Senior Cyber Security Engineer (EDR)

Sanderson Recruitment Plc
London, UK
7 days ago
Apply on www.totaljobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£55,000.0 - £85,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Amazon S3 Microsoft Azure Cyber Security Data Deduplication Data Reduction Intrusion Detection and Prevention Key Management Network Segmentation Zero Trust Network Access Security Information and Event Management Cloud Platform System
+4 more
Facebook Flow Mitre Att&ck Splunk Data Pipelines

Job description

We’re looking for an experienced Senior Security Engineer - Monitoring & Detection to play a key role in securing large-scale, cloud-based environments supporting critical public sector and government services.

This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation. You’ll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify and respond to emerging cyber threats.

Working alongside SOC analysts, engineers, architects, and stakeholders, you’ll help build modern security monitoring capabilities that improve resilience while enabling faster, risk-based decision-making.

What You’ll Be Doing

Detection Engineering & Threat Monitoring

  • Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
  • Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.
  • Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.
  • Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.
  • Validate detections through testing, simulation exercises, and red-team scenarios.

Security Data & Log Engineering

  • Manage and optimise log ingestion pipelines to ensure high-quality, actionable security data.
  • Configure routing, filtering, enrichment, and normalisation of security telemetry.
  • Improve data efficiency through deduplication, data reduction, and flow summarisation techniques.
  • Support cloud-native data streaming and storage solutions.
  • Ensure security data aligns with industry standards such as OCSF while maintaining strong encryption and access controls.

Stakeholder Engagement

  • Translate complex technical risks into clear business-focused recommendations.
  • Collaborate with technical and non-technical stakeholders to improve security outcomes.
  • Act as a trusted technical advisor across engineering and security teams.
  • Mentor junior engineers and contribute to the growth of the wider cyber security function.

Requirements

  • Strong hands-on experience within Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
  • Experience securing cloud environments across AWS, Azure, or GCP.
  • Expertise in one or more of the following:
  • Splunk and SPL
  • YARA rule development
  • EDR detection engineering
  • SIEM content development and tuning
  • Experience mapping detections to the MITRE ATT&CK framework.
  • Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.

Desirable Experience

  • Experience with Cribl and security data pipeline management.
  • Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies.
  • Understanding of OCSF and security data normalisation.
  • Experience working within government, defence, highly regulated industries, or the wider public sector.
  • Experience mentoring or leading engineers within a SOC or cyber security function.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.totaljobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

3:43 min

The enduring legacy of the amazon S3 storage API

Chris Heilmann +3 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:44 min

Automating storage savings with S3 intelligent tiering

Sébastien Stormacq · World Congress 2021

Videos

See all

Related articles

See all