Overview
Join to apply for the Cyber Security Detection Engineer role at Wurth IT Malaysia Sdn. Bhd. .
Würth IT is the global IT service provider of the Würth Group, supporting security operations globally. Our Cyber Defense Center combines Security Operations, Threat Intelligence, and Research & Development to protect the organization on a global scale. We are expanding the Research & Development team to Malaysia to design and improve detection methods, automate responses, and enhance defensive capabilities.
About the Role
As a Cyber Security Detection Engineer, you will help develop, optimize, and maintain detection and response mechanisms that enable the Cyber Defense Center to identify and counter threats early. You will collaborate with SOC operations and global R&D colleagues to ensure Würth Group systems and networks remain resilient against evolving cyber threats.
Responsibilities
- Detection Engineering
- Design and maintain detection rules across SIEM and XDR platforms to identify suspicious activity and advanced attack patterns.
- Develop use cases and playbooks that standardize detection coverage and enable fast, repeatable incident response.
- Build and tune SOAR automation workflows to reduce manual effort, improve alert enrichment, and accelerate containment.
- Perform quality assurance and continuous tuning of detection logic to ensure accuracy and reduce false positives.
- Guarantee the integration and normalization of log sources so detections are reliable and based on high-quality data.
- Threat Hunting & Monitoring
- Support SOC Operations with analysis of security incidents, identifying improvements to existing detection coverage.
- Conduct hypothesis-driven threat hunting to proactively uncover hidden threats and anomalies that bypass automated rules.
- Use advanced analytics and intelligence feeds to close detection blind spots and strengthen resilience against evolving attacks.
- Collaborate with SOC during incidents, providing in-depth investigations into scope, root cause, and impact.
- Perform forensic analysis of compromised systems, logs, and binaries to reconstruct attacker activity.
- Reverse engineer malware and tools to understand adversary behavior, identify vulnerabilities, and develop countermeasures.
- Evaluate new detection technologies, frameworks, and methods for integration into the Cyber Defense Center.
- Partner with global R&D colleagues to advance detection engineering practices, contributing to long-term security architecture.
- Share insights and improvements back into the SOC playbooks, ensuring knowledge gained becomes part of standard operations.
Qualifications
Education / Experience
Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.3–5 years of relevant experience in cybersecurity, ideally with a focus on detection engineering or SOC work.Technical Expertise
Strong knowledge of SIEM systems (e.g., Microsoft Sentinel, Splunk, Elastic) with hands-on experience in rule development and optimization.Experience with SOAR platforms and building automation workflows to streamline incident response.Proficiency in scripting languages (Python preferred; PowerShell or Bash useful) for automation, enrichment, and detection logic.Experience with version control systems (e.g., Git / GitHub) to manage detection rules and playbooks.Background in threat hunting methodologies and hypothesis-driven analysis, with ability to identify blind spots in coverage.Understanding of log normalization, data quality, and event source integration to ensure reliable detections.Knowledge of malware analysis, reverse engineering, and forensic methods to investigate incidents in depth.Familiarity with the MITRE ATT&CK framework and ability to apply it when designing and evaluating detection coverage.Excellent English communication skills (spoken and written) to collaborate effectively in an international team. Additional language skills (e.g., German) are an advantage.Collaborative and open-minded, able to thrive in a global, cross-functional environment.Flexible to occasionally align with colleagues in other time zones when needed, while working primarily within standard Malaysian office hours.Analytical and structured problem-solving approach with a proactive attitude.Why Join Us?
Work globally with colleagues across multiple regions and time zones.Make impact by shaping detection strategies that protect the Würth Group worldwide.Grow continuously through advanced tools, learning, and R&D projects.Count on stability with a strong, long-term focused global IT organization.#J-18808-Ljbffr