Detection Engineer

Cybanetix

Greater London

On-site

GBP 65,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement

Job summary

A cybersecurity firm in Greater London seeks a skilled security operations professional. This role entails designing and tuning detection logic across multiple platforms, writing and optimizing KQL queries, and collaborating with SOC teams for effective threat detection. Candidates must have SOC experience and a solid understanding of attack techniques, as well as familiarity with Microsoft security tools like Sentinel and Defender XDR. This position offers the chance to enhance security effectiveness and grow into senior roles.

Qualifications

  • Practical experience working in a SOC or security operations environment.
  • Knowledge of KQL or equivalent, with experience writing or tuning detections.
  • Solid understanding of common attack techniques across identity, endpoint, and cloud.
  • Experience with Microsoft security tooling, ideally Sentinel or Defender XDR.
  • Ability to reason about signal quality, false positives, and detection gaps.
  • Comfortable working independently and owning technical outcomes.

Responsibilities

  • Design and tune detection logic across Sentinel and XDR platforms.
  • Write and optimize KQL and S1QL queries for detection scenarios.
  • Support optimization of logging pipelines and signal ingestion.
  • Review and enhance existing analytic rules for coverage and performance.
  • Develop threat hunting queries and support proactive detection improvement initiatives.
  • Assist with detection testing and validation across endpoint, identity, and cloud telemetry.
  • Understand telemetry flow from endpoints, identity, cloud, and network into SIEM/XDR.
  • Support logging pipeline optimization and signal ingestion where required.
  • Contribute to detection-as-code and repeatable deployment practices.
  • Collaborate with SOC teams to refine detections based on feedback.
  • Liaise with threat intel contributors to align detections with attacker techniques.
  • Support customer discussions around detection coverage, tuning, and maturity.
  • Contribute to internal documentation, detection standards, and knowledge sharing.
  • Collaborate with engineering and architecture teams to improve overall security posture.

Skills

KQL
SOC experience
Analytical thinking
Microsoft security tooling
Understanding attack techniques

Tools

Sentinel
Defender XDR
Python
PowerShell

Job description

Exposure to other platforms such as CrowdStrike, or Elastic a plus

Threat intelligence integration and detection tuning

Join us and help strengthen the defensive capability of the organisations we support. You will focus on building, tuning, and improving detection logic across Microsoft and modern XDR platforms.

This role sits at the centre of threat detection, platform optimisation, and continuous improvement. You’ll work closely with SOC analysts, engineers, and threat intelligence practitioners to build high-quality detections.

Technical responsibilities
  • Design, build, and tune detection logic across Sentinel and XDR platforms.
  • Write and optimise KQL and S1QL queries for detection and hunting scenarios.
  • Improve signal quality through tuning, suppression logic, and data validation.
  • Review and enhance existing analytic rules for coverage, performance, and operational effectiveness.
  • Develop threat hunting queries and support proactive detection improvement initiatives.
  • Assist with detection testing and validation across endpoint, identity, and cloud telemetry.
  • Understand how telemetry from endpoints, identity, cloud, and network sources feeds into SIEM/XDR platforms.
  • Support optimisation of logging pipelines and signal ingestion where required.
  • Contribute to detection-as-code, structured rule development, and repeatable deployment practices.
  • Work closely with SOC teams to refine detections based on operational feedback.
  • Liaise with threat intelligence contributors to align detections with emerging attacker techniques.
  • Support customer discussions around detection coverage, tuning, and maturity improvements.
  • Contribute to internal documentation, detection standards, and knowledge sharing.
  • Collaborate with engineering and architecture teams to improve overall security posture.
What we’re looking for

Must have:

  • Practical experience working in a SOC or security operations environment.
  • Knowledge of KQL, or equivalent, and some experience writing or tuning detections.
  • Solid understanding of common attack techniques across identity, endpoint, and cloud.
  • Experience working with Microsoft security tooling, ideally Sentinel or Defender XDR.
  • Ability to think analytically about signal quality, false positives, and detection gaps.
  • Comfortable working independently and taking ownership of technical outcomes.
Nice to have
  • Experience with SentinelOne and S1QL.
  • Exposure to threat intelligence workflows and mapping detections to MITRE ATT&CK.
  • Familiarity with automation or scripting (PowerShell, Python).
  • Understanding of logging pipelines and data onboarding (AMA, Syslog, etc.).
  • Exposure to detection-as-code or CI/CD workflows.
  • Experience working in an MSSP or consultancy environment.
What this role gives you
  • Deep, hands‑on experience across modern SIEM and XDR platforms.
  • Exposure to real‑world attacker behaviours and evolving threat patterns.
  • The opportunity to directly improve the effectiveness of security teams.
  • A stepping stone toward senior engineering or architecture roles.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Franklin Fitch • Basingstoke

On-site
GBP 90,000 - 120,000
Detection Engineer: Build & Tune XDR Detections
Detection Engineer: Build & Tune XDR Detections

Cybanetix • Greater London

On-site
GBP 65,000 - 95,000
Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Security Engineer
Security Engineer

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000 - 85,000
Hybrid working
Training & certifications
Exposure to client environments
+2
Senior Security Engineer
Senior Security Engineer

InfoSec People Ltd • Basingstoke

On-site
GBP 65,000 - 85,000
Junior Security Engineer
Junior Security Engineer

Cybanetix • Greater London

On-site
GBP 50,000 - 70,000
Hands-on experience with modern SIEM, EDR, and Azure security tooling
Structured progression into security engineering
Mentorship from senior engineers and architects
Cyber Security Consultant
Cyber Security Consultant

Franklin Fitch • Greater London

Hybrid
GBP 55,000 - 65,000
Bonus
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Detection Engineer: Master Microsoft Sentinel & Defender XDR
Detection Engineer: Master Microsoft Sentinel & Defender XDR

Aviva • Bristol

On-site
GBP 39,000 - 65,000
Bonus: 10% of annual salary
Generous pension—Aviva contributes up,
Private medical benefit
+2
Head of Security Operations Technology · London, Dubai · Hybrid
Head of Security Operations Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 120,000 - 180,000