Principal Analyst Detection Engineering - Technology Vendor
- £60,000 - £70,000
- United Kingdom
- Permanent
- 70000
- Enterprise Security
- Cyber Security
Keen to join a company that champions growth and development?
Join a multi-award-winning cyber security specialist that has been helping organisations gain full visibility and control over cyber risk since 2015. The organization takes a fresh, innovative approach, delivering technically compelling solutions with clearly defined, measurable business outcomes.
The organization is inviting applications from experienced professionals for the role of Principal Detection Engineer to take ownership of detection efficiency and capability across a CREST-accredited managed detection and response service. Reporting to the Head of Security Operations, the successful candidate will lead the detection function, reducing false positives, maturing rule sets aligned to MITRE ATT&CK, and applying threat intelligence to stay ahead of the evolving threat landscape. The role also involves managing and mentoring a small team of analysts while retaining hands-on technical ownership across rule development, parser builds, and detection lab management. This is primarily a remote position, with occasional travel for quarterly meetings and client engagements.
If you would like to learn more about this opportunity, feel free to reach out and apply today!
Responsibilities:
- Devise and implement a measurable strategy to review alert volumes and reduce false positives, achieving set KPIs and targets
- Implement high fidelity alerting strategies and enable contextual alerting and case building for the analytical team
- Review, amend or retire detection rules to ensure they meet approved use cases
- Baseline newly onboarded customers over a 30-day period to achieve a known good monitoring state
- Advise on tuning and automation opportunities and assist in implementing improvements
- Review and ratify content updates to detection platforms; approve or retire new detections based on use cases
- Ensure all detection improvements and tuning are logged and auditable
- Design and implement a consistent, documented global deployment strategy for detections across a wide range of security technologies
- Build and manage rule packs based on technology feeds utilising the MITRE ATT&CK framework
- Utilise threat intelligence reports to continually refine detections against the current threat landscape
- Ratify log source receipt pre and post deployment, confirming logs are parsed and in a usable format
- Create deception detection capabilities where appropriate to improve team detection ability
- Research and recommend improvements to detection capabilities, processes and technologies
- Assist with alert investigation, QA and feedback to the wider team
- Create and document audit logging standards for all ingested log sources
- Attend internal incident response reviews and use findings to identify new detection opportunities
- Develop and maintain a detection lab for testing new detection capabilities
- Build or amend parsers to ensure event parsing meets approved detection capability requirements
- Run adversary emulation on a scheduled basis to identify detection gaps
- Ensure processes and operating procedures are documented, regularly reviewed and up to date
- Manage a small team, supporting role and responsibility allocation
- Deliver monthly one-to-ones and scheduled mentoring sessions with assigned team members
- Assist in creation of training and development plans to ensure knowledge sharing and consistency
- Assist with alert escalations and support incident response functions as required
- Research and ratify new technologies that could provide commercial advantage
- Pass all relevant manufacturer technical exams required to achieve or maintain accreditations
- Contribute to the operation and improvement of the 24/7 SOC/Service Desk function
Skills/Must Have:
- Minimum 5 years of practical, hands-on detection experience within a Security Operations Centre
- Strong working knowledge of MITRE ATT&CK and threat landscape intelligence
- Experience building, tuning and managing detection rule sets across a range of security technologies
- Practical technical and networking skills, including experience supporting a technical service desk environment
- Excellent understanding of cybersecurity issues, latest developments, risks and research
- Experience with parser builds, log source validation and audit logging standards
- Ability to communicate clearly to non-technical audiences in written and verbal form
- Evidence of ongoing personal development in the IT/cyber security space
- Degree in an information security or networking related discipline, or equivalent security qualifications (degree in progress also considered)
- Self-motivated, adaptable, team-oriented and driven to operate at the forefront of cyber security
Benefits:
- Remote-first working with some travel for quarterly meetings and client engagements; support toward manufacturer technical accreditations
Salary:
- £60,000 - £70,000