Detection Engineer

Detection Engineer

Full-Time 60000 - 80000 £ / year (est.) Working from home possible
Binalyze

At a Glance

  • Tasks: Build and validate detection logic to combat real-world cyber threats.
  • Company: Join a dynamic cybersecurity team at Binalyze, focused on innovation.
  • Benefits: Enjoy 28 days holiday, private medical insurance, and flexible remote work.
  • Other info: Collaborative environment with great growth opportunities and a commitment to diversity.
  • Why this job: Make a real impact in cybersecurity by turning attacker behaviour into actionable detections.
  • Qualifications: Degree in Computer Science or Cybersecurity; experience in detection engineering preferred.

The predicted salary is between 60000 - 80000 £ per year.

We’re looking for a Detection Engineer to join our Customer Experience, Research, and Training (CERT) team and take ownership of the hard part of detection engineering. You’ll be the technical specialist who takes detection logic out of the lab and proves it in the wild, validating, tuning, and operationalising detections inside real customer environments where the stakes are real. Working closely with the Lead Detection Engineer, you’ll ensure the detections we ship are investigation-ready, operationally effective, and grounded in how adversaries actually behave. If you’re excited by the challenge of turning real attacker behaviour into detections that actually catch them, and enjoy bridging the gap between research and real-world operations, we’d love to hear from you.

What you’ll do

  • Build, validate, and sharpen detection logic based on live investigative research and emerging threats.
  • Pressure-test detections against real-world telemetry.
  • Partner directly with Product Engineering to push high-confidence detections and investigative insights into Binalyze AIR, so the platform evolves at the speed of the threat landscape.
  • Turn what we learn from attackers this week into detection capability next week.

What Good Looks Like

  • By 3 months: Onboarded with CERT, Product, and Engineering; baseline understanding of Binalyze AIR detection coverage, customer telemetry patterns, and the current detection backlog; validated and tuned a first set of detections in for at least one product type; first structured feedback delivered to CERT on detection efficacy.
  • By 6 months: Established subject-matter ownership of at least one attacker-technique area; consistent flow of validated detection improvements landing in Binalyze AIR; recognised technical escalation point during complex customer investigations; trusted partner to Solutions Consulting and Forward Deployed Security Architects (FDSA) on detection-related engagements.
  • By 12 months: Measurable improvement in detection quality and investigative signal across the portfolio; faster validation of detections in real customer environments; reduced friction during investigations involving detection logic; demonstrable influence on detection-related roadmap decisions; positive feedback from Solutions Consulting, FDSA, and Product teams.

About You

  • Bachelor’s degree in Computer Science, Cybersecurity, or related field; or equivalent professional experience.
  • Strong background in cybersecurity investigations, detection engineering, threat hunting, or security operations.
  • Hands-on experience developing, validating, and tuning detections in live or production environments.
  • Practical experience with detection and analysis technologies such as YARA, Sigma, SQL, and Python.
  • Familiarity with reverse engineering, malware analysis, or deep artifact analysis to support detection development.
  • Deep understanding of attacker techniques, tradecraft, and investigative workflows across endpoint, network, and cloud environments.
  • Ability to translate technical findings into clear, actionable feedback for Product and Engineering teams.

Preferred/Desirable:

  • DFIR, SOC, or threat detection background in enterprise environments.
  • Experience contributing detections to security platforms or products.
  • Familiarity with endpoint, log, or telemetry-based detection systems.
  • Experience working in fast-moving, customer-facing security roles.

Skills & Behaviours

  • Technical skills: You develop, validate, and tune detection logic using YARA, Sigma, SQL, and Python in real production environments.
  • Detection engineering: You design detections grounded in investigator workflows and attacker tradecraft — not abstract theory — and refine them continuously based on real customer outcomes.
  • Communication: You translate complex technical findings into clear, actionable feedback for Product and Engineering teams.
  • Relationship building: You partner with customers, Solutions Architecture, and Field CIROs without losing technical rigor or investigative depth.
  • Data-driven: You ground detection decisions in real telemetry, attacker behavior, and investigative outcomes — not theory.
  • Project management: You manage multiple concurrent detection workstreams across live engagements and product integration without dropping signal.
  • AI & Automation Fluency: Advanced. You design and build AI-powered automation systems across functions with a focus on business impact. You are expected to operate at Game Changer level on the Binalyze AI Fluency Matrix.

