
Sanderson Government and Defence
Senior Cyber Security Engineer
Job Description
Salary: £85,000 - 85,000 per year
Requirements:- Strong hands-on experience within Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
- Experience securing cloud environments across AWS, Azure, or GCP.
- Expertise in one or more of the following: Splunk and SPL, YARA rule development, EDR detection engineering, or SIEM content development and tuning.
- Experience mapping detections to the MITRE ATT&CK framework.
- Strong understanding of modern security principles including Zero Trust, identity-first security, secrets management, and network segmentation.
- Experience with Cribl and security data pipeline management is desirable.
- Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies is desirable.
- Understanding of OCSF and security data normalisation is desirable.
- Experience working within government, defence, highly regulated industries, or the wider public sector is desirable.
- Experience mentoring or leading engineers within a SOC or cyber security function is desirable.
- Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
- Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.
- Map detections against the MITRE ATT&CK framework to ensure comprehensive threat coverage.
- Continuously improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.
- Validate detections through testing, simulation exercises, and red-team scenarios.
- Manage and optimise log ingestion pipelines to ensure high-quality, actionable security data.
- Configure routing, filtering, enrichment, and normalisation of security telemetry.
- Improve data efficiency through deduplication, data reduction, and flow summarisation techniques.
- Support cloud-native data streaming and storage solutions.
- Ensure security data aligns with industry standards such as OCSF while maintaining strong encryption and access controls.
- Translate complex technical risks into clear business-focused recommendations.
- Collaborate with technical and non-technical stakeholders to improve security outcomes.
- Act as a trusted technical advisor across engineering and security teams.
- Mentor junior engineers and contribute to the growth of the wider cyber security function.
- AWS
- Azure
- Cloud
- Flow
- GCP
- Support
- Network
- Security
- Splunk
More:
We are hiring a Senior Security Engineer - Monitoring & Detection for a hybrid role based in Bristol, London, Manchester, or Swansea, with a salary of £55,000 to £85,000 plus benefits. This is a hands-on engineering position supporting large-scale cloud-based environments that help protect critical public sector and government services. You will work alongside SOC analysts, engineers, architects, and stakeholders to strengthen security monitoring, improve resilience, and enable faster, risk-based decision-making. We are committed to respect, equality, diversity, and inclusion, and we welcome applications from people of all backgrounds and perspectives. If you need any help or adjustments during the recruitment process, we encourage you to let us know when you apply.
last updated 37 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Sanderson Government and Defence

Sanderson Government and Defence
Manchester
IT
Skills & Technologies
Inferred from job description
Salary Insight
£85,000
This role
£75,000
UK median
This salary is 13% above the UK median for Senior roles (£75,000/yr).
Based on 2024–2025 UK technology sector benchmarks