Skip to main content
RoleCybersecurity

Detection Engineer

Write Sigma/Splunk rules, tune noise, hunt the gap your SIEM missed.

POST verdict

The most defensible blue-team specialism going. Smaller market than SOC, much harder to be bad at, much harder to be replaced.

Domain
Cybersecurity
Entry
£32–52k
Senior
£95–135k
Pick this if
  • You enjoy adversary behaviour more than alerts and dashboards
  • You can write code, properly, not just KQL one-liners
  • You want a seat that compounds, every detection you write is yours
  • You're patient enough to tune for months before you see clean signal
Skip this if
  • You're hoping detection engineering will get you off shift work without doing the homework
  • You don't enjoy reading other people's incident reports for fun
  • You can't work without immediate feedback, the loop here is long
  • Your detections survive a year without retuning
  • You can read a threat report and ship coverage from it the same week
  • Red team finds your rules before they find your gaps
  • Other analysts copy your detection structure without being told
The bit you're probably underestimating

The role assumes a foundation that bootcamps don't teach: SOC time, IR exposure, real coding ability, and a working theory of how adversaries operate. Without that, you'll spend a year writing rules that fire on benign noise and a second year being quietly moved back to triage. Earn the seat by doing detection-adjacent work inside SOC first. Skip the queue and you'll get found out fast.

Hover any chip for the calibrated meaning. Ratings are directional, not absolute.

Strong. Staff Detection / Threat Engineering tracks are well established.

  • +SOC analyst
  • +IR analyst
  • +Sysadmin with security interest
  • That it's just rule-writing, modeling adversary behavior is the real work.
  • Threat Hunter
  • Security Engineer
  • Purple Team

Listed because the graph connects them to this role, not because you need all of them. Most practitioners pick one or two.

Practitioner assessment checked against published external evidence.

Last reviewed: September 2026 · UK market · Confidence: indicative

Where this fits

Roles connect to pathways, certs and other roles. Use one to test the next.

The next step

You've read about the role. The harder question is whether it's the right one for you.

A Career Verdict is the written, practitioner-authored call on your specific route into and out of this role. Six primitives, same format every time.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.