Search by job, company or skills

Detection Engineer L3

Detection Engineer L3

Capgemini
Fresher
Not Disclosed
Early Applicant
  • Posted 18 days ago
  • Be among the first 10 applicants

Job Description

Your role

As a Detection Engineer at Capgemini, you will be responsible for designing, developing, testing, and continuously improving threat detection capabilities across enterprise environments, including cloud, identity, endpoint, email, SaaS, OT, and data platforms. You will leverage Microsoft security technologies, threat intelligence, and threat-informed defense methodologies to build scalable, actionable, and high-fidelity detection content that strengthens the organization's cyber defense posture.

  • Design, develop, tune, and maintain detection use cases, analytics rules, correlation logic, hunting queries, dashboards, watchlists, and behavioral analytics within Microsoft Sentinel, Defender XDR, Azure Data Explorer, and related platforms.
  • Translate threat intelligence, incident findings, attack emulation results, vulnerability insights, cloud/SaaS risks, and business priorities into effective detection requirements and detection engineering roadmaps.
  • Validate detections through attack simulation, synthetic telemetry, threat emulation frameworks, historical data analysis, and operational testing while minimizing false positives through tuning and enrichment.
  • Collaborate with SOC, Data Onboarding, Automation, Cloud, Identity, and Infrastructure teams to ensure telemetry readiness, detection effectiveness, SOAR integration, and successful operational handoff.
  • Maintain detection-as-code practices, CI/CD pipelines, testing frameworks, documentation, MITRE ATT&CK mapping, threat hunting outcomes, and continuous improvement processes for detection lifecycle management.

Your profile

  • Hands-on experience in Microsoft Sentinel, Defender XDR, Azure Data Explorer, and advanced threat hunting across enterprise environments.
  • Expert-level proficiency in Kusto Query Language (KQL) with strong Python and PowerShell scripting skills for detection engineering, automation, and attack simulation.
  • Strong understanding of MITRE ATT&CK, threat-informed defense, detection engineering, SIEM/XDR architectures, correlation logic, entity mapping, and alert enrichment.
  • Experience with detection-as-code, content lifecycle management, CI/CD pipelines, Git, testing automation, Sigma/YAML content development, and security analytics engineering.
  • Deep knowledge of Windows, Linux, Active Directory, Entra ID, Azure, Microsoft 365, cloud security, SaaS platforms, endpoint security, network security, OT/industrial telemetry, threat intelligence, and security data science tools such as Databricks, MSTICPy, and Jupyter notebooks.

Work location : Mumbai / Bengaluru

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

Jupyter notebooks

Defender XDR

Azure Data Explorer

MSTICPy

Microsoft Sentinel

SaaS platforms

Entra ID

OT industrial telemetry

Windows

About Company