Role Overview
An experienced Security Engineer to strengthen detection, response, and automation capabilities within a large enterprise security function.
The role spans SIEM engineering, threat hunting, SOAR automation, and secure CI/CD pipeline integration, operating across cross-functional and geographically dispersed teams.
The position requires strong client-facing skills and a proactive, continuous improvement mindset.
Key Responsibilities
- Design, build, and maintain SIEM engineering capabilities, developing and tuning detection rules and use cases to improve threat visibility across the enterprise.
- Lead detection engineering activities, creating and refining detection logic to identify threats across the security telemetry landscape.
- Support and enhance incident response engineering processes, ensuring timely and effective response to security events and alerts.
- Conduct proactive threat hunting activities, leveraging security telemetry and intelligence to identify hidden or emerging threats within the environment.
- Develop and maintain SOAR automation playbooks and integrate security tooling within secure CI/CD pipelines to streamline and accelerate response capabilities.
Top 5 Skills
- SIEM engineering - Proven hands-on experience engineering and administering SIEM platforms at enterprise scale, including rule development, tuning, and optimisation for effective threat detection.
- Detection engineering - Demonstrated ability to develop, refine, and maintain detection logic and use cases across a broad range of threat scenarios and security telemetry sources.
- Incident response engineering - Strong experience supporting and enhancing incident response processes, including triage, investigation, and resolution of security events within enterprise environments.
- SOAR automation - Hands-on experience developing and maintaining SOAR playbooks and automation workflows to accelerate and streamline security operations response activities.
- Threat hunting & secure CI/CD - Proven threat hunting capability using security telemetry, alongside experience integrating security controls within CI/CD pipelines; strong stakeholder management and client-facing communication skills are essential.
Role Details:
- Rate: £500- £550 per day inside IR35
- Length: 12 Month Initial Contract
- Location: Multiple UK Locations (London, Bristol, Leeds, Edinburgh, Halifax)