Hiring.Camp

Associate Cyber Detections Engineer

Sky

·

Today

Location
Osterley, United Kingdom
Type
Full-time
Department
Engineering
Seniority
Entry
Visa
Not sponsored
Source
Workday

Description

We don’t just believe in better. We make it happen.  

Better content. Better products. And better careers.  

 

Working in Tech, Product or Data at Sky is about building the next and the new. From broadband to broadcast, streaming to mobile, Sky Stream to Sky Glass, we never stand still. We optimise and innovate. We turn big ideas into the products, content and services millions of people love. And we do it all right here at Sky. 

 

Role/Team overview 

The Associate Cyber Detections Engineer will support platform log ingestion and transformation, plus the design, development, testing, tuning, and maintenance of security detection content across the organisation’s cyber monitoring platforms. The role is suited to an early-career engineer with strong analytical ability, curiosity about technology, and a practical interest in using log events to identify suspicious or malicious activity.

This role helps improve the organisation’s ability to detect cyber threats quickly and accurately by collecting correct and accurate logs and creating/maintaining reliable detection rules to use them, with supporting documentation.

Working with senior detection engineers, SOC analysts, incident responders, and platform teams, the Associate Cyber Detections Engineer will help convert threat intelligence, use cases, and operational requirements into effective, measurable detections.


 

What you’ll do 

  • Develop, test, tune, and maintain SIEM detection rules to identify suspicious activity across security, infrastructure, cloud, and application telemetry. 

  • Write and optimise SIEM queries, particularly using SQL and Splunk Search Processing Language (SPL), to support detection engineering, threat hunting, and investigation use cases.

  • Assist with translating threat intelligence, attack techniques, incident learnings, and control requirements into practical detection logic.

  • Review detection performance, investigate false positives, and recommend tuning improvements to increase fidelity and reduce unnecessary alert noise.

  • Use Linux command-line tools to inspect logs, validate data, troubleshoot ingestion issues, and support investigation or engineering tasks.

  • Document detection logic, assumptions, test evidence, dependencies, known limitations, and operational response guidance.

  • Work with SOC, incident response, platform engineering, and cloud teams to understand telemetry sources and ensure detections are actionable for analysts.

  • Support detection lifecycle activities, including peer review, version control, testing, deployment, monitoring, and periodic review.

  • Contribute to continuous improvement of detection coverage across common adversary behaviours, cloud activity, identity events, endpoint telemetry, and network logs.


 

What you’ll bring  

The ideal candidate is analytical, technically curious, and comfortable working with log data and security tools. They do not need to be a fully experienced detection engineer, but they should be able to demonstrate hands-on querying ability, a methodical approach to troubleshooting, and a strong interest in building reliable security detections. They should be comfortable collaborating with others, learning from senior engineers, and improving their technical skills over time.


 

Essential criteria:  

  • Practical experience writing SIEM queries, especially using SQL and Splunk SPL.

  • Understanding of SIEM detection rules, correlation searches, alert logic, and the importance of detection quality and tuning.

  • Comfortable using the Linux command line for searching files, inspecting logs, running commands, navigating file systems, and troubleshooting basic issues.

  • Ability to analyse log data and identify meaningful patterns, anomalies, or behaviours that may indicate security risk.

  • Basic understanding of cyber security concepts, including common attack techniques, security monitoring, incident response, and log sources.

  • Good written communication skills, with the ability to document technical logic clearly for both engineers and analysts.

Desirable skills and experience: 

  • Familiarity with AWS cloud services, particularly EC2, IAM and VPC

  • Exposure to infrastructure as code and configuration management tools, particularly Terraform and Ansible.

  • Experience using Git or other version control systems to manage scripts, configuration, or detection content.

  • Awareness of MITRE ATT&CK and how adversary tactics, techniques, and procedures can be mapped to detection coverage.

  • Basic scripting experience, such as Bash or Python, to automate repeatable analysis or engineering tasks.

  • Experience working in, or closely with, a SOC, security engineering, cloud engineering, or infrastructure operations team.


 

Benefits and perks 

There's one thing people can't stop talking about when it comes to life at Sky: the perks. Here’s a taster:  

  • Free Sky TV or NOW package, including Sky Sports and Sky Cinema   

  • Pension package with up to 9% employer contribution

  • Private healthcare with mental health support 

  • Aviva Digital GP and dental insurance 

  • Discounts on Sky products, including Sky Mobile, Sky Broadband, Sky Glass and Sky Protect  

  • Sharesave and Tech schemes 

  • A range of Sky VIP rewards and experiences  

 

How you’ll work 

We've adopted a hybrid working approach to give more flexibility on where and how we work. The hybrid working expectations for this role are 2 days in the office per week. 

 

Your office base  

Our Sky Group HQ. Equipped with state-of-the-art technology and workspaces, there’s plenty of space to see your big ideas come to life. Here you’ll find 13 subsidised restaurants and cafes. You can re-energise at our gym, catch the latest films at our cinema, get your car washed and even get pampered at our beauty salon. 

Our Osterley Campus is just a 10-minute walk from Syon Lane train station, or you can get one of our free shuttle buses from Osterley, Gunnersbury and Ealing Broadway stations. Plus, there’s free onsite parking available for cars, motorbikes and bicycles.

 

Who we are 

We’re Sky, a leading media and entertainment company who connect millions with entertainment, sports, news and arts through innovative products and services. Working with us means you’ll be bringing the joy of a better experience to more people, every day. All so we can do better and deliver better for our customers, colleagues and society.

 

We’re an equal opportunity employer and value diversity at our company. We're a Disability Confident Accredited Employer, and welcome and encourage applications from all candidates. We will look to ensure a fair and consistent experience for all and will make reasonable adjustments to support you where appropriate. Please flag any adjustments you need as early as you can. 

Just so you know: if your application is successful, we’ll ask you to complete a criminal record check. And depending on the role you have applied for and the nature of any convictions you may have, we might have to withdraw the offer.  

To be eligible for this role you are required to have the appropriate right to work in the UK. Please be aware Sky does not offer sponsorship for this position.


 

To find out more about working with us, search #LifeAtSky on social media. 

Skills

PythonAWSTerraformAnsibleLinuxSQLGitSIEMSOCSplunk