# MDR - Schuberg Philis

[Schubergphilis](https://gurify.com/jobs?q=Schubergphilis) · Schiphol-Rijk, Netherlands · Posted 3 months ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://job-boards.greenhouse.io/schubergphilis/jobs/7693208003)

## Job description

Shape how threats are detected before they become incidents and protect what truly matters in our customers’ most critical environments.
As an MDR Threat Hunter, you are responsible for proactively identifying, analyzing, and translating emerging threats into actionable detection capabilities within mission-critical environments. You operate on top of a central MDR platform and continuously improve detection coverage by combining deep technical understanding with a strong security mindset. You play a key role in shaping how we detect and respond to threats: not by following predefined playbooks, but by understanding system behaviour, identifying gaps, and designing new detection use cases that matter.

This role bridges security engineering, detection engineering, and threat intelligence. You'll need curiosity, a sense of ownership, and the ability to turn abstract threats into practical detection logic in complex environments.This is a critical role in delivering high-quality, tailored detection and response capabilities for large, complex customer landscapes.

/ What you will do

### Detection engineering & threat hunting

- Develop and continuously improve detection use cases based on emerging threats and observed behaviour.

- Translate threat scenarios and security insights into actionable detection logic.

- Proactively perform threat hunting on the environment to identify abnormal or suspicious patterns.

- Analyse logs and telemetry data to uncover behaviours that are not yet covered by existing detections.

### Use case development & response design

- Define what should happen when detections trigger (response actions, automation, escalation paths).

- Continuously refine detection logic to improve quality, relevance, and signal-to-noise ratio.

- Contribute to building custom detection scenarios tailored to customer environments.

### Threat intelligence & continuous improvement

- Actively follow security developments, vulnerabilities, and threat intelligence and translate these into new hunts and detections.

- Identify gaps in detection coverage and proactively propose improvements.

- Contribute to the evolution of the MDR detection strategy.

### Communication & advisory

- Translate findings into clear, actionable communication for engineers and stakeholders.

- Contribute to security advisories and share relevant threats across the organisation.

- Work closely with engineers to understand system behaviour and validate detection strategies.

### Platform collaboration

- Leverage the central MDR platform to implement detections and analyse data.

- Collaborate with platform/automation engineers to improve integrations and detection capabilities.

/ What you bring

We are looking for someone who combines engineering fundamentals with a strong interest in security and is motivated to move towards or deepen expertise in threat hunting and detection engineering.

### Must have skills:

- Strong automation mindset and ability to translate problems into scalable logic.

- Experience working with logs, telemetry, and detection use cases.

- Solid engineering fundamentals (Linux, networking, infrastructure behaviour).

- Ability to distinguish normal vs. abnormal system behaviour.

- Experience with Python and/or Bash scripting.

- Familiarity with SIEM / log analytics platforms (e.g. OpenSearch, Elastic, Splunk, Sentinel).

- Strong understanding of security principles in detection and response.

- Analytical, curious, and driven to understand how systems and threats behave.

- Ownership mindset with responsibility for detection quality and coverage.

- Strong communication skills to translate findings into actionable insights.

- Ability to connect business context to detection logic.

### Nice to have skills:

- Experience with SOAR / security automation.

- Exposure to threat hunting, detection engineering, or advanced SOC.

- Experience with cloud environments (AWS, Azure or similar).

- Familiarity with CI/CD, Git, or configuration tooling.

/ Who are you?

You are an engineer with a strong interest in security, driven to understand how systems behave and how threats manifest. You don’t follow playbooks blindly, you want to understand why detections exist and how they can be improved.You combine analytical thinking with a hands-on mindset and enjoy working with complex data and environments. You are curious, proactive, and take ownership of the quality of your work. At the same time, you are able to clearly communicate your findings and collaborate effectively with engineers and stakeholders across the organisation.

/ What can you expect?

At Schuberg Philis, you’ll join a community of engineers with an awesome combination of exceptionally high security standards, an infatuation with automation, and the power to make a positive, sustainable impact on customers’ business. Due to the nature of our customer engagements, there is no pressure on (billable) hours; we focus on quality and impact – or how we like to call it: “freedom & responsibility”. You know best how to deliver the most value.

You’ll be embedded in a company committed to helping colleagues grow as people and professionals through training, knowledge sharing, mentoring, and good old-fashioned fun.

Our offices are high quality workspaces, and we go way beyond what is expected. We have productive equipment, good food and drinks, team outings, family days, labs to experiment with innovative technologies, etc. We’re active in relevant tech communities, attending and organizing meetups and conferences, and we organize internal knowledge sharing events where Tech Leads play an important role.

