Senior Detection and Response Engineer

Jobtailor

Cambridge

On-site

GBP 65,000 - 95,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Cambridge is seeking a hands-on security investigator to lead investigations into escalated incidents, develop hypotheses, collect artefacts and determine root cause across endpoints, networks and cloud. You will build and optimise detection rules, queries and monitoring logic to strengthen our security posture.

The role covers threat hunting using MITRE ATT&CK, creating runbooks and automation to speed investigations, and collaborating with external SOC and internal engineering

Qualifications

  • Hands-on experience investigating security incidents, including developing investigation hypotheses, collecting artefacts and analysing endpoint, network and application data.
  • Strong working knowledge of SIEM and security monitoring tooling, including the ability to write and develop queries for complex investigations.
  • Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles.
  • Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid infrastructure.
  • Background developing detection logic, runbooks, automation or security tooling.
  • Knowledge of operating system internals and forensic investigation across Windows, macOS or Linux environments.
  • Scripting knowledge such as PowerShell or Python would be advantageous.

Responsibilities

  • Lead investigations into escalated security events and incidents, developing hypotheses, collecting evidence and determining root cause and impact.
  • Build and optimise detection rules, queries and monitoring logic across cloud, endpoint, network and application environments.
  • Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times.
  • Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections.
  • Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations.
  • Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability.
  • Participate in an on-call rotation.

Skills

Incident Investigation
Detection Logic Development
MITRE ATT&CK
SIEM Tooling
Cloud Security
Threat Hunting
Forensic Investigation
Scripting (PowerShell/Python)

Tools

SIEM
Security Monitoring Tooling
Automation Tools

Job description

  • Lead investigations into escalated security events and incidents, developing hypotheses, collecting evidence and determining root cause and impact.
  • Build and optimise detection rules, queries and monitoring logic across cloud, endpoint, network and application environments.
  • Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times.
  • Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections.
  • Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations.
  • Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability.
  • Participate in an on-call rotation.
Requirements
  • Hands-on experience investigating security incidents, including developing investigation hypotheses, collecting artefacts and analysing endpoint, network and application data.
  • Strong working knowledge of SIEM and security monitoring tooling, including the ability to write and develop queries for complex investigations.
  • Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles.
  • Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid infrastructure.
  • Background developing detection logic, runbooks, automation or security tooling.
  • Knowledge of operating system internals and forensic investigation across Windows, macOS or Linux environments.
  • Scripting knowledge such as PowerShell or Python would be advantageous.
Core Competencies

Demonstrates expertise in investigating security incidents, developing detection logic, and applying security controls across cloud and hybrid environments. Proficient in utilizing frameworks like MITRE ATT&CK and enhancing security telemetry through automation and tooling.

Highest-signal resume keywords
  • Incident Investigation
  • Detection Logic Development
  • MITRE ATT&CK Framework
  • SIEM Tooling
  • Cloud Security Practices
ATS Optimization Keywords
Hard Skills
  • Security Incident Investigation
  • Detection Rule Development
  • Threat Hunting
  • Forensic Investigation
  • Scripting (PowerShell, Python)
Industry Keywords
  • Adversary Tactics
  • TTPs
  • Cloud Environments
  • Hybrid Infrastructure
  • Incident Response
Tools & Technologies
  • SIEM
  • Security Monitoring Tooling
  • Automation Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Cyber security Operation Manager
Cyber security Operation Manager

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Detection Engineer
Detection Engineer

Cybanetix • Greater London

On-site
GBP 65,000 - 95,000
Hands-on experience with modern SIEM and XDR platforms
Exposure to real-world attacker behaviors
Opportunity for career advancement
L3 SOC Analyst
L3 SOC Analyst

Saviynt • United Kingdom

On-site
GBP 60,000 - 80,000
Senior Security Analyst
Senior Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Creative Artists Agency • Greater London

On-site
GBP 90,000 - 120,000
Security Operations Analyst: Threat Detection & Response
Security Operations Analyst: Threat Detection & Response

Graphic Packaging International • United Kingdom

On-site
GBP 40,000 - 70,000
Cyber Security Analyst
Cyber Security Analyst

Graphic Packaging International • United Kingdom

On-site
GBP 40,000 - 70,000
Senior Security Engineer Consultant
Senior Security Engineer Consultant

InfoSec People Ltd • Basingstoke

Hybrid
GBP 70,000 - 100,000
Hybrid working model
Comprehensive employee benefits
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000