Associate Security Content Engineer
Bitdefender is a cybersecurity leader delivering best-in-class threat prevention, detection, and response solutions worldwide. Guardian over millions of consumer, enterprise, and government environments, Bitdefender is one of the industry’s most trusted experts for eliminating threats, protecting privacy, digital identity and data, and enabling cyber resilience. With deep investments in research and development, Bitdefender Labs discovers hundreds of new threats each minute and validates billions of threat queries daily. The company has pioneered breakthrough innovations in antimalware, IoT security, behavioral analytics, and artificial intelligence and its technology is licensed by more than 180 of the world’s most recognized technology brands. Founded in 2001, Bitdefender has customers in 170+ countries with offices around the world. For more information, visit https://www.bitdefender.com
Security Content Engineer – Managed Detection and Response
Our mission at Bitdefender is to reduce risk to our customers’ businesses so they can confidently pursue their goals. We are committed to delivering real, effective cybersecurity value—no fluff, no gimmicks. To support this mission, we are expanding our team with a Security Content Engineer role.
About Us
Bitdefender’s Managed Detection and Response (MDR) service is a rapidly growing division dedicated to protecting customers from real-world threats. Our team includes passionate cybersecurity professionals from around the globe, including seasoned defenders from military, intelligence, and leading cybersecurity organizations. We operate in a 24/7 environment, managing high-impact security incidents and continuously improving our defenses.
We believe in trust, accountability, and strong processes. Our team prioritizes collaboration and fosters a culture of ownership and problem-solving. If you are passionate about cybersecurity and want to work with others who take the mission seriously, this is the place for you.
About the Role
The Security Content Engineer plays a critical role in proactively identifying and mitigating threats across customer environments by developing and maintaining high-quality detection, investigation, and response content.
This role also supports the automation of SOC operations by designing and maintaining workflows and playbooks that improve triage, investigation, response, and overall analyst efficiency.
This is a full-time position aligned with a four-day, ten-hour schedule within Monday through Friday, with occasional on-call or weekend coverage depending on team needs.
You Will
- Design and develop detection content that drives high-fidelity alerts and investigations.
- Create and refine analytics rules to identify emerging threats and suspicious behavior.
- Design, build, test, document, and maintain SOC automation and response playbooks using n8n.
- Develop automated workflows supporting detection triage, enrichment, investigation, customer verification, response actions, and escalation.
- Work with workflow management and orchestration platforms, such as Temporal and n8n, to support reliable and scalable security operations.
- Integrate security platforms, data sources, APIs, and internal services into automated SOC workflows.
- Maintain and tune customer environment baselines to reduce false positives and improve alert accuracy.
- Conduct quality assessments on operational data to ensure reliability and relevance.
- Develop threat-hunting queries and custom detection content based on threat intelligence.
- Collaborate with MDR analysts to gather feedback and continuously improve detection content, automation, and playbooks.
- Define and maintain data parsers to ensure consistent data normalization and availability.
- Support investigations through ad hoc content development, workflow development, and detection tuning.
- Review and respond to content-related tickets, automation requests, and feature requests.
- Monitor automation performance, troubleshoot workflow failures, and improve playbook reliability.
About You
You are a hands-on engineer with a passion for security, detection engineering, threat hunting, and SOC automation. You enjoy solving difficult operational problems and turning analyst knowledge into repeatable, scalable workflows that improve customer security outcomes.
You Bring
- Hands-on experience developing SOC automation workflows and security playbooks using n8n.
- Experience working with workflow management or orchestration platforms, such as Temporal.
- Experience creating automation for security triage, enrichment, investigation, and response processes.
- Experience integrating security tools and data sources through APIs, webhooks, and other automated methods.
- Experience working with detection and response platforms, such as SIEM, EDR, XDR, or SOAR technologies.
- Strong understanding of threat-detection logic, signal-to-noise tuning, and false-positive reduction.
- Familiarity with common attacker techniques, including the MITRE ATT&CK framework, and corresponding defensive countermeasures.
- Knowledge of log formats and telemetry across multiple operating systems and security technologies.
- Experience designing and implementing parsers for structured and unstructured data.
- Scripting experience supporting security automation, detection engineering, and content development.
- Ability to troubleshoot complex workflows and identify failures across interconnected systems.
- Ability to collaborate across teams and communicate technical information effectively.
Bonus Qualifications
- Experience with Bitdefender GravityZone, Graylog, N8N, or Swimlane.
- Background in SOC operations or security content management within an MDR or MSSP environment.
- Experience developing and refining detection and automation KPIs, such as baseline adherence, false-positive rates, playbook success rates, and analyst time savings.
- Familiarity with software development practices, including version control, testing, peer review, and deployment pipelines.
- Experience translating analyst investigation processes into documented and reusable automated playbooks.
Create a Job Alert
Interested in building your career at Bitdefender? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field