If you’re an engineer in the Netherlands with a strong interest in security and want to proactively hunt threats, design detections, and make real impact in mission-critical environments, we’d love to hear from you.

Everyone we work with and consider working with has a right to equal treatment. The hiring and appraisal process at Schuberg Philis is designed to be thorough and equitable, implementing fair payment, benefits, and opportunities across all demographics.

It is our desire to be a company that brings together multiple nationalities, cultures, religions, genders, abilities, and talents within and across our teams. We welcome colleagues from diverse backgrounds to join Schuberg Philis and actively support diversity and inclusion in the tech industry.

Everyone we work with and consider working with has a right to equal treatment. The hiring and appraisal process at Schuberg Philis is designed to be thorough and equitable, implementing fair payment, benefits, and opportunities across all demographics.

It is our desire to be a company that brings together multiple nationalities, cultures, religions, genders, abilities, and talents within and across our teams. We welcome colleagues from diverse backgrounds to join Schuberg Philis and actively support diversity and inclusion in the tech industry.

**Live in Schubergphilis’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- RE [Lead Physical Security Engineer](https://gurify.com/job/lead-physical-security-engineer-at-reddit-e1db18b35616) Reddit · Amsterdam, Netherlands · 4 weeks ago
- DA [Senior Specialist Solutions Engineer - Platform Security and Cloud ...](https://gurify.com/job/senior-specialist-solutions-engineer-platform-security-and-cloud-at-c1616db887cb) Databricks · Amsterdam, Netherlands · 4 weeks ago
- CN [Customer Success Engineer – AI Security](https://gurify.com/job/customer-success-engineer-ai-security-at-cato-networks-7520a3059408) Cato Networks · Amsterdam, Netherlands · 2 months ago
- FL [Product Security Engineer II](https://gurify.com/job/product-security-engineer-ii-at-flexport-434522279c39) Flexport · Amsterdam, Netherlands · 2 months ago
- AP [Security Engineer](https://gurify.com/job/security-engineer-at-apolloresearch-d96f4fe38ecb) Apolloresearch · London & San Francisco · last week
- SO [Application Security Engineer](https://gurify.com/job/application-security-engineer-at-sonarsource-a1847194c1cb) Sonarsource · Geneva · 6 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"MDR - Schuberg Philis","description":"\u003Cp\u003EShape how threats are detected before they become incidents and protect what truly matters in our customers\u2019 most critical environments.\u003Cbr /\u003EAs an MDR Threat Hunter, you are responsible for proactively identifying, analyzing, and translating emerging threats into actionable detection capabilities within mission-critical environments. You operate on top of a central MDR platform and continuously improve detection coverage by combining deep technical understanding with a strong security mindset. You play a key role in shaping how we detect and respond to threats: not by following predefined playbooks, but by understanding system behaviour, identifying gaps, and designing new detection use cases that matter.\u003C/p\u003E\u003Cp\u003EThis role bridges security engineering, detection engineering, and threat intelligence. You\u0026#39;ll need curiosity, a sense of ownership, and the ability to turn abstract threats into practical detection logic in complex environments.This is a critical role in delivering high-quality, tailored detection and response capabilities for large, complex customer landscapes.\u003C/p\u003E\u003Cp\u003E/ What you will do\u003C/p\u003E\u003Ch3\u003EDetection engineering \u0026amp; threat hunting\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDevelop and continuously improve detection use cases based on emerging threats and observed behaviour.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETranslate threat scenarios and security insights into actionable detection logic.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProactively perform threat hunting on the environment to identify abnormal or suspicious patterns.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnalyse logs and telemetry data to uncover behaviours that are not yet covered by existing detections.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EUse case development \u0026amp; response design\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDefine what should happen when detections trigger (response actions, automation, escalation paths).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContinuously refine detection logic to improve quality, relevance, and signal-to-noise ratio.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to building custom detection scenarios tailored to customer environments.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EThreat intelligence \u0026amp; continuous improvement\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EActively follow security developments, vulnerabilities, and threat intelligence and translate these into new hunts and detections.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EIdentify gaps in detection coverage and proactively propose improvements.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to the evolution of the MDR detection strategy.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ECommunication \u0026amp; advisory\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ETranslate findings into clear, actionable communication for engineers and stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EContribute to security advisories and share relevant threats across the organisation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork closely with engineers to understand system behaviour and validate detection strategies.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EPlatform collaboration\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ELeverage the central MDR platform to implement detections and analyse data.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with platform/automation engineers to improve integrations and detection capabilities.