Detection Engineer

Detection Engineer

Full-Time 36000 - 60000 Β£ / year (est.) No home office possible
Go Premium
G

At a Glance

  • Tasks: Design and optimise threat detection rules across various platforms and data sources.
  • Company: Join the Government Cyber Coordination Centre, a key player in national cyber security.
  • Benefits: Competitive salary, job security, and opportunities for professional growth.
  • Why this job: Make a real impact on public safety by enhancing government cyber resilience.
  • Qualifications: Experience with query languages and detection engines; strong analytical skills required.
  • Other info: Dynamic role with potential for career advancement in a vital government initiative.

The predicted salary is between 36000 - 60000 Β£ per year.

This is an exciting opportunity to work at the heart of Government cyber security, as part of the Government Cyber Coordination Centre (GC3). The GC3 coordinates the cross-Government response to cyber security vulnerabilities, threats, and incidents, enhancing cyber resilience and enabling the Government to more efficiently and effectively protect public services.

Design, implement, and optimize threat detection content across a wide range of platforms and data sources. This role combines advanced query language skills, a deep understanding of system and network logging, and experience with rule-based detection engines and CI/CD pipelines (notably those developed in Python).

Successful candidates must meet the security requirements before they can be appointed. The level of security needed is Security Check (SC) but must be willing to undergo Developed Vetting (DV) clearance whilst in post where necessary.

Key Responsibilities
  • Develop and optimize detection rules using query languages such as:
  • KQL (Microsoft Sentinel / Defender XDR)
  • SPL (Splunk)
  • AQL (QRadar)
  • EQL/Lucene (Elastic Security)
  • SQL (across traditional and security data platforms)
  • Create and manage detection rules using cross-platform languages such as Sigma and YARA
  • Build, test, and deploy detection rules using CI/CD tools and principles (e.g., GitHub Actions, GitLab CI, Azure DevOps)
  • Tune and validate alerting logic to reduce false positives and optimize signal-to-noise ratio
  • Contribute to detection-as-code practices with structured rule repositories (e.g., Sigma, Panther, custom JSON/YAML formats)
  • Support threat hunting and incident triage using advanced log queries and packet inspection
  • Collaborate with offensive security and threat intelligence teams to translate TTPs into behavioural detections, aligned with industry frameworks such as MITRE ATT&CK
  • Detection Engineer employer: Government Recruitment Service

    Joining the Government Cyber Coordination Centre (GC3) as a Detection Engineer offers a unique opportunity to contribute to national cyber security efforts while working in a collaborative and innovative environment. With a strong focus on employee development, the GC3 provides access to cutting-edge training and resources, fostering growth in advanced detection techniques and technologies. Located within the Department for Science, Innovation and Technology, this role not only supports vital public services but also allows you to be part of a mission-driven team dedicated to enhancing the UK's cyber resilience.
    G

    Contact Detail:

    Government Recruitment Service Recruiting Team

    StudySmarter Expert Advice 🀫

    We think this is how you could land Detection Engineer

    ✨Tip Number 1

    Network, network, network! Get out there and connect with professionals in the cyber security field. Attend meetups, webinars, or even local events. The more people you know, the better your chances of landing that Detection Engineer role.

    ✨Tip Number 2

    Show off your skills! Create a portfolio showcasing your detection rules and any projects you've worked on. This is your chance to demonstrate your expertise in query languages and CI/CD tools. Trust us, a strong portfolio can make you stand out from the crowd.

    ✨Tip Number 3

    Prepare for interviews by brushing up on your technical knowledge and understanding of threat detection frameworks like MITRE ATT&CK. Be ready to discuss how you've applied your skills in real-world scenarios. Confidence and preparation are key!

    ✨Tip Number 4

    Don't forget to apply through our website! We want to see your application and help you get your foot in the door. Plus, it’s a great way to stay updated on any new opportunities that pop up in the Government Cyber Coordination Centre.

    We think you need these skills to ace Detection Engineer

    Advanced Query Language Skills
    System and Network Logging
    Rule-Based Detection Engines
    CI/CD Pipelines
    Python
    KQL (Microsoft Sentinel / Defender XDR)
    SPL (Splunk)
    AQL (QRadar)
    EQL/Lucene (Elastic Security)
    SQL
    Sigma
    YARA
    GitHub Actions
    GitLab CI
    Azure DevOps
    Threat Hunting
    Incident Triage
    Log Queries
    Packet Inspection
    Collaboration with Offensive Security Teams
    Understanding of MITRE ATT&CK Framework

    Some tips for your application 🫑

    Tailor Your CV: Make sure your CV is tailored to the Detection Engineer role. Highlight your experience with query languages and detection rules, as well as any relevant projects you've worked on. We want to see how your skills align with what we're looking for!

    Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to the GC3. Be sure to mention any specific experiences that relate to the responsibilities outlined in the job description.

    Showcase Your Technical Skills: Don’t forget to showcase your technical skills in your application. Mention your proficiency with tools like KQL, SPL, and CI/CD pipelines. We love seeing candidates who can demonstrate their hands-on experience with these technologies!

    Apply Through Our Website: We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you don’t miss out on any important updates. Plus, it’s super easy!

    How to prepare for a job interview at Government Recruitment Service

    ✨Know Your Query Languages

    Make sure you brush up on your query languages like KQL, SPL, and SQL. Be ready to discuss how you've used these in past projects or roles. It’s a great way to show your technical expertise and how you can hit the ground running.

    ✨Understand Detection Rules

    Familiarise yourself with detection rules and how they work across different platforms. Be prepared to explain your experience with rule-based detection engines and CI/CD pipelines, especially if you've worked with Python. This will demonstrate your hands-on experience and problem-solving skills.

    ✨Showcase Your Collaboration Skills

    This role involves working closely with offensive security and threat intelligence teams. Think of examples where you've collaborated effectively in the past. Highlighting your teamwork skills can set you apart from other candidates.

    ✨Prepare for Security Clearance Questions

    Since this position requires Security Check (SC) clearance, be ready to discuss your understanding of security protocols and any relevant experiences. Showing that you take security seriously will resonate well with the interviewers.

    Land your dream job quicker with Premium

    You’re marked as a top applicant with our partner companies
    Individual CV and cover letter feedback including tailoring to specific job roles
    Be among the first applications for new jobs with our AI application
    1:1 support and career advice from our career coaches
    Go Premium

    Money-back if you don't land a job in 6-months

    G
    Similar positions in other companies
    UK’s top job board for Gen Z
    discover-jobs-cta
    Discover now
    >