Senior Threat Detection & Incident Response Engineer

Jobtailor

Cambridge

On-site

GBP 65,000 - 95,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor in Cambridge is seeking a hands-on security investigator to lead investigations into escalated incidents, develop hypotheses, collect artefacts and determine root cause across endpoints, networks and cloud. You will build and optimise detection rules, queries and monitoring logic to strengthen our security posture.

The role covers threat hunting using MITRE ATT&CK, creating runbooks and automation to speed investigations, and collaborating with external SOC and internal engineering

Qualifications

  • Hands-on experience investigating security incidents, including developing investigation hypotheses, collecting artefacts and analysing endpoint, network and application data.
  • Strong working knowledge of SIEM and security monitoring tooling, including the ability to write and develop queries for complex investigations.
  • Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles.
  • Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid infrastructure.
  • Background developing detection logic, runbooks, automation or security tooling.
  • Knowledge of operating system internals and forensic investigation across Windows, macOS or Linux environments.
  • Scripting knowledge such as PowerShell or Python would be advantageous.

Responsibilities

  • Lead investigations into escalated security events and incidents, developing hypotheses, collecting evidence and determining root cause and impact.
  • Build and optimise detection rules, queries and monitoring logic across cloud, endpoint, network and application environments.
  • Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times.
  • Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections.
  • Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations.
  • Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability.
  • Participate in an on-call rotation.

Skills

Incident Investigation
Detection Logic Development
MITRE ATT&CK
SIEM Tooling
Cloud Security
Threat Hunting
Forensic Investigation
Scripting (PowerShell/Python)

Tools

SIEM
Security Monitoring Tooling
Automation Tools

Job description

Jobtailor in Cambridge is seeking a hands-on security investigator to lead investigations into escalated incidents, develop hypotheses, collect artefacts and determine root cause across endpoints, networks and cloud. You will build and optimise detection rules, queries and monitoring logic to strengthen our security posture.

The role covers threat hunting using MITRE ATT&CK, creating runbooks and automation to speed investigations, and collaborating with external SOC and internal engineering

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SecOps Architect: Detection, IR & Automation
Senior SecOps Architect: Detection, IR & Automation

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Senior Security Analyst: Threat Hunting & Incident Response
Senior Security Analyst: Threat Hunting & Incident Response

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Senior SOC Engineer: Lead Threat Detection & Incident Response
Senior SOC Engineer: Lead Threat Detection & Incident Response

MTI • Greater London

On-site
GBP 60,000 - 80,000
Security Ops Lead: Threat Detection & IR
Security Ops Lead: Threat Detection & IR

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Senior SOC Incident Lead & Detection Engineer
Senior SOC Incident Lead & Detection Engineer

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Senior Threat Hunter & Incident Response Lead
Senior Threat Hunter & Incident Response Lead

Made Tech Limited • United Kingdom

On-site
GBP 60,000 - 80,000
Sponsorship for recognized cyber certifications
Support for achieving SC clearance
Senior Detection & Response Engineer - Telemetry & IR
Senior Detection & Response Engineer - Telemetry & IR

Techfellow Limited • Greater London

Hybrid
GBP 250,000 - 350,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Creative Artists Agency • Greater London

On-site
GBP 90,000 - 120,000
Senior Threat Detection & Response Engineer
Senior Threat Detection & Response Engineer

Pirum Systems Ltd. • Greater London

Hybrid
GBP 90,000 - 150,000
Hybrid work options
Private medical insurance
Eyecare
+5