Senior Security Engineer - Monitoring & Detection

Open 1d
We help UK public sector organisations build and run digital services that are secure, trustworthy, and resilient. As a Senior Security Engineer in our Cyber practice, you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.

We're looking for a Senior Security Engineer- Monitoring & Detection who can build and tune detection logic in a live SOC, and own the pipelines that feed it. You'll work hands-on across SIEM/detection and log ingestion/normalisation, and translate technical risk into decisions for government stakeholders and system owners. This is a delivery role: security assurance should speed decisions up, not slow them down.

Detection Engineering
  • Build & tune: detection rules across Splunk (SPL), YARA and EDR platforms.

  • Coverage & quality: map detections to MITRE ATT&CK; track signal-to-noise and false-positive rates to keep alerting high-fidelity.

  • Validation: test new/updated rules via replay and load testing; run red-team scenarios for critical rules.

  • Feedback loops: work with L1–L3 analysts so detections stay grounded in operational reality.

  • Pipelines: manage log ingestion on Cribl — routing, filtering, normalisation, and enrichment at the edge.

  • Optimisation: reduce volume via deduplication, trimming, and NetFlow summarisation; manage streaming/storage (Kinesis, S3, Amazon Security Lake).

  • Standards: apply hot/warm/cold data tiering; normalise into OCSF; enforce encryption and least-privilege access.

Stakeholders & Team
  • Translation: turn technical risk into business/policy terms for civil servant stakeholders and system owners.

  • Mentorship: support junior/mid-level engineers and act as a technical point of contact across teams.
  • Hands-on cloud security experience — AWS, Azure, or GCP.

  • Either: Advanced Splunk (SPL); YARA, and EDR detection logic.
or
  • Experience with Cribl, Kinesis, S3, Amazon Security Lake, and OCSF/data normalisation.

  • Strong grasp of Zero Trust, identity-first security, secrets management, and network segmentation.

  • Experience working with or alongside UK Government / public sector stakeholders.
We are always listening to our growing teams and evolving the benefits available to our people. As we scale, as do our benefits and we are scaling quickly. We've recently introduced a flexible benefit platform which includes a Smart Tech scheme, Cycle to work scheme, and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. We’re also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.

Here are some of our most popular benefits listed below:

30 days Holiday - we offer 30 days of paid annual leave
Flexible Working Hours - we are flexible with what hours you work
Flexible Parental Leave - we offer flexible parental leave options
Remote Working - we offer part time remote working for all our staff
Paid counselling - we offer paid counselling as well as financial and legal advice

At this point, we hope you're feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if you’d like an informal chat about the role and your suitability before applying. We are hiring for this role directly, so will not respond to any CVs sent via external recruitment agencies.

SC Eligibility
An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result, we're looking for all successful candidates for this role to have eligibility.

Eligibility for SC requires 5 years' UK residency and 5 year' employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC, we won't be able to progress your application and we will contact you to let you know why.

Support in applying
If you need this job description in another format, or other support in applying, please email [email protected].

We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. We’re collectively continuing to grow a culture that is happy, healthy, safe and inspiring for people of all backgrounds and experiences, so we encourage people from underrepresented groups to apply for roles with us.

When you apply, we’ll put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. We’ve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.

Working hours: Our standard hours are Monday to Friday, but the nature of this role means some work outside normal hours may be required, for example during release and change windows, planned maintenance, or to align with client operating hours. This is occasional rather than routine, and we'll always give as much notice as we can and agree it with you in advance wherever possible.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available