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E/ What you bring\u003C/p\u003E\u003Cp\u003EWe are looking for someone who combines engineering fundamentals with a strong interest in security and is motivated to move towards or deepen expertise in threat hunting and detection engineering.\u003C/p\u003E\u003Ch3\u003EMust have skills:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EStrong automation mindset and ability to translate problems into scalable logic.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working with logs, telemetry, and detection use cases.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ESolid engineering fundamentals (Linux, networking, infrastructure behaviour).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to distinguish normal vs. abnormal system behaviour.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with Python and/or Bash scripting.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with SIEM / log analytics platforms (e.g. OpenSearch, Elastic, Splunk, Sentinel).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong understanding of security principles in detection and response.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnalytical, curious, and driven to understand how systems and threats behave.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EOwnership mindset with responsibility for detection quality and coverage.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong communication skills to translate findings into actionable insights.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to connect business context to detection logic.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENice to have skills:\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience with SOAR / security automation.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExposure to threat hunting, detection engineering, or advanced SOC.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with cloud environments (AWS, Azure or similar).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with CI/CD, Git, or configuration tooling.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003E/ Who are you?\u003C/p\u003E\u003Cp\u003EYou are an engineer with a strong interest in security, driven to understand how systems behave and how threats manifest. You don\u2019t follow playbooks blindly, you want to understand why detections exist and how they can be improved.You combine analytical thinking with a hands-on mindset and enjoy working with complex data and environments. You are curious, proactive, and take ownership of the quality of your work. At the same time, you are able to clearly communicate your findings and collaborate effectively with engineers and stakeholders across the organisation.\u003C/p\u003E\u003Cp\u003E/ What can you expect?\u003C/p\u003E\u003Cp\u003EAt Schuberg Philis, you\u2019ll join a community of engineers with an awesome combination of exceptionally high security standards, an infatuation with automation, and the power to make a positive, sustainable impact on customers\u2019 business. Due to the nature of our customer engagements, there is no pressure on (billable) hours; we focus on quality and impact \u2013 or how we like to call it: \u201Cfreedom \u0026amp; responsibility\u201D. You know best how to deliver the most value.\u003C/p\u003E\u003Cp\u003EYou\u2019ll be embedded in a company committed to helping colleagues grow as people and professionals through training, knowledge sharing, mentoring, and good old-fashioned fun.\u003C/p\u003E\u003Cp\u003EOur offices are high quality workspaces, and we go way beyond what is expected. We have productive equipment, good food and drinks, team outings, family days, labs to experiment with innovative technologies, etc. We\u2019re active in relevant tech communities, attending and organizing meetups and conferences, and we organize internal knowledge sharing events where Tech Leads play an important role.\u003C/p\u003E\u003Cp\u003EIf you\u2019re an engineer in the Netherlands with a strong interest in security and want to proactively hunt threats, design detections, and make real impact in mission-critical environments, we\u2019d love to hear from you.\u003C/p\u003E\u003Cp\u003EEveryone we work with and consider working with has a right to equal treatment. The hiring and appraisal process at Schuberg Philis is designed to be thorough and equitable, implementing fair payment, benefits, and opportunities across all demographics.\u003C/p\u003E\u003Cp\u003EIt is our desire to be a company that brings together multiple nationalities, cultures, religions, genders, abilities, and talents within and across our teams. We welcome colleagues from diverse backgrounds to join Schuberg Philis and actively support diversity and inclusion in the tech industry.\u003C/p\u003E\u003Cp\u003EEveryone we work with and consider working with has a right to equal treatment. The hiring and appraisal process at Schuberg Philis is designed to be thorough and equitable, implementing fair payment, benefits, and opportunities across all demographics.\u003C/p\u003E\u003Cp\u003EIt is our desire to be a company that brings together multiple nationalities, cultures, religions, genders, abilities, and talents within and across our teams. We welcome colleagues from diverse backgrounds to join Schuberg Philis and actively support diversity and inclusion in the tech industry.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"mdr-schuberg-philis-at-schubergphilis-ea8955b95db8"},"url":"https://gurify.com/job/mdr-schuberg-philis-at-schubergphilis-ea8955b95db8","datePosted":"2026-06-08","validThrough":"2026-10-22T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Schubergphilis","sameAs":"https://job-boards.greenhouse.io/schubergphilis"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"NL","addressLocality":"Schiphol-Rijk"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Netherlands","item":"https://gurify.com/jobs/netherlands"},{"@type":"ListItem","position":3,"name":"MDR - Schuberg Philis","item":"https://gurify.com/job/mdr-schuberg-philis-at-schubergphilis-ea8955b95db8"}]}
```
