Detection Engineer

  • Sixworks
  • Farnborough, Hampshire
  • Dec 13, 2025
Full time I.T. & Communications

Job Description

About the job

We currently have an exciting opportunity for a Detection Engineer to join our existing experienced team.

Tasks / Responsibilities
  • Design, implement, and optimise detection logic, rules, and use cases in SIEM, EDR, and related platforms.
  • Tune existing alerts and rules to reduce false positives and enhance detection fidelity.
  • Monitor, analyse, and investigate security alerts to identify potential threats and malicious activity.
  • Conduct threat hunting activities to proactively discover hidden or advanced threats.
  • Collaborate with Incident Response teams to provide detection insights and support investigations.
  • Maintain and improve detection coverage based on emerging threats, adversary tactics (MITRE ATT&CK), and threat intelligence.
  • Develop automation scripts and playbooks to streamline detection and alert triage processes.
  • Document detection processes, use cases, and provide knowledge transfer to SOC analysts.
Qualifications
  • Relevant qualification(s) in Cyber Security, or other related technical roles
  • Examples:
    • Degree in Cyber Security, Computer Science, Networks etc.
    • Professional Qualifications from organisations such as CompTIA, ISACA etc.
    • Technical qualifications in security and technology such as (but not limited to) cloud computing, SIEM, Vulnerability Scanning/Management etc.
Experience (essential)
  • Strong experience with Security Information and Event Management (SIEM) tools, in order of preference:
  • Elastic Security (Mandatory)
  • Sentinel (Optional)
  • Splunk (Optional)
  • Hands on knowledge of Endpoint Detection & Response (EDR) solutions (e.g., Elastic XDR, Microsoft Defender, CrowdStrike, Carbon Black, SentinelOne).
  • Practical understanding of log sources across network, endpoint, cloud, and identity platforms.
  • Solid knowledge of MITRE ATT&CK framework and application in detection engineering.
  • Proficiency in detection rule development using query languages (e.g., ESQL, KQL, Lucene).
  • Experience in incident detection, triage, and analysis in SOC or related environments.
  • Understanding of malware techniques, lateral movement, persistence mechanisms, and threat actor TTPs.
Experience (nice to have)
  • Exposure to cloud security monitoring (AWS, Azure, GCP logging and detections).
  • Knowledge of SOAR platforms and automation playbook creation.
  • Experience with YARA, Sigma, or Snort/Suricata rule writing.
  • Familiarity with container and Kubernetes security monitoring.
  • Threat intelligence analysis and integrating threat intel into detection workflows.
  • Knowledge of offensive security/red teaming methodologies to improve detection coverage.
  • Familiarity with scripting/programming (Python, PowerShell, or similar) for automation and detection enrichment.
About SiXworks

SiXworks is a leading provider of secure digital solutions, specialising in digital experimentation and focused on fail safe fast cutting edge technology solutions deployed in highly secure environments. We are unified in our mission to accelerate innovation and adoption of secure, digital technology to improve the operational agility of Defence and National Security. This is an exciting time for us, we have ambitious plans for continued growth and development, and we are seeking to add brilliant, experienced, motivated, and passionate people to our team to work with us on this journey.

Why join SiXworks?

Our team is a fusion of brilliance, featuring senior operational, technical, and business leaders from various industries and the armed forces. We're also powered by a league of extraordinary IT engineers, architects, developers, and project managers. Together, we're an unstoppable force of digital innovation!

What can we offer in return?

SiXworks offers a unique work culture around our core principles Agility, Security, Innovation, Quality, Collaboration and Inclusivity. Together, these six principles form SiXworks'NORTH STAR, guiding the organisation towards success. This is reflected in the raft of benefits available to all our employees.

Benefits
  • 25 days annual leave + bank holidays
  • Private Medical Insurance
  • Life Assurance Scheme
  • Pension scheme
  • Professional Development opportunities
  • Cycle to Work scheme
  • Perks at Work scheme
  • Discretionary Bonus scheme
A word on UK Security Clearance

Due to the secure nature of the position and working environment, you must have, or be eligible to obtain Security Clearance.

More details relating to UK Security Clearance can be found here:

United Kingdom Security Vetting: clearance levels - GOV.UK ()

SiXworks is an IBM subsidiary which has been acquired by IBM and will be integrated into the IBM organisation. SiXworks will be the hiring entity. By proceeding with this application, you understand that SiXworks will share your personal information with other IBM subsidiaries involved in your recruitment process, wherever these are located. More Information on how IBM protects your personal information, including the safeguards in case of cross border data transfer, are available here: