Senior Security Engineer Monitoring & Detection
Posted:
5 July 2026 (30+ days ago)
Application Deadline:
19 November 2026
Vacancies:
1 Vacancy
Job Summary
We help UK public sector organisations build and run digital services that are secure trustworthy and resilient. As a Senior Security Engineer in our Cyber practice you will need to be able to take end-to-end ownership of securing the systems we build; embedding security into delivery pipelines and building the tooling and automation that keep complex government services safe by default.
Were looking for a Senior Security Engineer- Monitoring & Detection who can build and tune detection logic in a live SOC and own the pipelines that feed it. Youll work hands-on across SIEM/detection and log ingestion/normalisation and translate technical risk into decisions for government stakeholders and system owners. This is a delivery role: security assurance should speed decisions up not slow them down.
Key Responsibilities
Detection Engineering
- Build & tune: detection rules across Splunk (SPL) YARA and EDR platforms.
- Coverage & quality: map detections to MITRE ATT&CK; track signal-to-noise and false-positive rates to keep alerting high-fidelity.
- Validation: test new/updated rules via replay and load testing; run red-team scenarios for critical rules.
- Feedback loops: work with L1L3 analysts so detections stay grounded in operational reality.
- Pipelines: manage log ingestion on Cribl routing filtering normalisation and enrichment at the edge.
- Optimisation: reduce volume via deduplication trimming and NetFlow summarisation; manage streaming/storage (Kinesis S3 Amazon Security Lake).
- Standards: apply hot/warm/cold data tiering; normalise into OCSF; enforce encryption and least-privilege access.
Stakeholders & Team
- Translation: turn technical risk into business/policy terms for civil servant stakeholders and system owners.
- Mentorship: support junior/mid-level engineers and act as a technical point of contact across teams.
Skills Knowledge & Expertise
- Hands-on cloud security experience AWS Azure or GCP.
- Either: Advanced Splunk (SPL); YARA and EDR detection logic.
or
- Experience with Cribl Kinesis S3 Amazon Security Lake and OCSF/data normalisation.
- Strong grasp of Zero Trust identity-first security secrets management and network segmentation.
- Experience working with or alongside UK Government / public sector stakeholders.
Job Benefits
We are always listening to our growing teams and evolving the benefits available to our people. As we scale as do our benefits and we are scaling quickly. Weve recently introduced a flexible benefit platform which includes a Smart Tech scheme Cycle to work scheme and an individual benefits allowance which you can invest in a Health care cash plan or Pension plan. Were also big on connection and have an optional social and wellbeing calendar of events for all employees to join should they choose to.
Here are some of our most popular benefits listed below:
Paid counselling - we offer paid counselling as well as financial and legal advice
At this point we hope youre feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if youd like an informal chat about the role and your suitability before applying. We are hiring for this role directly so will not respond to any CVs sent via external recruitment agencies.
SC Eligibility
At this point we hope youre feeling excited about Made Tech and the job opportunity. Get in touch with our talent team if youd like an informal chat about the role and your suitability before applying. We are hiring for this role directly so will not respond to any CVs sent via external recruitment agencies.
SC Eligibility
An increasing number of our customers are specifying a minimum of SC (security check) clearance in order to work on their projects. As a result were looking for all successful candidates for this role to have eligibility.
Eligibility for SC requires 5 years UK residency and 5 year employment history (or back to full-time education). Please note that if at any point during the interview process it is apparent that you may not be eligible for SC we wont be able to progress your application and we will contact you to let you know why.
Support in applying
Support in applying
If you need this job description in another format or other support in applying please email .
We believe we can use tech to make public services better. We also believe this can happen best when our own team represents the society that actually uses the services we work on. Were collectively continuing to grow a culture that is happy healthy safe and inspiring for people of all backgrounds and experiences so we encourage people from underrepresented groups to apply for roles with us.
When you apply well put you in touch with a member of our talent team who can help with any needs or adjustments we may need to make to help with your application. Weve put together this blog as a resource to share more about reasonable adjustments and some examples of what this could include. We also welcome any feedback on how we can improve the experience for future candidates.
Working hours: Our standard hours are Monday to Friday but the nature of this role means some work outside normal hours may be required for example during release and change windows planned maintenance or to align with client operating hours. This is occasional rather than routine and well always give as much notice as we can and agree it with you in advance wherever possible.
Working hours: Our standard hours are Monday to Friday but the nature of this role means some work outside normal hours may be required for example during release and change windows planned maintenance or to align with client operating hours. This is occasional rather than routine and well always give as much notice as we can and agree it with you in advance wherever possible.
Required Experience:
Senior IC
About Company
We provide Digital, Data and Technology services to help organisations make a positive impact – fast.