Hamilton Barnes 🌳
Principal Analyst - Detection Engineering

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
🚀 Principal Analyst – Detection Engineering | £60,000 – £70,000 | Remote (with occasional travel)
A strong opportunity for a senior detection engineering professional to join a CREST-accredited managed detection and response team, taking principal-level ownership of detection efficiency and capability across a wide range of security products. Reporting to the Head of Security Operations, you'll lead the detection function — reducing false positives, building and maturing detection rule sets aligned to MITRE ATT&CK, utilising threat intelligence to stay ahead of the current threat landscape, and managing a small team of analysts. This is primarily a remote role with some travel for quarterly meetings and client engagements.
If you're a detection-focused SOC professional with strong MITRE ATT&CK and threat intelligence experience, and you're ready to operate at a principal level, this is well worth a conversation.
✨ Why this role stands out:
- Principal-level ownership of detection engineering across the full MDR service — from strategy and rule pack development through to adversary emulation, parser builds and detection lab management
- Lead and mentor a small team, shaping training plans, knowledge sharing and development alongside hands-on technical delivery
- Backed support toward relevant manufacturer technical accreditations and certifications, within a collaborative SOC environment at a well-regarded managed security services provider
🎯 Responsibilities:
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Detection Efficiency
- Devise and implement a measurable strategy to reduce false positives and hit set KPIs
- Implement high fidelity alerting strategies and enable contextual alerting for the analytical team
- Review, amend or retire detection rules to ensure they meet approved use cases
- Baseline newly onboarded customers to achieve a known good monitoring state
- Advise on tuning and automation opportunities and assist in implementing improvements
- Review and ratify content updates to detection platforms
Detection Capability
- Design and implement a consistent, documented global deployment strategy for detections
- Build and manage rule packs based on technology feeds utilising MITRE ATT&CK
- Utilise threat intelligence to continually refine detections against the current threat landscape
- Ratify log source receipt pre and post deployment, confirming logs are parsed correctly
- Research and recommend improvements to detection capabilities, processes and technologies
- Develop and maintain a detection lab for testing new detection capabilities
- Build or amend parsers to meet approved detection capability requirements
- Run scheduled adversary emulation to identify detection gaps
Team & Other
- Manage a small team, supporting role and responsibility allocation
- Deliver monthly one-to-ones and mentoring sessions with assigned team members
- Assist in creating training and development plans
- Support alert escalations and incident response functions as required
- Pass relevant manufacturer technical exams to achieve or maintain accreditations
- Contribute to the operation and improvement of the 24/7 SOC/Service Desk function


Get help with your application
Your very own career expert that helps elevate your application to the next level.
🛠️ Skills/Must Have:
- Minimum 5 years' practical, hands-on detection experience within a Security Operations Centre
- Strong working knowledge of MITRE ATT&CK and threat landscape intelligence
- Experience building, tuning and managing detection rule sets across a range of security technologies
- Practical technical and networking skills, including experience supporting a technical service desk environment
- Experience with parser builds, log source validation and audit logging standards
- Ability to communicate clearly to non-technical audiences in written and verbal form
- Evidence of ongoing personal development in the IT/cyber security space
- Degree in an information security or networking related discipline, or equivalent security qualifications (degree in progress also considered)
- Self-motivated, adaptable, team-oriented and driven to operate at the forefront of cyber security
🎁 Benefits:
- Remote-first working with some travel for quarterly meetings and client engagements
- Support toward manufacturer technical accreditations
💰 Salary: £60,000 – £70,000
📩 Interested? Get in touch to find out more or send your CV directly.
#DetectionEngineering #MITREATTACK #SOC #ThreatIntelligence #MDR #CyberSecurity #RemoteJobs #CRESTAccredited #InfoSecJobs
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location