Senior Cyber Security Engineer (EDR)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
& Threat MonitoringDevelop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms. Create and optimise detection logic using technologies such as Splunk and endpoint security solutions. Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage. Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness. Validate detections through testing, simulation exercises, and red-team scenarios.Security Data & Log EngineeringManage and optimise log ingestion pipelines to ensure high-quality, actionable security data. Configure routing, filtering, enrichment, and normalisation of security telemetry. Improve data efficiency through deduplication, data reduction, and flow summarisation techniques. Support cloud-native data streaming and storage solutions. Ensure security data aligns with industry standards such as OCSF while maintaining strong encryption and access controls.Stakeholder
Requirements
EngagementTranslate complex technical risks into clear business-focused recommendations. Collaborate with technical and non-technical stakeholders to improve security outcomes. Act as a trusted technical advisor across engineering and security teams. Mentor junior engineers and contribute to the growth of the wider cyber security function.What We’re Looking For Essential ExperienceStrong hands-on experience within Security Operations, Detection Engineering, Threat Detection, or Security Monitoring. Experience securing cloud environments across AWS, Azure, or GCP. Expertise in one or more of the following: Splunk and SPL YARA rule development EDR detection engineering SIEM content development and tuning Experience mapping detections to the MITRE ATT&CK framework. Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.Desirable ExperienceExperience with Cribl and security data pipeline management. Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies. Understanding of OCSF and security data normalisation. Experience working within government, defence, highly regulated industries, or the wider public sector. Experience mentoring or leading engineers within a SOC or cyber security function.Reasonable Adjustments:Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.If you need any help or adjustments during the recruitment process for any reason, please let us know when you apply or talk to the recruiters directly so we can support you.JBRP1_UKTJ
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Data Engineer Salary UK
Where To Find Software Engineering Jobs
9 Ways to Make Money Hacking
Is Software Engineering Over-Saturated?