Job Search and Career Advice Platform

Enable job alerts via email!

Detection Engineer

SiXworks

Farnborough

On-site

GBP 80,000 - 100,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading provider of secure digital solutions is seeking a Detection Engineer in Farnborough. The role involves designing and optimizing detection logic, monitoring security alerts, and conducting threat hunts. Candidates should have strong experience with SIEM tools and relevant technical qualifications in Cyber Security. The position offers a variety of benefits including private medical insurance, flexible working, and professional development opportunities, making it a great opportunity for those passionate about digital security.

Benefits

25 days annual leave + bank holidays
Private Medical Insurance
Life Assurance Scheme
Pension scheme
Professional Development opportunities
Cycle to Work scheme
Perks at Work scheme
Discretionary Bonus scheme

Qualifications

  • Relevant qualification(s) in Cyber Security or other related technical roles.
  • Experience in incident detection, triage, and analysis in SOC or related environments.
  • Solid understanding of MITRE ATT&CK framework.

Responsibilities

  • Design, implement, and optimise detection logic in SIEM.
  • Monitor, analyse, and investigate security alerts.
  • Conduct threat hunting activities.

Skills

Strong experience with SIEM tools
Hands-on knowledge of EDR solutions
Proficiency in detection rule development
Understanding of malware techniques
Familiarity with scripting/programming

Education

Degree in Cyber Security or related fields
Professional Qualifications (e.g., CompTIA, ISACA)

Tools

Elastic Security
Sentinel
Splunk
Job description
About the job

We currently have an exciting opportunity for a Detection Engineer to join our existing experienced team.

Tasks / Responsibilities
  • Design, implement, and optimise detection logic, rules, and use cases in SIEM, EDR, and related platforms.
  • Tune existing alerts and rules to reduce false positives and enhance detection fidelity.
  • Monitor, analyse, and investigate security alerts to identify potential threats and malicious activity.
  • Conduct threat hunting activities to proactively discover hidden or advanced threats.
  • Collaborate with Incident Response teams to provide detection insights and support investigations.
  • Maintain and improve detection coverage based on emerging threats, adversary tactics (MITRE ATT&CK), and threat intelligence.
  • Develop automation scripts and playbooks to streamline detection and alert triage processes.
  • Document detection processes, use cases, and provide knowledge transfer to SOC analysts.
Qualifications
  • Relevant qualification(s) in Cyber Security, or other related technical roles
  • Examples:
    • Degree in Cyber Security, Computer Science, Networks etc.
    • Professional Qualifications from organisations such as CompTIA, ISACA etc.
    • Technical qualifications in security and technology such as (but not limited to) cloud computing, SIEM, Vulnerability Scanning/Management etc.
Experience (essential)
  • Strong experience with Security Information and Event Management (SIEM) tools, in order of preference:
  • Elastic Security (Mandatory)
  • Sentinel (Optional)
  • Splunk (Optional)
  • Hands‑on knowledge of Endpoint Detection & Response (EDR) solutions (e.g., Elastic XDR, Microsoft Defender, CrowdStrike, Carbon Black, SentinelOne).
  • Practical understanding of log sources across network, endpoint, cloud, and identity platforms.
  • Solid knowledge of MITRE ATT&CK framework and application in detection engineering.
  • Proficiency in detection rule development using query languages (e.g., ESQL, KQL, Lucene).
  • Experience in incident detection, triage, and analysis in SOC or related environments.
  • Understanding of malware techniques, lateral movement, persistence mechanisms, and threat actor TTPs.
Experience (nice to have)
  • Exposure to cloud security monitoring (AWS, Azure, GCP logging and detections).
  • Knowledge of SOAR platforms and automation playbook creation.
  • Experience with YARA, Sigma, or Snort/Suricata rule writing.
  • Familiarity with container and Kubernetes security monitoring.
  • Threat intelligence analysis and integrating threat intel into detection workflows.
  • Knowledge of offensive security/red teaming methodologies to improve detection coverage.
  • Familiarity with scripting/programming (Python, PowerShell, or similar) for automation and detection enrichment.
About SiXworks

SiXworks is a leading provider of secure digital solutions, specialising in digital experimentation and focused on fail‑safe‑fast cutting‑edge technology solutions deployed in highly secure environments. We are unified in our mission to accelerate innovation and adoption of secure, digital technology to improve the operational agility of Defence and National Security. This is an exciting time for us, we have ambitious plans for continued growth and development, and we are seeking to add brilliant, experienced, motivated, and passionate people to our team to work with us on this journey.

Why join SiXworks?

Our team is a fusion of brilliance, featuring senior operational, technical, and business leaders from various industries and the armed forces. We're also powered by a league of extraordinary IT engineers, architects, developers, and project managers. Together, we're an unstoppable force of digital innovation!

What can we offer in return?

SiXworks offers a unique work culture around our core principles Agility, Security, Innovation, Quality, Collaboration and Inclusivity. Together, these six principles form SiXworks'NORTH STAR, guiding the organisation towards success. This is reflected in the raft of benefits available to all our employees.

Benefits
  • 25 days annual leave + bank holidays
  • Private Medical Insurance
  • Life Assurance Scheme
  • Pension scheme
  • Professional Development opportunities
  • Cycle to Work scheme
  • Perks at Work scheme
  • Discretionary Bonus scheme
A word on UK Security Clearance

Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance.

More details relating to UK Security Clearance can be found here:

United Kingdom Security Vetting: clearance levels - GOV.UK (www.gov.uk)

SiXworks is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organisation. SiXworks will be the hiring entity. By proceeding with this application, you understand that SiXworks will share your personal information with other IBM subsidiaries involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross‑border data transfer, are available here: https://www.ibm.com/privacy
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.