Senior Cyber Security Engineer (EDR)

Sanderson Government & Defence

Manchester

Hybrid

GBP 55,000 - 85,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid working locations
Benefits package

Job summary

Sanderson Government & Defence is seeking a Senior Security Engineer focusing on monitoring and detection. The role is hybrid with locations in Bristol, London, Manchester or Swansea, and offers a salary of £55,000–£85,000 plus benefits and active SC clearance requirements.

You will design and enhance detection capabilities, support cloud-based critical services, and work with SOC analysts, engineers, and stakeholders to improve security visibility and response.

Qualifications

  • Hands-on experience in Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
  • Experience securing cloud environments across AWS, Azure, or GCP.
  • Expertise in Splunk and SPL, YARA, EDR detection engineering, and SIEM content tuning.
  • Experience mapping detections to the MITRE ATT&CK framework.
  • Strong understanding of Zero Trust and identity-first security principles.

Responsibilities

  • Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
  • Create and optimise detection logic using Splunk and endpoint security solutions.
  • Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.
  • Continuously improve detection quality by analysing alert fidelity and false positives.
  • Validate detections through testing, simulations, and red-team exercises.

Skills

Security operations
SIEM
Threat detection
Cloud security
MITRE ATT&CK
Splunk
EDR
Log management

Tools

Splunk
EDR solutions
Kinesis (AWS)

Job description

Senior Security Engineer - Monitoring & Detection

Hybrid Working (Bristol, London, Manchester or Swansea)

£55,000 - £85,000 + Benefits

Active SC Clearance Required

Join a Team Protecting Critical Digital Services

We're looking for an experienced Senior Security Engineer - Monitoring & Detection to play a key role in securing large-scale, cloud-based environments supporting critical public sector and government services.

This is a hands-on engineering role focused on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation. You'll design and enhance detection capabilities, improve security visibility, and ensure organisations can rapidly identify and respond to emerging cyber threats.

Working alongside SOC analysts, engineers, architects, and stakeholders, you'll help build modern security monitoring capabilities that improve resilience while enabling faster, risk-based decision-making.

What You'll Be Doing
  • Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
  • Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.
  • Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.
  • Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.
  • Validate detections through testing, simulation exercises, and red-team scenarios.
Security Data & Log Engineering
  • Manage and optimise log ingestion pipelines to ensure high-quality, actionable security data.
  • Configure routing, filtering, enrichment, and normalisation of security telemetry.
  • Improve data efficiency through deduplication, data reduction, and flow summarisation techniques.
  • Support cloud-native data streaming and storage solutions.
  • Ensure security data aligns with industry standards such as OCSF while maintaining strong encryption and access controls.
Stakeholder Engagement
  • Translate complex technical risks into clear business-focused recommendations.
  • Collaborate with technical and non-technical stakeholders to improve security outcomes.
  • Act as a trusted technical advisor across engineering and security teams.
  • Mentor junior engineers and contribute to the growth of the wider cyber security function.
What We're Looking For
Essential Experience
  • Strong hands-on experience within Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
  • Experience securing cloud environments across AWS, Azure, or GCP.
  • Expertise in one or more of the following:
    • Splunk and SPL
    • YARA rule development
    • EDR detection engineering
    • SIEM content development and tuning
  • Experience mapping detections to the MITRE ATT&CK framework.
  • Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.
Desirable Experience
  • Experience with Cribl and security data pipeline management.
  • Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies.
  • Understanding of OCSF and security data normalisation.
  • Experience working within government, defence, highly regulated industries, or the wider public sector.
  • Experience mentoring or leading engineers within a SOC or cyber security function.
Reasonable Adjustments

Respect and equality are core values to us. We are proud of the diverse and inclusive community we have built, and we welcome applications from people of all backgrounds and perspectives. Our success is driven by our people, united by the spirit of partnership to deliver the best resourcing solutions for our clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Monitoring & Detection
Senior Security Engineer - Monitoring & Detection

Made Tech Limited • West of England

On-site
GBP 55,000 - 85,000
30 days Holiday
Flexible Working Hours
Remote Working (part-time)
+1
Senior Security Engineer
Senior Security Engineer

TRIA • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Basingstoke

Hybrid
GBP 56,000 - 80,000
Salary up to £80,000
Bonuses
Hybrid work
Security Engineer (Site Reliability Engineering) - SC Cleared
Security Engineer (Site Reliability Engineering) - SC Cleared

Sanderson Government & Defence • City Of London

Hybrid
GBP 125,000 - 136,000
Security Engineer
Security Engineer

Franklin Fitch • Reading

Hybrid
GBP 60,000 - 70,000
Hybrid work model
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
SC Cleared Cyber Security Engineer
SC Cleared Cyber Security Engineer

Lorien • Stevenage

On-site
GBP 180,000 - 210,000
Cyber Security Engineer
Cyber Security Engineer

Guidant Global • Stevenage

On-site
GBP 109,000 - 142,000
Cyber Security Consultant
Cyber Security Consultant

Franklin Fitch • Greater London

Hybrid
GBP 55,000 - 65,000
Bonus
Cyber Security Engineer
Cyber Security Engineer

Carbon 60 • Stevenage

On-site
GBP 109,000 - 142,000