Senior Cyber Defence Engineer
Job Summary
The Opportunity:
We need a senior hands-on defender who lives in the trenches. Not a manager not a coordinator - a technical owner who can hunt investigate detect and build. If you enjoy taking a security capability from zero to mature and then keeping it sharp this is for you.
You will be the technical authority for our detection and response stack. You decide what we need you build it you run it you break it to make it better.
What Youll Own:
This is a full-lifecycle ownership role. You are responsible for the health effectiveness and evolution of the tools and processes that let us find and stop attackers - from selection and deployment to tuning integration and eventual decommissioning.
Your Focus Areas:
1. Make Intelligence Actionable
Turn outside noise into inside defence. Youll track adversaries follow campaigns and understand how they operate. Your job is to make sure what we learn about attackers actually shows up in our controls the same day.
2. Own Incidents End-to-End
When something happens you lead the technical response. Youll dig through EDR telemetry logs network and cloud traces to figure out what happened how they got in what they touched and how to kick them out for good. Youll document it properly so we learn from it.
3. Hunt Before The Alert Fires
You wont wait for a SIEM alert. Youll proactively look for attacker behaviors that our tools missed across endpoints identities and cloud. Youll write the detections yourself test them like an attacker would and close the gaps you find.
4. Secure & Defend The Cloud
Youll investigate threats natively in AWS / Azure / GCP. This means knowing where to look in CloudTrail Entra ID GCP audit logs spotting risky permissions identity abuse and helping engineering fix it at the root.
5. Protect The Brand Outside The Perimeter
Takedown phishing fake domains impersonation malicious infra. Youll reverse the kits and payloads and build the evidence packs needed to take it down.
6. Make Vulnerabilities Mean Something
We dont just patch CVEs. Youll connect external exploit chatter with our actual exposure prioritize what is truly weaponized help validate what matters and drive closure on zero-days that pose real risk.
7. Leave The Environment Better Than You Found It
Every incident is a product feedback loop. Youll harden EDR/SIEM/cloud controls automate repetitive response steps and write the playbooks that make the whole team faster next time.
What You Bring:
- 5 to 8 years minimum doing the actual work in IR Threat Hunting or Cyber Threat Intelligence.
- Deep hands-on experience with modern EDR - CrowdStrike preferred - you can query investigate and do live response in your sleep.
- You have handled real incidents solo not just as part of a queue.
- You can write good detections - KQL / SPL / Sigma or similar - and you know how to tune out noise without losing signal.
- You understand how attackers really operate - how they persist move escalate steal creds and hide C2.
- Youve chased threats in the cloud not just on-prem.
- You can script your way out of problems - Python PowerShell or Bash.