Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection

Company: Sanderson Recruitment
Apply for the Senior Cyber Security Engineer (EDR) Senior Security Engineer – Monitoring & Detection
Location: London
Job Description:

Overview

In this role you will design and improve security monitoring across cloud environments to protect critical public sector services. You will work with a multi-disciplinary team to develop robust detection capabilities, optimise SOC operations, and enhance visibility for faster threat response. The role blends hands-on detection engineering with stakeholder collaboration and guidance for the wider security function. You will be instrumental in shaping secure, resilient digital services at scale.

Responsibilities

  • Develop, tune, and maintain detection rules across SIEM, EDR, and threat detection platforms
  • Create and optimise detection logic using Splunk and endpoint security solutions
  • Map detections to the MITRE ATT&CK framework for comprehensive coverage
  • Improve detection quality by analysing alerts, reducing false positives, and boosting operational effectiveness
  • Validate detections through testing, simulations, and red-team exercises
  • Manage and optimise log ingestion pipelines with routing, filtering, enrichment, and normalisation
  • Enhance data efficiency via deduplication and data reduction; support cloud-native data streaming/storage
  • Ensure security data aligns with standards (OCSF) with strong encryption and access controls
  • Translate technical risks into business-focused recommendations
  • Collaborate with stakeholders to improve security outcomes and mentor junior engineers

Key requirements

  • Hands-on experience in Security Operations, Detection Engineering, Threat Detection, or Security Monitoring
  • Experience securing cloud environments (AWS, Azure, or GCP)
  • Expertise in Splunk and SPL; YARA rule development; EDR detection engineering; SIEM content development and tuning
  • Experience mapping detections to MITRE ATT&CK
  • Understanding of Zero Trust, identity-first security, secrets management, and network segmentation
  • Stakeholder engagement
  • Mentoring or leadership of engineers
  • Clear communication of technical risk to non-technical audiences
  • Splunk and SPL
  • YARA rule development
  • EDR detection engineering

…

Posted: October 1st, 2026