Rodeo
Get started

Sky

Associate Cyber Detections Engineer

Hounslow
Posted about 17 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

We don’t just believe in better. We make it happen. Better content. Better products. And better careers. Working in Tech, Product or Data at Sky is about building the next and the new. From broadband to broadcast, streaming to mobile, Sky Stream to Sky Glass, we never stand still. We optimise and innovate. We turn big ideas into the products, content and services millions of people love. And we do it all right here at Sky.

Role/Team overview

The Associate Cyber Detections Engineer will support platform log ingestion and transformation, plus the design, development, testing, tuning, and maintenance of security detection content across the organisation’s cyber monitoring platforms. The role is suited to an early-career engineer with strong analytical ability, curiosity about technology, and a practical interest in using log events to identify suspicious or malicious activity.

This role helps improve the organisation’s ability to detect cyber threats quickly and accurately by collecting correct and accurate logs and creating/maintaining reliable detection rules to use them, with supporting documentation.

Working with senior detection engineers, SOC analysts, incident responders, and platform teams, the Associate Cyber Detections Engineer will help convert threat intelligence, use cases, and operational requirements into effective, measurable detections.

What you’ll do

  • Develop, test, tune, and maintain SIEM detection rules to identify suspicious activity across security, infrastructure, cloud, and application telemetry.
  • Write and optimise SIEM queries, particularly using SQL and Splunk Search Processing Language (SPL), to support detection engineering, threat hunting, and investigation use cases.
  • Assist with translating threat intelligence, attack techniques, incident learnings, and control requirements into practical detection logic.
  • Review detection performance, investigate false positives, and recommend tuning improvements to increase fidelity and reduce unnecessary alert noise.
  • Use Linux command-line tools to inspect logs, validate data, troubleshoot ingestion issues, and support investigation or engineering tasks.
  • Document detection logic, assumptions, test evidence, dependencies, known limitations, and operational response guidance.
  • Work with SOC, incident response, platform engineering, and cloud teams to understand telemetry sources and ensure detections are actionable for analysts.
  • Support detection lifecycle activities, including peer review, version control, testing, deployment, monitoring, and periodic review.
  • Contribute to continuous improvement of detection coverage across common adversary behaviours, cloud activity, identity events, endpoint telemetry, and network logs.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What you’ll bring

The ideal candidate is analytical, technically curious, and comfortable working with log data and security tools. They do not need to be a fully experienced detection engineer, but they should be able to demonstrate hands-on querying ability, a methodical approach to troubleshooting, and a strong interest in building reliable security detections. They should be comfortable collaborating with others, learning from senior engineers, and improving their technical skills over time.

Essential criteria:

  • Practical experience writing SIEM queries, especially using SQL and Splunk SPL.
  • Understanding of SIEM detection rules, correlation searches, alert logic, and the importance of detection quality and tuning.
  • Comfortable using the Linux command line for searching files, inspecting logs, running commands, navigating file systems, and troubleshooting basic issues.
  • Ability to analyse log data and identify meaningful patterns, anomalies, or behaviours that may indicate security risk.
  • Basic understanding of cyber security concepts, including common attack techniques, security monitoring, incident response, and log sources.
  • Good written communication skills, with the ability to document technical logic clearly for both engineers and analysts.

Desirable skills and experience:

  • Familiarity with AWS cloud services, particularly EC2, IAM and VPC
  • Exposure to infrastructure as code and configuration management tools, particularly Terraform and Ansible.
  • Experience using Git or other version control systems to manage scripts, configuration, or detection content.
  • Awareness of MITRE ATT&CK and how adversary tactics, techniques, and procedures can be mapped to detection coverage.
  • Basic scripting experience, such as Bash or Python, to automate repeatable analysis or engineering tasks.
  • Experience working in, or closely with, a SOC, security engineering, cloud engineering, or infrastructure operations team.

Benefits and perks

There's one thing people can't stop talking about when it comes to life at Sky: the perks. Here’s a taster:

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Free Sky TV or NOW package, including Sky Sports and Sky Cinema
  • Pension package with up to 9% employer contribution
  • Private healthcare with mental health support
  • Aviva Digital GP and dental insurance
  • Discounts on Sky products, including Sky Mobile, Sky Broadband, Sky Glass and Sky Protect
  • Sharesave and Tech schemes
  • A range of Sky VIP rewards and experiences

How you’ll work

We've adopted a hybrid working approach to give more flexibility on where and how we work. The hybrid working expectations for this role are 2 days in the office per week.

Your office base

Our Sky Group HQ. Equipped with state-of-the-art technology and workspaces, there’s plenty of space to see your big ideas come to life. Here you’ll find 13 subsidised restaurants and cafes. You can re-energise at our gym, catch the latest films at our cinema, get your car washed and even get pampered at our beauty salon.

Our Osterley Campus is just a 10-minute walk from Syon Lane train station, or you can get one of our free shuttle buses from Osterley, Gunnersbury and Ealing Broadway stations. Plus, there’s free onsite parking available for cars, motorbikes and bicycles.

Who we are

We’re Sky, a leading media and entertainment company who connect millions with entertainment, sports, news and arts through innovative products and services. Working with us means you’ll be bringing the joy of a better experience to more people, every day. All so we can do better and deliver better for our customers, colleagues and society.

We’re an equal opportunity employer and value diversity at our company. We're a Disability Confident Accredited Employer, and welcome and encourage applications from all candidates. We will look to ensure a fair and consistent experience for all and will make reasonable adjustments to support you where appropriate. Please flag any adjustments you need as early as you can.

Just so you know: if your application is successful, we’ll ask you to complete a criminal record check. And depending on the role you have applied for and the nature of any convictions you may have, we might have to withdraw the offer.

To be eligible for this role you are required to have the appropriate right to work in the UK. Please be aware Sky does not offer sponsorship for this position.

To find out more about working with us, search #LifeAtSky on social media.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

SIEM Querying
Splunk SPL
SQL
Linux Command Line
Log Analysis
Threat Intelligence
Detection Engineering
Threat Hunting
AWS
Terraform
Ansible
Git
MITRE ATT&CK
Bash
Python
Security Monitoring

Location

Hounslow, England, United Kingdom

Sign up to applySee more jobs like this