Senior Cyber Security Engineer

Sanderson Government and Defence

Manchester

Hybrid

GBP 55,000 - 85,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid role

Job summary

Sanderson Government and Defence is hiring a Senior Security Engineer - Monitoring & Detection for a hybrid role across the UK, including Manchester. The role focuses on hands-on development, tuning and maintenance of detection rules for SIEM, EDR and threat detection platforms.

You will work with AWS/Azure/GCP environments, map detections to MITRE ATT&CK, and collaborate with SOC analysts and engineers to strengthen security monitoring across government services.

Qualifications

  • Hands-on experience in Security Operations, Detection Engineering, Threat Detection or Security Monitoring.
  • Experience securing cloud environments (AWS, Azure or GCP).
  • Expertise with Splunk and SPL, YARA rules, EDR detection engineering or SIEM content development.
  • Experience mapping detections to the MITRE ATT&CK framework.
  • Strong knowledge of Zero Trust, identity-first security, secrets management and network segmentation.
  • Desirable: Cribl and security data pipeline management.
  • Desirable: knowledge of Kinesis, S3, or Security Lake.
  • Desirable: OCSF and security data normalisation.
  • Experience in government/defence or heavily regulated sectors.

Responsibilities

  • Develop, tune and maintain detection rules across SIEM, EDR and threat platforms.
  • Create and optimise detection logic using Splunk and endpoint security tools.
  • Map detections against MITRE ATT&CK to ensure coverage.
  • Improve detection quality by analysing alerts, false positives and ops effectiveness.
  • Validate detections via testing, exercises and red-team scenarios.
  • Manage and optimise log ingestion pipelines for high-quality data.
  • Configure routing, filtering, enrichment and normalisation of telemetry.
  • Improve data efficiency through deduplication and flow summarisation.
  • Support cloud-native data streaming and storage solutions.
  • Ensure security data aligns with standards such as OCSF and encryption practices.
  • Translate complex risks into clear business-focused recommendations.
  • Collaborate with stakeholders to improve security outcomes.
  • Act as trusted technical advisor across engineering and security teams.
  • Mentor junior engineers and grow the security function.

Skills

Security Operations
Detection Engineering
Threat Detection
Security Monitoring
Cloud Security (AWS)
Cloud Security (Azure)
Cloud Security (GCP)
Splunk
SPL
YARA
EDR
MITRE ATT&CK
Zero Trust

Tools

AWS
Azure
GCP
Splunk
Cribl
Kinesis
S3
Security Lake
OCSF

Job description

Salary: £85,000 - 85,000 per year

Requirements
  • Strong hands-on experience within Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
  • Experience securing cloud environments across AWS, Azure, or GCP.
  • Expertise in one or more of the following: Splunk and SPL, YARA rule development, EDR detection engineering, or SIEM content development and tuning.
  • Experience mapping detections to the MITRE ATT&CK framework.
  • Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.
  • Experience with Cribl and security data pipeline management is desirable.
  • Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies is desirable.
  • Understanding of OCSF and security data normalisation is desirable.
  • Experience working within government, defence, highly regulated industries, or the wider public sector is desirable.
  • Experience mentoring or leading engineers within a SOC or cyber security function is desirable.
Responsibilities
  • Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
  • Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.
  • Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.
  • Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.
  • Validate detections through testing, simulation exercises, and red-team scenarios.
  • Manage and optimise log ingestion pipelines to ensure high-quality, actionable security data.
  • Configure routing, filtering, enrichment, and normalisation of security telemetry.
  • Improve data efficiency through deduplication, data reduction, and flow summarisation techniques.
  • Support cloud-native data streaming and storage solutions.
  • Ensure security data aligns with industry standards such as OCSF while maintaining strong encryption and access controls.
  • Translate complex technical risks into clear business-focused recommendations.
  • Collaborate with technical and non-technical stakeholders to improve security outcomes.
  • Act as a trusted technical advisor across engineering and security teams.
  • Mentor junior engineers and contribute to the growth of the wider cyber security function.
Technologies
  • AWS
  • Azure
  • Cloud
  • Flow
  • GCP
  • Support
  • Network
  • Security
  • Splunk
More

We are hiring a Senior Security Engineer - Monitoring & Detection for a hybrid role based in Bristol, London, Manchester, or Swansea, with a salary of £55,000 to £85,000 plus benefits. This is a hands-on engineering position supporting large-scale cloud-based environments that help protect critical public sector and government services. You will work alongside SOC analysts, engineers, architects, and stakeholders to strengthen security monitoring, improve resilience, and enable faster, risk-based decision-making. We are committed to respect, equality, diversity, and inclusion, and we welcome applications from people of all backgrounds and perspectives. If you need any help or adjustments during the recruitment process, we encourage you to let us know when you apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer (EDR)
Senior Cyber Security Engineer (EDR)

Sanderson Government & Defence • Manchester

On-site
GBP 55,000 - 85,000
Hybrid working locations
Benefits package
Senior Security Engineer
Senior Security Engineer

Made Tech • Manchester

Hybrid
GBP 75,000 - 110,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+2
Senior Security Engineer
Senior Security Engineer

Made Tech • Greater London

On-site
GBP 75,000 - 110,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+1
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Southampton

Hybrid
GBP 72,000 - 88,000
Performance-based bonuses
Collaborative engineering environment
Industry-leading benefits
Cybersecurity Engineer
Cybersecurity Engineer

AMS CWS • Greater London

On-site
GBP 50,000 - 70,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

On-site
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Cloud Security Engineer – National Security West
Cloud Security Engineer – National Security West

Hackajob Ltd • Leeds

Hybrid
GBP 61,000 - 101,000
25 days annual leave
Private medical and dental insurance
Flexible benefits package
+4
Security Engineer (SRE) - SC Cleared
Security Engineer (SRE) - SC Cleared

Sanderson Government and Defence • Greater London

Hybrid
GBP 131,000 - 142,000
Security Consultant
Security Consultant

Consult • Greater London

Hybrid
GBP 55,000 - 70,000
Cyber Security Engineer (Ref: 197774)
Cyber Security Engineer (Ref: 197774)

Forsyth Barnes Consultancy • Manchester

On-site
GBP 60,000 - 90,000
SIEM engineering exposure
Cloud security focus
Risk and governance
+1