK in practice - ability to map detection coverage to the framework, identify gaps, and plan development. • Analytical thinking - ability to identify errors in reports, inconsistencies in detections, and gaps in processes. • Communication and collaboration - ability to provide constructive feedback to shift analysts and effective collaboration with teams and clients. • Scripting - Python, PowerShell, or Bash at a level sufficient to build tools supporting quality review and detection automation. Nice to have • Experience in building a detection engineering program from scratch or its significant development. • Working with CrowdStrike Falcon (NG-SIEM, XDR, custom IOA). • Experience in creating security reports for MSSP/MDR clients. • Conducting training sessions, webinars, technical publications. • Certifications: GCIH, GCFA, OSCP, CCD, CCFH, SC-200/SC-100. What we offer • Standard business hours. • Opportunity to co-define a completely new role in the organization - real influence on the SOC operational model. • Modern stack: SIEM, XDR (CrowdStrike Falcon), SOAR, forensic and network tools. • Training, certification, and conference budget + learning platforms. • Close cooperation with Principal and SDM - you are part of the SOC leadership core.

Required skills

Interested in this position?

Create your free account and tailor your CV to match this job.