Principal Analyst Detection Engineering - Technology Vendor

Hamilton Barnes Associates Limited

United Kingdom

Remote

GBP 60,000 - 70,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote-first with travel

Job summary

Hamilton Barnes Associates Limited is seeking a Principal Detection Engineer to own detection efficiency and capability across a CREST-accredited managed detection and response service. You will lead the detection function, reducing false positives, maturing rule sets aligned to MITRE ATT&CK, and applying threat intelligence to stay ahead of evolving threats.

Manage a small analyst team while retaining hands-on ownership of rule development and lab management.

Qualifications

  • Minimum 5 years of hands-on detection experience within a Security Operations Centre.
  • Strong working knowledge of MITRE ATT&CK and threat landscape intelligence.
  • Experience building, tuning and managing detection rule sets across a range of security technologies.
  • Practical technical and networking skills, including experience supporting a technical service desk environment.
  • Excellent understanding of cybersecurity issues, latest developments, risks and research.
  • Experience with parser builds, log source validation and audit logging standards.
  • Ability to communicate clearly to non-technical audiences in written and verbal form.
  • Evidence of ongoing personal development in the IT/cyber security space.
  • Degree in an information security or networking related discipline, or equivalent security qualifications (degree in progress also considered).
  • Self-motivated, adaptable, team-oriented and driven to operate at the forefront of cyber security.

Responsibilities

  • Devise and implement a measurable strategy to review alert volumes and reduce false positives.
  • Implement high fidelity alerting strategies and enable contextual alerting and case building for the analytical team.
  • Review, amend or retire detection rules to ensure they meet approved use cases.
  • Baseline newly onboarded customers over a 30-day period to achieve a known good monitoring state.
  • Advise on tuning and automation opportunities and assist in implementing improvements.
  • Review and ratify content updates to detection platforms; approve or retire new detections based on use cases.
  • Ensure all detection improvements and tuning are logged and auditable.
  • Design and implement a consistent, documented global deployment strategy for detections across a wide range of security technologies.
  • Build and manage rule packs based on technology feeds utilising the MITRE ATT&CK framework.
  • Utilise threat intelligence reports to continually refine detections against the current threat landscape.
  • Ratify log source receipt pre and post deployment, confirming logs are parsed and in a usable format.
  • Create deception detection capabilities where appropriate to improve team detection ability.
  • Research and ratify new technologies that could provide commercial advantage.
  • Pass all relevant manufacturer technical exams required to achieve or maintain accreditations.
  • Contribute to the operation and improvement of the 24/7 SOC/Service Desk function.

Skills

MITRE ATT&CK
Detection rules tuning
SOC experience
Threat intelligence
Parser builds
Log source validation
Audit logging standards
Clear communication
Cyber security research
Information security degree
Team-oriented

Education

Degree in information security or networking

Tools

MITRE ATT&CK framework
Threat intelligence platforms

Job description

Keen to join a company that champions growth and development?

Join a multi-award-winning cyber security specialist that has been helping organisations gain full visibility and control over cyber risk since 2015. The organization takes a fresh, innovative approach, delivering technically compelling solutions with clearly defined, measurable business outcomes.

The organization is inviting applications from experienced professionals for the role of Principal Detection Engineer to take ownership of detection efficiency and capability across a CREST-accredited managed detection and response service. Reporting to the Head of Security Operations, the successful candidate will lead the detection function, reducing false positives, maturing rule sets aligned to MITRE ATT&CK, and applying threat intelligence to stay ahead of the evolving threat landscape. The role also involves managing and mentoring a small team of analysts while retaining hands‑on technical ownership across rule development, parser builds, and detection lab management. This is primarily a remote position, with occasional travel for quarterly meetings and client engagements.