Behaviours:

  • Adaptability: You work comfortably with ambiguity and shifting attacker landscapes. You make calls with incomplete information and adjust as evidence emerges.
  • Initiative: You identify detection gaps and investigative friction points without being asked. You don't wait for a brief.
  • Collaborative: You work across CERT, Product, and Engineering as equal partners, sharing credit and surfacing tradeoffs honestly.
  • Growth mindset: You treat every customer investigation as a chance to sharpen your detection craft and your understanding of attacker behavior.
  • Remote working: You are effective at working asynchronously across time zones. You communicate proactively in writing (Slack, Confluence) and don't rely on being in the same room.

What we offer

  • 28 days holiday allowance + wellbeing days + birthday off!
  • Private medical insurance for you and your family.
  • A supportive and collaborative team that's as passionate as you are.
  • Home office setup support and fully remote and flexible working.
  • Great opportunities for growth and development.
  • Entertainment allowance.
  • Healthy living allowance.

Ready to make an impact? If you’re passionate about building great products, solving complex problems, and advancing the future of cybersecurity, we’d love to meet you.

Diversity & Inclusion

At Binalyze, we are committed to building a diverse and inclusive team. We welcome applicants from all backgrounds, perspectives, and experiences.

Detection Engineer employer: Binalyze

At Binalyze, we pride ourselves on being an exceptional employer, offering a dynamic and collaborative work culture that empowers our Detection Engineers to make a real impact in the cybersecurity landscape. With generous benefits including 28 days of holiday, private medical insurance, and a focus on employee growth through continuous learning opportunities, we ensure our team members thrive both personally and professionally. Our fully remote and flexible working environment allows you to balance your life while contributing to cutting-edge detection engineering that protects our customers in real-world scenarios.

Binalyze

Contact Details:

Binalyze Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Detection Engineer

Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those who work at Binalyze or similar companies. Attend industry events, webinars, and meetups to make connections that could lead to job opportunities.

Tip Number 2

Show off your skills! Create a portfolio showcasing your detection engineering projects, including any YARA or Sigma rules you've developed. This will give potential employers a taste of what you can do and how you think.

Tip Number 3

Prepare for interviews by brushing up on real-world scenarios. Be ready to discuss how you've tackled detection challenges in the past and how you would approach new ones. Use examples that highlight your problem-solving skills and technical expertise.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our team and making an impact in the cybersecurity space.

We think you need these skills to ace Detection Engineer

Detection Engineering
Cybersecurity Investigations
Threat Hunting
Security Operations
YARA
Sigma
SQL

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter for the Detection Engineer role. Highlight your experience with detection logic, cybersecurity investigations, and any relevant tools like YARA or Sigma. We want to see how your skills align with what we’re looking for!

Showcase Your Technical Skills:Don’t hold back on showcasing your technical prowess! Include specific examples of how you've developed, validated, and tuned detections in real-world environments. This is your chance to shine and show us you can bridge the gap between research and operations.

Be Clear and Concise:When writing your application, keep it clear and to the point. Use straightforward language to explain your experiences and achievements. We appreciate clarity, especially when it comes to complex topics like detection engineering!

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you don’t miss out on any important updates. Plus, it shows you’re keen to join our team at StudySmarter!

How to prepare for a job interview at Binalyze

Know Your Stuff

Make sure you brush up on your technical skills, especially in YARA, Sigma, SQL, and Python. Be ready to discuss how you've developed, validated, and tuned detection logic in real-world environments. This is your chance to showcase your hands-on experience!

Understand the Adversary

Familiarise yourself with common attacker techniques and tradecraft. Be prepared to explain how you would translate these behaviours into effective detection strategies. Showing that you can think like an adversary will set you apart from other candidates.

Communicate Clearly

Practice explaining complex technical concepts in simple terms. You’ll need to demonstrate your ability to provide actionable feedback to Product and Engineering teams. Clear communication is key, so think about examples where you've successfully done this before.

Show Your Collaborative Spirit

Highlight your experience working with cross-functional teams. Discuss how you've partnered with customers or other departments to improve detection capabilities. Being a team player who values collaboration will resonate well with the CERT team.