Open roleExternal
Senior Detection and Response Engineer
- cambridge, england, United Kingdom
- £65 - £95 Per Hour
Job Description
- Lead investigations into escalated security events and incidents, developing hypotheses, collecting evidence and determining root cause and impact.
- Build and optimise detection rules, queries and monitoring logic across cloud, endpoint, network and application environments.
- Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times.
- Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections.
- Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations.
- Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability.
- Participate in an on-call rotation.
Requirements
- Hands-on experience investigating security incidents, including developing investigation hypotheses, collecting artefacts and analysing endpoint, network and application data.
- Strong working knowledge of SIEM and security monitoring tooling, including the ability to write and develop queries for complex investigations.
- Understanding of adversary tactics, techniques and procedures (TTPs), offensive security concepts and MITRE ATT&CK principles.
- Practical knowledge of cloud environments and security controls, with the ability to apply detection and incident response practices across hybrid infrastructure.
- Background developing detection logic, runbooks, automation or security tooling.
- Knowledge of operating system internals and forensic investigation across Windows, macOS or Linux environments.
- Scripting knowledge such as PowerShell or Python would be advantageous.
Core Competencies
Demonstrates expertise in investigating security incidents, developing detection logic, and applying security controls across cloud and hybrid environments. Proficient in utilizing frameworks like MITRE ATT&CK and enhancing security telemetry through automation and tooling.
Highest-signal resume keywords
- Incident Investigation
- Detection Logic Development
- MITRE ATT&CK Framework
- SIEM Tooling
- Cloud Security Practices
ATS Optimization Keywords
Hard Skills
- Security Incident Investigation
- Detection Rule Development
- Threat Hunting
- Forensic Investigation
- Scripting (PowerShell, Python)
Industry Keywords
- Adversary Tactics
- TTPs
- Cloud Environments
- Hybrid Infrastructure
- Incident Response
Tools & Technologies
- SIEM
- Security Monitoring Tooling
- Automation Tools