Responsibilities:
  • Devise and implement a measurable strategy to review alert volumes and reduce false positives, achieving set KPIs and targets
  • Implement high fidelity alerting strategies and enable contextual alerting and case building for the analytical team
  • Review, amend or retire detection rules to ensure they meet approved use cases
  • Baseline newly onboarded customers over a 30-day period to achieve a known good monitoring state
  • Advise on tuning and automation opportunities and assist in implementing improvements
  • Review and ratify content updates to detection platforms; approve or retire new detections based on use cases
  • Ensure all detection improvements and tuning are logged and auditable
  • Design and implement a consistent, documented global deployment strategy for detections across a wide range of security technologies
  • Build and manage rule packs based on technology feeds utilising the MITRE ATT&CK framework
  • Utilise threat intelligence reports to continually refine detections against the current threat landscape
  • Ratify log source receipt pre and post deployment, confirming logs are parsed and in a usable format
  • Create deception detection capabilities where appropriate to improve team detection ability
  • Research and recommend improvements to detection capabilities, processes and technologies
  • Assist with alert investigation, QA and feedback to the wider team
  • Create and document audit logging standards for all ingested log sources
  • Attend internal incident response reviews and use findings to identify new detection opportunities
  • Develop and maintain a detection lab for testing new detection capabilities
  • Build or amend parsers to ensure event parsing meets approved detection capability requirements
  • Run adversary emulation on a scheduled basis to identify detection gaps
  • Ensure processes and operating procedures are documented, regularly reviewed and up to date
  • Manage a small team, supporting role and responsibility allocation
  • Deliver monthly one-to-ones and scheduled mentoring sessions with assigned team members
  • Assist in creation of training and development plans to ensure knowledge sharing and consistency
  • Assist with alert escalations and support incident response functions as required
  • Research and ratify new technologies that could provide commercial advantage
  • Pass all relevant manufacturer technical exams required to achieve or maintain accreditations
  • Contribute to the operation and improvement of the 24/7 SOC/Service Desk function
Skills/Must Have:
  • Minimum 5 years of practical, hands‑on detection experience within a Security Operations Centre
  • Strong working knowledge of MITRE ATT&CK and threat landscape intelligence
  • Experience building, tuning and managing detection rule sets across a range of security technologies
  • Practical technical and networking skills, including experience supporting a technical service desk environment
  • Excellent understanding of cybersecurity issues, latest developments, risks and research
  • Experience with parser builds, log source validation and audit logging standards
  • Ability to communicate clearly to non-technical audiences in written and verbal form
  • Evidence of ongoing personal development in the IT/cyber security space
  • Degree in an information security or networking related discipline, or equivalent security qualifications (degree in progress also considered)
  • Self-motivated, adaptable, team-oriented and driven to operate at the forefront of cyber security
Benefits:
  • Remote‑first working with some travel for quarterly meetings and client engagements; support toward manufacturer technical accreditations
Salary:
  • £60,000 - £70,000
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Security Engineer - Detection & Response | Leading Global Investment Group
Security Engineer - Detection & Response | Leading Global Investment Group

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Threat Hunting & Detection Engineering Analyst in Cheltenham
Threat Hunting & Detection Engineering Analyst in Cheltenham

Energy Jobline ZR • Cheltenham

Hybrid
GBP 70,000 - 100,000
Private medical insurance
Generous annual leave
Technical training and career growth
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 51,000 - 69,000
Security Engineer - Systems Integrator
Security Engineer - Systems Integrator

Hamilton Barnes Associates Limited • Greater London, Cardiff

Hybrid
GBP 41,000 - 50,000
Primarily remote work
Occasional office attendance (London /
Client-facing responsibilities
AD - Global Detection Engineering
AD - Global Detection Engineering

NCC Group • Greater London

Hybrid
GBP 120,000 - 180,000
Flexible Working
25 days holiday + bank holidays
Pension & Life Assurance
+2
Senior Cyber Security Engineer (EDR)
Senior Cyber Security Engineer (EDR)

Sanderson Government & Defence • Manchester

Hybrid
GBP 55,000 - 85,000
Hybrid working locations
Benefits package
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Detection Engineer Microsoft Sentinel & Defender XDR - Netbuilder
Detection Engineer Microsoft Sentinel & Defender XDR - Netbuilder

OpenTalent • Greater London

Hybrid
GBP 63,000 - 77,000