Detection Engineer
Capgemini
Capgemini
Empower your career at Capgemini, a global leader in business and technology transformation. Join a collaborative community and help world-leading organizations unlock technology's potential to build a more sustainable and inclusive future. We are seeking a skilled Detection Engineer to join our dynamic team.
This role offers a unique opportunity to work on mission-critical projects for Fortune 500 clients, ensuring security, compliance, and operational efficiency. You'll be part of an AI-powered organization with a strong heritage, delivering end-to-end solutions and driving tangible business value.
Design, develop, and refine detection use cases using Microsoft KQL to proactively identify and respond to cyber threats. Enhance detection coverage and validate effectiveness by leveraging Cyber Threat Intelligence (CTI) and the MITRE ATT&CK framework, while also pinpointing security gaps.
Conduct in-depth threat hunting and incident investigations across Windows, Linux, Azure, and Microsoft 365 environments. Develop SOAR playbooks, automation workflows, dashboards, and reports to boost SOC operational efficiency and response capabilities.
Perform threat emulation and detection validation using tools like Atomic Red Team and Caldera to continuously assess and strengthen the organization's security posture.
A minimum of 4 years of experience in detection engineering is essential, with a proven track record in developing and tuning detection use cases using Microsoft KQL within enterprise environments. A strong foundation in cybersecurity domains, including threat intelligence, incident response, endpoint security, cloud security, identity management, and vulnerability management, is required.
Demonstrated hands-on experience in investigating security incidents, conducting threat hunting, and mapping detections to the MITRE ATT&CK framework to identify and address security gaps. Proficiency in Microsoft Sentinel, Azure, Microsoft 365 Security, and the Defender suite is necessary. Experience with security automation using PowerShell and Python, creating analysis playbooks, performing malware analysis, and leveraging tools such as Atomic Red Team, Caldera, and AttackIQ is also expected.
Capgemini
IT Services and IT Consulting