Senior Detection and Response Engineer
- Location
- Cambridge, England, United Kingdom
Lead investigations into escalated security events and incidents, developing hypotheses, collecting evidence and determining root cause and impact. Build and optimise detection rules, queries and monitoring logic across cloud, endpoint, network and application environments. Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows … response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create and continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations. Work with the external SOC and internal engineering teams ...