Sanderson Recruitment
Senior Cyber Security Engineer (EDR) – Monitoring & Detection
Job Description
Salary: £54,000 - 94,000 per year
Requirements:- Active SC Clearance required.
- Strong hands-on experience in Security Operations, Detection Engineering, Threat Detection, or Security Monitoring.
- Experience securing cloud environments across AWS, Azure, or GCP.
- Expertise in one or more of the following: Splunk and SPLYARA rule development, EDR detection engineering, or SIEM content development and tuning.
- Experience mapping detections to the MITRE ATT&CK framework.
- Strong understanding of modern security principles, including Zero Trust, identity-first security, secrets management, and network segmentation.
- Desirable: Experience with Cribl and security data pipeline management.
- Desirable: Knowledge of Kinesis, Amazon S3, Amazon Security Lake, or similar technologies.
- Desirable: Understanding of OCSF and security data normalisation.
- Desirable: Experience in government, defence, highly regulated industries, or the wider public sector.
- Desirable: Experience mentoring or leading engineers in a SOC or cyber security function.
- Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms.
- Create and optimise detection logic using technologies such as Splunk and endpoint security solutions.
- Map detections against the MITRE ATT&CK framework to support comprehensive threat coverage.
- Improve detection quality by analysing alert fidelity, false positives, and operational effectiveness.
- Validate detections through testing, simulation exercises, and red-team scenarios.
- Manage and optimise log ingestion pipelines to provide high-quality, actionable security data.
- Configure routing, filtering, enrichment, and normalisation of security telemetry.
- Improve data efficiency through deduplication, data reduction, and flow summarisation.
- Support cloud-native data streaming and storage solutions.
- Ensure security data aligns with industry standards such as OCSF, with strong encryption and access controls.
- Translate technical risks into clear, business-focused recommendations.
- Collaborate with technical and non-technical stakeholders to improve security outcomes.
- Act as a trusted technical advisor across engineering and security teams.
- Mentor junior engineers and contribute to the growth of our wider cyber security function.
- AWS
- Azure
- Cloud
- Flow
- GCP
- Support
- Network
- Security
- Splunk
More:
We are seeking a Senior Security Engineer – Monitoring & Detection to help secure large-scale, cloud-based environments supporting critical public sector and government services. This hands-on role focuses on threat detection, SIEM engineering, security monitoring, log management, and SOC optimisation, working alongside SOC analysts, engineers, architects, and stakeholders. The position offers hybrid working in Bristol, London, Manchester, or Swansea, with a salary of £55,000–£85,000 plus benefits. We value respect and equality and welcome applicants from all backgrounds and perspectives. We can provide support and adjustments during the recruitment process.
last updated 40 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Sanderson Recruitment
Sanderson Recruitment
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£74,000
This role
£75,000
UK median
This salary is 1% below the UK median for Senior roles (£75,000/yr).
Based on 2024–2025 UK technology sector benchmarks