Job Search and Career Advice Platform

Enable job alerts via email!

Detection Engineering Consultant

Bridewell

Cardiff

Hybrid

GBP 50,000 - 70,000

Full time

10 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading cyber security services company in Cardiff is seeking a Detection Engineering Consultant. In this hands-on role, you will develop detection capabilities across on-premises and cloud environments, working closely with client teams to enhance their cyber security posture. Ideal candidates will have experience with detection engineering using platforms like Microsoft Sentinel, as well as a strong understanding of current attacker behaviours. This position offers a competitive salary and flexible hybrid working conditions.

Benefits

Competitive Salary
25 Days Holiday – Plus buy and sell options
Flexible Working (around core office hours)
Profit Share Scheme
Company Pension
Employee Shareholder Scheme
Dedicated Training Budget
Life Assurance
Cycle to Work Scheme
Electric Vehicle Scheme
Private Healthcare
Vision Care
Birthday off (After 1 year)

Qualifications

  • Experience with Microsoft Sentinel detection engineering is highly desirable.
  • Experience in developing detection logic aligned with real-world threats.
  • Ability to work closely with client stakeholders and communicate effectively.

Responsibilities

  • Design, develop, and maintain high-fidelity detection logic.
  • Apply threat frameworks to guide detection coverage.
  • Contribute to detection-as-code practices and CI/CD pipelines.

Skills

Developing detection logic using query languages such as KQL or SPL
Working with SIEM and detection platforms like Microsoft Sentinel
Understanding modern attacker techniques
Translating threat intelligence into detection use cases
Writing automation scripts (e.g., Python, PowerShell)
Operating confidently in production environments

Tools

Microsoft Sentinel
Splunk
KQL
SPL
Azure
AWS
Job description

One of the most exciting prospects in the UK cyber security sector today, Bridewell is a leading cyber security services company specialising in protecting and transforming critical business functions for some of the world’s most trusted organisations. We are the trusted partner for operators of essential services and provide end-to-end cyber security capabilities that help our clients overcome their security challenges, allowing them to operate safely and securely.

Bridewell holds the Gold level, Investors in People award which we feel solidifies and reflects on the outstanding calibre that makes us truly one team.

Who are we looking for?

We are seeking an experienced Detection Engineering Consultant to join our Detection Engineering team. In this role, you will initially be embedded with one of our clients, supporting and enhancing their cyber detection capability, before going on to work across a range of Bridewell customers.

This is a hands‑on detection engineering role, suited to someone who enjoys working close to operational teams, understands modern attacker behaviours, and is passionate about building high‑quality, threat‑led detections at scale.

For the initial engagement, experience with Microsoft Sentinel detection engineering is highly desirable.

What you’ll be doing

As a Detection Engineering Consultant, you will work closely with client security operations, engineering, and threat intelligence teams to develop, test, and mature detection capabilities across on‑premises and cloud environments.

Your responsibilities will include:
Detection Engineering & Capability Development
  • Designing, developing, and maintaining high‑fidelity detection logic aligned to real‑world threats.
  • Improving existing detection content to reduce alert fatigue and increase signal quality.
  • Ensuring detections are robust, well‑tested, and supported by meaningful context and response guidance for SOC analysts and incident responders.
  • Translating threat intelligence, attacker TTPs, and research into actionable detection logic.
Threat‑Led & Test‑Driven Engineering
  • Applying threat frameworks such as MITRE ATT&CK and Cyber Kill Chain to guide detection coverage.
  • Conducting positive and negative testing of detection logic, including attacker emulation where appropriate.
  • Reviewing detection code and processes to identify gaps, weaknesses, or opportunities for improvement.
  • Supporting threat hunts and contributing to detection‑led investigations when required.
Automation & Engineering
  • Contributing to detection‑as‑code practices, CI/CD pipelines, and validation tooling.
  • Developing or maintaining lightweight automation and scripts to improve detection engineering workflows.
  • Working with platform and engineering teams to ensure detection content scales reliably across environments.
Client Engagement & Consultancy
  • Working closely with client stakeholders to understand their environment, risks, and detection priorities.
  • Providing clear, practical guidance on detection strategy, coverage, and improvements.
  • Communicating technical findings and recommendations in a way that is accessible and actionable.
  • Acting as a trusted consultant while representing Bridewell values and best practices.
What we’re looking for

You’ll have experience of:

  • Developing and maintaining detection logic using query languages such as KQL or SPL.
  • Working with SIEM and detection platforms such as Microsoft Sentinel, Splunk, or Chronicle.
  • Understanding modern attacker techniques, behaviours, and evasion methods.
  • Translating threat intelligence into effective detection use cases.
  • Working knowledge of Windows, macOS, and/or Linux operating systems.
  • Secure, test‑driven engineering practices and detection lifecycle management.
  • Writing or maintaining automation scripts (e.g. Python, PowerShell, Bash).
  • Working independently while collaborating effectively within multi‑disciplinary teams.
  • Operating confidently in production environments at scale.
It’s a benefit if you have
  • Previous experience working as a Detection Engineer within an MSSP or consultancy.
  • Strong hands‑on experience with Microsoft Sentinel detection engineering.
  • Knowledge of cloud infrastructure and security across Azure, AWS, or GCP.
  • Experience developing detections as code and integrating them into CI/CD pipelines.
  • Exposure to adversary emulation, purple teaming, or offensive security techniques.
  • Familiarity with Infrastructure as Code tools (e.g. Bicep, Terraform).
What’s in it for you?

Our vision is to create a safe, inclusive digital world where people and organisations can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasise the importance of the part we play in society, and our commitment to our people and clients. Bridewell will provide a great career opportunity with continual development as well as the following benefits:

  • Competitive Salary
  • 25 Days Holiday – Plus buy and sell options
  • Flexible Working (around core office hours)
  • Profit Share Scheme
  • Company Pension
  • Employee Shareholder Scheme
  • Dedicated Training Budget
  • Life Assurance
  • Cycle to Work Scheme
  • Electric Vehicle Scheme
  • Private Healthcare (incl. Gym discounts)
  • Vision Care
  • Birthday off (After 1 year)
About Bridewell

One of the most exciting prospects in the UK cyber security sector today, Bridewell is one of the fastest growing cyber security services businesses with a strong track record for delivering complex security projects and providing excellent customer service. Bridewell holds the Gold level Investors in People award which we feel solidifies and reflects on the outstanding calibre that makes us truly one team.

Along with our focus on our people, we also have a big focus on sustainability and recognise the role we play in the fight against climate change. Today, Bridewell is proud to be a carbon negative business.

Location

Bridewell operates a hybrid and flexible working policy; however you will be required to travel to different sites on occasion.

Bridewell values diversity in the workplace and is a fair and equal opportunity employer.

We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.