Senior Security Engineer

Made Tech

Manchester

Hybrid

GBP 75,000 - 110,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

30 days Holiday
Flexible Working Hours
Flexible Parental Leave
Remote Working
Paid counselling

Job summary

Made Tech is seeking a Senior Security Engineer to own end‑to‑end security for our government‑grade services. You will build detection logic and tuning across Splunk, YARA, and EDR, while shaping security via automation and tooling in a live SOC.

You will translate risk for civil servants and system owners, mentor engineers, and lead monitoring pipelines across Cribl, Kinesis, and AWS/GCP/Azure platforms. This is a delivery‑driven security role with impact on public sector projects.

Qualifications

  • Hands-on cloud security experience — AWS, Azure, or GCP.
  • Advanced Splunk (SPL); YARA, and EDR detection logic.

Responsibilities

  • Build and tune detection rules across Splunk (SPL), YARA and EDR platforms.
  • Coverage and quality: map detections to MITRE ATT&CK; track signal-to-noise and false‑positive rates to keep alerting high‑fidelity.
  • Validation: ensure detections are accurate and actionable.
  • Feedback loops: work with L1–L3 analysts so detections stay grounded in operational reality.
  • Pipelines: manage log ingestion on Cribl — routing, filtering, normalisation, and enrichment at the edge.
  • Optimisation: reduce volume via deduplication, trimming, and NetFlow summarisation; manage streaming/storage (Kinesis, S3, Amazon Security Lake).
  • Standards: apply hot/warm/cold data tiering; normalise into OCSF; enforce encryption and least‑privilege access.
  • Translation: turn technical risk into business/policy terms for civil servant stakeholders.
  • Mentorship: support junior/mid-level engineers and act as a technical point of contact across teams.

Skills

Cloud security
Threat detection concepts

Tools

Splunk (SPL)
YARA
EDR detection
Cribl
Kinesis
S3
Amazon Security Lake
OCSF/data normalisation

Job description

We help UK public sector organisations build and run digital services that are secure, trustworthy, and resilient. As a Senior Security Engineer in our Cyber practice, you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.

We're looking for a Senior Security Engineer- Monitoring & Detection who can build and tune detection logic in a live SOC, and own the pipelines that feed it. You'll work hands‑on across SIEM/detection and log ingestion/normalisation, and translate technical risk into decisions for government stakeholders and system owners. This is a delivery role: security assurance should speed decisions up, not slow them down.

Key responsibilities
Detection Engineering
  • Build & tune: detection rules across Splunk (SPL), YARA and EDR platforms.
  • Coverage & quality: map detections to MITRE ATT&CK; track signal-to-noise and false‑positive rates to keep alerting high‑fidelity.
  • Validation:
  • Feedback loops: work with L1–L3 analysts so detections stay grounded in operational reality.
  • Pipelines: manage log ingestion on Cribl — routing, filtering, normalisation, and enrichment at the edge.
  • Optimisation: reduce volume via deduplication, trimming, and NetFlow summarisation; manage streaming/storage (Kinesis, S3, Amazon Security Lake).
  • Standards: apply hot/warm/cold data tiering; normalise into OCSF; enforce encryption and least‑privilege access.
Stakeholders & Team
  • Translation: turn technical risk into business/policy terms for civil servant stakeholders and system owners.
  • Mentorship: support junior/mid-level engineers and act as a technical point of contact across teams.
Skills, knowledge and expertise
  • Hands‑on cloud security experience — AWS, Azure, or GCP.
  • Either: Advanced Splunk (SPL); YARA, and EDR detection logic.
or
  • Experience with Cribl, Kinesis, S3, Amazon Security Lake, and OCSF/data normalisation.
  • Strong grasp of Zero Trust, identity‑first security, secrets management, and network segmentation.
  • Experience working with or alongside UK Government / public sector stakeholders.

We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We’re also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Here are some of our most popular benefits listed below:

30 days Holiday

we offer 30 days of paid annual leave

Flexible Working Hours

we are flexible with what hours you work

Flexible Parental Leave

we offer flexible parental leave options

Remote Working

we offer part time remote working for all our staff

Paid counselling

we offer paid counselling as well as financial and legal advice

An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we're looking for all successful candidates for this role to have eligibility.

Eligibility for SC requires 5 years' UK residency and 5 year' employment history (or back to full‑time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We’re collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us.

Working hours: Our standard hours are Monday to Friday, but the nature of this role means some work outside normal hours may be required, for example during release and change windows, planned maintenance, or to align with client operating hours. This is occasional rather than routine, and we'll always give as much notice as we can and agree it with you in advance wherever possible.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Made Tech • Greater London

On-site
GBP 75,000 - 110,000
30 days Holiday
Flexible Working Hours
Flexible Parental Leave
+1
Senior Cyber Security Engineer (EDR)
Senior Cyber Security Engineer (EDR)

Sanderson Government & Defence • Manchester

Hybrid
GBP 55,000 - 85,000
Hybrid working locations
Benefits package
Lead Security Analyst
Lead Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 90,000 - 120,000
Senior Security Analyst
Senior Security Analyst

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance
Security Engineer (Site Reliability Engineering) - SC Cleared
Security Engineer (Site Reliability Engineering) - SC Cleared

Sanderson Government & Defence • City Of London

Hybrid
GBP 125,000 - 136,000
Security Engineer (Site Reliability Engineering)
Security Engineer (Site Reliability Engineering)

Sanderson Government & Defence • Greater London

Hybrid
GBP 101,000 - 109,000
SOC Engineer - UK Public Sector
SOC Engineer - UK Public Sector

IBM • Hursley

On-site
GBP 70,000 - 100,000
Flexible working
Private medical + pension
Senior Security Operations Centre Analyst
Senior Security Operations Centre Analyst

Sopra Steria • Farnborough

On-site
GBP 52,000 - 64,000
25 days annual leave
Health cash plan
Life assurance
+2
SOC Engineer - UK Public Sector
SOC Engineer - UK Public Sector

IBM • Abbots Worthy

On-site
GBP 65,000 - 95,000
Flexible working
Private medical
Dental & optical cover
+2
Senior Security Engineering Consultant
Senior Security Engineering Consultant

Infosec • Southampton

Hybrid
GBP 72,000 - 88,000
Performance-based bonuses
Collaborative engineering environment
Industry-leading benefits