Detection Engineer in Farnborough

Detection Engineer in Farnborough

Farnborough Full-Time 36000 - 60000 £ / year (est.) No home office possible
Sixworks

At a Glance

  • Tasks: Design and optimise detection logic to combat cyber threats in a dynamic environment.
  • Company: Join SiXworks, a leader in secure digital solutions and innovation.
  • Benefits: Enjoy 25 days leave, private medical insurance, and professional development opportunities.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
  • Qualifications: Relevant qualifications in Cyber Security or related fields are essential.
  • Other info: Be part of a brilliant team driving digital innovation in Defence and National Security.

The predicted salary is between 36000 - 60000 £ per year.

We currently have an exciting opportunity for a Detection Engineer to join our existing experienced team.

Tasks / Responsibilities

  • Design, implement, and optimise detection logic, rules, and use cases in SIEM, EDR, and related platforms.
  • Tune existing alerts and rules to reduce false positives and enhance detection fidelity.
  • Monitor, analyse, and investigate security alerts to identify potential threats and malicious activity.
  • Conduct threat hunting activities to proactively discover hidden or advanced threats.
  • Collaborate with Incident Response teams to provide detection insights and support investigations.
  • Maintain and improve detection coverage based on emerging threats, adversary tactics (MITRE ATT&CK), and threat intelligence.
  • Develop automation scripts and playbooks to streamline detection and alert triage processes.
  • Document detection processes, use cases, and provide knowledge transfer to SOC analysts.

Qualifications

  • Relevant qualification(s) in Cyber Security, or other related technical roles. Examples: Degree in Cyber Security, Computer Science, Networks etc.
  • Professional Qualifications from organisations such as CompTIA, ISACA etc.
  • Technical qualifications in security and technology such as (but not limited to) cloud computing, SIEM, Vulnerability Scanning/Management etc.

Experience (essential)

  • Strong experience with Security Information and Event Management (SIEM) tools, in order of preference: Elastic Security (Mandatory), Sentinel (Optional), Splunk (Optional).
  • Hands‑on knowledge of Endpoint Detection & Response (EDR) solutions (e.g., Elastic XDR, Microsoft Defender, CrowdStrike, Carbon Black, SentinelOne).
  • Practical understanding of log sources across network, endpoint, cloud, and identity platforms.
  • Solid knowledge of MITRE ATT&CK framework and application in detection engineering.
  • Proficiency in detection rule development using query languages (e.g., ESQL, KQL, Lucene).
  • Experience in incident detection, triage, and analysis in SOC or related environments.
  • Understanding of malware techniques, lateral movement, persistence mechanisms, and threat actor TTPs.

Experience (nice to have)

  • Exposure to cloud security monitoring (AWS, Azure, GCP logging and detections).
  • Knowledge of SOAR platforms and automation playbook creation.
  • Experience with YARA, Sigma, or Snort/Suricata rule writing.
  • Familiarity with container and Kubernetes security monitoring.
  • Threat intelligence analysis and integrating threat intel into detection workflows.
  • Knowledge of offensive security/red teaming methodologies to improve detection coverage.
  • Familiarity with scripting/programming (Python, PowerShell, or similar) for automation and detection enrichment.

About SiXworks

SiXworks is a leading provider of secure digital solutions, specialising in digital experimentation and focused on fail‑safe‑fast cutting‑edge technology solutions deployed in highly secure environments. We are unified in our mission to accelerate innovation and adoption of secure, digital technology to improve the operational agility of Defence and National Security. This is an exciting time for us, we have ambitious plans for continued growth and development, and we are seeking to add brilliant, experienced, motivated, and passionate people to our team to work with us on this journey.

Why join SiXworks?

Our team is a fusion of brilliance, featuring senior operational, technical, and business leaders from various industries and the armed forces. We’re also powered by a league of extraordinary IT engineers, architects, developers, and project managers. Together, we’re an unstoppable force of digital innovation!

What can we offer in return?

SiXworks offers a unique work culture around our core principles Agility, Security, Innovation, Quality, Collaboration and Inclusivity. Together, these six principles form SiXworks’ NORTH STAR, guiding the organisation towards success. This is reflected in the raft of benefits available to all our employees.

Benefits

  • 25 days annual leave + bank holidays
  • Private Medical Insurance
  • Life Assurance Scheme
  • Pension scheme
  • Professional Development opportunities
  • Cycle to Work scheme
  • Perks at Work scheme
  • Discretionary Bonus scheme

A word on UK Security Clearance

Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance.

More details relating to UK Security Clearance can be found here: United Kingdom Security Vetting: clearance levels - GOV.UK (www.gov.uk)

Detection Engineer in Farnborough employer: Sixworks

SiXworks is an exceptional employer that fosters a unique work culture centred around Agility, Security, Innovation, Quality, Collaboration, and Inclusivity. With a strong focus on professional development and a range of benefits including private medical insurance and a generous leave policy, employees are empowered to grow and thrive in their careers while contributing to cutting-edge digital solutions in a secure environment. Joining SiXworks means being part of a dynamic team of experts dedicated to driving innovation in Defence and National Security.
Sixworks

Contact Detail:

Sixworks Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Detection Engineer in Farnborough

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and join online forums. The more connections we make, the better our chances of hearing about job openings before they even hit the market.

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your detection logic, scripts, or any relevant projects. This gives us a chance to demonstrate our expertise beyond just a CV.

✨Tip Number 3

Prepare for interviews by practising common questions related to detection engineering. We should also be ready to discuss real-world scenarios and how we would tackle them. Confidence is key!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure our application gets noticed. Plus, it shows we’re genuinely interested in joining the SiXworks team.

We think you need these skills to ace Detection Engineer in Farnborough

Detection Logic Design
SIEM Tools (Elastic Security, Sentinel, Splunk)
Endpoint Detection & Response (EDR) Solutions
Threat Hunting
Incident Response Collaboration
MITRE ATT&CK Framework
Detection Rule Development (ESQL, KQL, Lucene)
Log Source Analysis
Malware Techniques Understanding
Cloud Security Monitoring (AWS, Azure, GCP)
SOAR Platforms Knowledge
YARA, Sigma, Snort/Suricata Rule Writing
Scripting/Programming (Python, PowerShell)
Threat Intelligence Analysis

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Detection Engineer role. Highlight your experience with SIEM tools, EDR solutions, and any relevant qualifications. We want to see how your skills match what we're looking for!

Showcase Your Projects: If you've worked on any cool projects related to detection engineering or threat hunting, don’t hold back! Share those experiences in your application. It helps us understand your hands-on skills and creativity.

Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points where possible to make it easy for us to read. We appreciate a well-structured application that gets straight to the good stuff!

Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and we can’t wait to see your application come through!

How to prepare for a job interview at Sixworks

✨Know Your Tools Inside Out

Make sure you’re well-versed in the SIEM tools mentioned in the job description, especially Elastic Security. Brush up on your knowledge of EDR solutions too, as they’ll likely come up during the interview.

✨Understand the MITRE ATT&CK Framework

Familiarise yourself with the MITRE ATT&CK framework and be ready to discuss how you've applied it in your previous roles. This shows that you can think critically about threat detection and understand adversary tactics.

✨Prepare for Scenario-Based Questions

Expect scenario-based questions where you might need to demonstrate your problem-solving skills. Think of examples from your past experience where you successfully identified threats or optimised detection rules.

✨Showcase Your Collaboration Skills

Since the role involves working with Incident Response teams, be prepared to talk about your experience collaborating with others. Highlight any instances where your insights led to successful investigations or improved detection processes.

Detection Engineer in Farnborough
Sixworks
Location: Farnborough

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>