All Jobs Vacancy

Security Detection Engineer

Posted 1 day ago by McCabe & Barton

Key Responsibilities

  • Detection Engineering & SIEM Uplift
  • Design and implement detection rules in Datadog (or Sentinel/SIEM equivalent)
  • Support UEBA (User & Entity Behaviour Analytics) to catch compromise early
  • Use Claude Code to develop detection logic and correlation rules
  • Build AI-powered anomaly detection (user behaviour, access patterns)
  • Automate alert triage and prioritization
  • Platform Integration & Automation
  • Integrate Datadog with Azure monitoring and GCP Cloud Logging
  • Use Terraform to automate detection deployment and configuration
  • Build CI/CD for detection rules (version control, testing, rollback)
  • Develop custom metrics and alerting for deal-sensitive operations

Required Experience & Skills

  • Core Detection & Threat Analysis
  • Experienced building detection rules (SIEM, EDR, or cloud-native tooling)
  • Deep understanding of attack patterns (MITRE ATT&CK framework)
  • SOC operations, threat analysis, or incident response
  • Datadog & Cloud Monitoring
  • Hands-on Datadog OR equivalent Sentinel/SIEM experience
  • Azure Monitor and Log Analytics familiarity
  • GCP Cloud Logging and Cloud Security Command Center desirable
  • Technical Engineering
  • SQL proficiency (query security events, build custom reports)
  • Python or PowerShell (detection automation, data enrichment)
  • Terraform (automate detection deployment) essential
  • YAML (configuration management for detections)
  • Cloud & Data Platforms
  • Azure security architecture (Entra ID, networking, identity)
  • GCP security basics desirable
  • Snowflake security fundamentals
  • EDR platform experience (CrowdStrike, Microsoft Defender, or similar)
  • Security & Compliance
  • Knowledge of financial services threats (insider threats, data theft, credential abuse)
  • Understanding of regulatory requirements (DORA, FCA, SOC2)
  • Familiarity with incident response frameworks
  • Comfortable in 24/7 on-call environment during integration crisis period

Ideal candidate

  • Seasoned Security engineer who can operate independently
  • Experience of hands-on detection/threat analysis
  • Strong technical foundations (SQL, Python, cloud platforms)
  • Integration or M&A security experience
  • Forward-thinking mindset (AI-assisted security, emerging threats)
  • Independent operator (self-directed in ambiguous environment)
  • Datadog OR Sentinel experience (or very strong hands-on SIEM background)
  • Open-source and modern tech stack comfortable
  • Snowflake and/or data platform security exposure valuable
Rate:
£750/day
Location:
London
IR35 Status:
Inside
Remote Status:
Hybrid
Industry:
Cybersecurity
Seniority Level:
Mid-Level

Take-Home Pay

£11,200 per month

Visit calculators for additional details

Create a free account to view the take-home pay for this contract

Share job